Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.
Changes included in this PR
Vulnerabilities that will be fixed
With an upgrade:
Why? CVSS 8.1
SNYK-JS-AJV-584908
Why? Proof of Concept exploit, CVSS 7.5
SNYK-JS-ANSIREGEX-1583908
Why?
SNYK-JS-BABELTRAVERSE-5962462
Why?
SNYK-JS-BODYPARSER-7926860
Why?
SNYK-JS-BRACES-6838727
Why?
SNYK-JS-BROWSERIFYSIGN-6037026
Why? Proof of Concept exploit, CVSS 5.3
SNYK-JS-BROWSERSLIST-1090194
Why?
SNYK-JS-COOKIE-8163060
Why?
SNYK-JS-DECODEURICOMPONENT-3149970
Why? CVSS 6.8
SNYK-JS-ELLIPTIC-1064899
Why?
SNYK-JS-ELLIPTIC-7577916
Why?
SNYK-JS-ELLIPTIC-7577917
Why?
SNYK-JS-ELLIPTIC-7577918
Why?
SNYK-JS-ELLIPTIC-8172694
Why?
SNYK-JS-ELLIPTIC-8187303
Why?
SNYK-JS-ES5EXT-6095076
Why?
SNYK-JS-EXPRESS-6474509
Why?
SNYK-JS-EXPRESS-7926867
Why? Proof of Concept exploit, CVSS 5.3
SNYK-JS-GLOBPARENT-1016905
Why? Proof of Concept exploit, CVSS 5.3
SNYK-JS-HOSTEDGITINFO-1088355
Why?
SNYK-JS-HTTPCACHESEMANTICS-3248783
Why?
SNYK-JS-INFLIGHT-6095116
Why?
SNYK-JS-JSON5-3182856
Why?
SNYK-JS-LOADERUTILS-3042992
Why?
SNYK-JS-LOADERUTILS-3043105
Why?
SNYK-JS-LOADERUTILS-3105943
Why? Proof of Concept exploit, Has a fix available, CVSS 5.3
SNYK-JS-LODASH-1018905
Why? Proof of Concept exploit, Has a fix available, CVSS 7.2
SNYK-JS-LODASH-1040724
Why? Proof of Concept exploit, Has a fix available, CVSS 8.2
SNYK-JS-LODASH-567746
Why? Proof of Concept exploit, CVSS 7.3
SNYK-JS-LODASHSET-1320032
Why?
SNYK-JS-MICROMATCH-6838728
Why?
SNYK-JS-MINIMATCH-3050818
Why? Proof of Concept exploit, CVSS 3.7
SNYK-JS-MINIMIST-2429795
Why? Has a fix available, CVSS 6.5
SNYK-JS-NODEFETCH-2342118
Why? Proof of Concept exploit, CVSS 7.5
SNYK-JS-NTHCHECK-1586032
Why? Proof of Concept exploit, CVSS 5.3
SNYK-JS-PATHPARSE-1077067
Why?
SNYK-JS-PATHTOREGEXP-7925106
Why? Proof of Concept exploit, Has a fix available, CVSS 5.3
SNYK-JS-POSTCSS-1090595
Why? Proof of Concept exploit, Has a fix available, CVSS 5.3
SNYK-JS-POSTCSS-1255640
Why?
SNYK-JS-POSTCSS-5926692
Why?
SNYK-JS-QS-3153490
Why? CVSS 5.3
SNYK-JS-REDIS-1255645
Why?
SNYK-JS-SEMVER-3247795
Why?
SNYK-JS-SEND-7926862
Why?
SNYK-JS-SERIALIZEJAVASCRIPT-6147607
Why?
SNYK-JS-SERVESTATIC-7926865
Why? Proof of Concept exploit, CVSS 7.5
SNYK-JS-SSRI-1246392
Why? CVSS 8.2
SNYK-JS-TAR-1536528
Why? CVSS 8.2
SNYK-JS-TAR-1536531
Why? CVSS 3.7
SNYK-JS-TAR-1536758
Why? CVSS 8.5
SNYK-JS-TAR-1579147
Why? CVSS 8.5
SNYK-JS-TAR-1579152
Why? CVSS 8.5
SNYK-JS-TAR-1579155
Why?
SNYK-JS-TAR-6476909
Why? CVSS 5.3
SNYK-JS-TERSER-2806366
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
SNYK-JS-TRIM-1017038
Why? CVSS 7.5
SNYK-JS-TRIMNEWLINES-1298042
Why? CVSS 7.5
SNYK-JS-UNSETVALUE-2400660
Why?
SNYK-JS-WEBPACK-7840298
Why? Proof of Concept exploit, CVSS 7.3
SNYK-JS-Y18N-1021887
Why?
npm:debug:20170905
(*) Note that the real score may have changed since the PR was raised.
Commit messages
Package name: babel-loader
The new version differs by 70 commits.See the full diff
Package name: cheerio
The new version differs by 250 commits.See the full diff
Package name: cookie-parser
The new version differs by 42 commits.See the full diff
Package name: copy-webpack-plugin
The new version differs by 173 commits.See the full diff
Package name: css-loader
The new version differs by 211 commits.note
tags reset ordered list numbering github/docs#1552)See the full diff
Package name: express
The new version differs by 250 commits.See the full diff
Package name: got
The new version differs by 250 commits.See the full diff
Package name: ioredis-mock
The new version differs by 67 commits.See the full diff
Package name: linkinator
The new version differs by 144 commits.labels
parameter: "array of undefineds" github/docs#549)See the full diff
Package name: mini-css-extract-plugin
The new version differs by 131 commits.