Skip to content

[Snyk] Fix for 1 vulnerabilities #1

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

gstearmit
Copy link
Owner

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • package.json

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
medium severity 479/1000
Why? Has a fix available, CVSS 5.3
Regular Expression Denial of Service (ReDoS)
SNYK-JS-GLOBPARENT-1016905
Yes No Known Exploit

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: webpack The new version differs by 250 commits.
  • 4be093d 2.2.0
  • 2278469 2.2.0-rc.8
  • b946eb4 Merge pull request #3988 from malstoun/bug/2664
  • 260e413 Merge pull request #3986 from webpack/bugfix/revert_use_of_buffer_dot_from
  • 0ec7de9 Fix regression with watch cli opt, add tests for this case
  • 72226db add missing disable line
  • 4d30675 build fresh yarn.lock file to remove buffer polyfill
  • 91c1f35 fix(node): rollback changes of Buffer.from to new Buffer() and bump down travis to 4.3 min node v
  • 0b47602 2.2.0-rc.7
  • db6ccbc Merge pull request #3978 from webpack/bugfix/conditional-reexports
  • 82a5b03 Merge pull request #3977 from malstoun/bug/2664
  • fc1a43b Merge pull request #3976 from timse/rely-on-defaults
  • a44694a hoist exports declarations too
  • 682bde8 Fix lint
  • c6d7d90 Add tests
  • af8d49e remove defaults values to shave a few bytes
  • 9796696 2.2.0-rc.6
  • e9bdb05 Merge pull request #3971 from webpack/bugfix/fix_available_vars_in_fmtp
  • bd45bdc add test case for global in harmony modules
  • bfccb20 fix PR
  • 5a3a23f fix(nmf): Fix exports for var injection to include free glob exports or arguments
  • 437dce4 2.2.0-rc.5
  • 91cb1df Merge pull request #3970 from webpack/ci/appveyor
  • 9fd55e5 Merge pull request #3969 from webpack/bugfix/issue-3964

See the full diff

Package name: webpack-stream The new version differs by 24 commits.
  • b445690 v4.0.0
  • 69ee9e0 Last of the manual release history
  • d327ac7 Test on more travis versions
  • eca18b1 Merge branch 'master' of github.com:shama/webpack-stream
  • 6ec5dcf Merge pull request #155 from sirlancelot/patch/update-dependencies
  • 59b734a Update backwards compat deps to latest
  • 711fd52 Merge branch 'master' of github.com:shama/webpack-stream
  • ab27f87 Merge pull request #129 from renaesop/master
  • 5f76f26 Merge pull request #123 from Simek/patch-1
  • 0743db0 Merge pull request #140 from logicrebel/peetersdiet-readme-multi-compiler
  • 7121ea1 Merge pull request #143 from FrancescElies/patch-1
  • 1d90268 Update copyright year
  • ad685b7 Merge pull request #137 from renminghao/master
  • 25b953b Merge pull request #126 from jeroennoten/patch-1
  • 2e35808 Fix lint warning
  • 096119b Add Webpack to devDependencies; fix tests
  • 2f5009c Update dependencies
  • 6d1cb17 Move Webpack out of dependencies
  • ad1447a Adds installation section to readme
  • bd29d45 Added example for multi-compiler support
  • f493370 fix bug
  • 58b98c5 fix a bug:
  • d78a356 No error event on compilation error when watching
  • f8541ac Fix TypeError when 'stats' are undefined

See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic

The following vulnerabilities are fixed with an upgrade:
- https://snyk.io/vuln/SNYK-JS-GLOBPARENT-1016905
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants