Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Snyk] Security upgrade lodash from 4.17.20 to 4.17.21 #79

Merged
merged 1 commit into from
Feb 23, 2021

Conversation

NetCZ
Copy link
Owner

@NetCZ NetCZ commented Feb 23, 2021

Snyk has created this PR to fix one or more vulnerable packages in the `yarn` dependencies of this project.

merge advice

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • package.json
    • yarn.lock

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
medium severity 658/1000
Why? Proof of Concept exploit, Recently disclosed, Has a fix available, CVSS 5.3
Regular Expression Denial of Service (ReDoS)
SNYK-JS-LODASH-1018905
No Proof of Concept
high severity 753/1000
Why? Proof of Concept exploit, Recently disclosed, Has a fix available, CVSS 7.2
Command Injection
SNYK-JS-LODASH-1040724
No Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic

closes #78

@codeclimate
Copy link

codeclimate bot commented Feb 23, 2021

Code Climate has analyzed commit 6fcd313 and detected 0 issues on this pull request.

View more on Code Climate.

@coveralls
Copy link

Pull Request Test Coverage Report for Build 476

  • 0 of 0 changed or added relevant lines in 0 files are covered.
  • No unchanged relevant lines lost coverage.
  • Overall coverage remained the same at 89.873%

Totals Coverage Status
Change from base Build 470: 0.0%
Covered Lines: 99
Relevant Lines: 108

💛 - Coveralls

3 similar comments
@coveralls
Copy link

Pull Request Test Coverage Report for Build 476

  • 0 of 0 changed or added relevant lines in 0 files are covered.
  • No unchanged relevant lines lost coverage.
  • Overall coverage remained the same at 89.873%

Totals Coverage Status
Change from base Build 470: 0.0%
Covered Lines: 99
Relevant Lines: 108

💛 - Coveralls

@coveralls
Copy link

Pull Request Test Coverage Report for Build 476

  • 0 of 0 changed or added relevant lines in 0 files are covered.
  • No unchanged relevant lines lost coverage.
  • Overall coverage remained the same at 89.873%

Totals Coverage Status
Change from base Build 470: 0.0%
Covered Lines: 99
Relevant Lines: 108

💛 - Coveralls

@coveralls
Copy link

Pull Request Test Coverage Report for Build 476

  • 0 of 0 changed or added relevant lines in 0 files are covered.
  • No unchanged relevant lines lost coverage.
  • Overall coverage remained the same at 89.873%

Totals Coverage Status
Change from base Build 470: 0.0%
Covered Lines: 99
Relevant Lines: 108

💛 - Coveralls

@NetCZ NetCZ merged commit ea86d3f into master Feb 23, 2021
@NetCZ NetCZ deleted the snyk-fix-b41e26362eb167488eb1e9bd34a75571 branch February 23, 2021 12:56
@NetCZ
Copy link
Owner Author

NetCZ commented Feb 23, 2021

🎉 This PR is included in version 1.7.6 🎉

The release is available on:

Your semantic-release bot 📦🚀

@NetCZ NetCZ added the released label Feb 23, 2021
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants