Skip to content
This repository was archived by the owner on May 5, 2025. It is now read-only.

[Snyk] Fix for 1 vulnerabilities#7

Open
Mairu wants to merge 1 commit into
masterfrom
snyk-fix-ad98d7aa844ab2c21d08444770061251
Open

[Snyk] Fix for 1 vulnerabilities#7
Mairu wants to merge 1 commit into
masterfrom
snyk-fix-ad98d7aa844ab2c21d08444770061251

Conversation

@Mairu

@Mairu Mairu commented Jun 20, 2023

Copy link
Copy Markdown
Owner

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • package.json

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
medium severity 658/1000
Why? Proof of Concept exploit, Recently disclosed, Has a fix available, CVSS 5.3
Regular Expression Denial of Service (ReDoS)
SNYK-JS-SEMVER-3247795
Yes Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: electron-packager The new version differs by 161 commits.
  • 41acebf docs(news): fix 15.0.0 link
  • 0fb2f1f 15.0.0
  • 65ae3fe chore(deps): bump electron-notarize from 0.3.0 to 1.0.0 (#1157)
  • 198ffb2 refactor: replace sanitize-filename with filenamify (#1156)
  • 34d6fb1 build: test Node 14 in CI (#1155)
  • 4d22659 fix(infer): add missing fields to the infer error message (#1153)
  • e41de9f build(deps-dev): upgrade eslint to ^7.1.0 & @ typescript-eslint/* to ^3.0.0 (#1152)
  • 1ba3294 build: merge ESLint config files into package.json when possible
  • 0505742 docs: clarify disabling pruning via the API in the README
  • a0ef38f refactor: rename ignore source files/functions to copy-filter (#1151)
  • e3913f6 feat: Add support for macOS app API key notarization (#1127)
  • 366df35 build(deps): upgrade electron-notarize to ^0.3.0
  • 37a0f2c Merge pull request #1139 - refactor: replace cross-zip with extract-zip
  • bc61ca5 refactor: replace cross-zip with extract-zip
  • 9c9b8de test(unzip): refactor for efficiency and readability
  • b4247f9 test(unzip): unzip should preserve symbolic links
  • 39851a1 chore(deps): bump fs-extra from 8.1.0 to 9.0.0 (#1137)
  • fc1dbbc chore(deps-dev): bump typedoc from 0.16.11 to 0.17.1 (#1136)
  • c9c5170 fix(mac): check for osxNotarize.hardened-runtime in addition to hardenedRuntime
  • 4081666 build: upgrade asar to ^3.0.0
  • 30169e3 build: ignore typedoc output for eslint
  • eaf597b build: upgrade to malept/github-action-gh-pages@1.0.2
  • c937f41 docs: note in usage that sub-properties listed aren't exhaustive
  • 68c63f7 docs: add electron-notarize to DEBUG list

See the full diff

Package name: semver The new version differs by 168 commits.
  • e7b78de chore: release 7.5.2
  • 58c791f fix: diff when detecting major change from prerelease (#566)
  • 5c8efbc fix: preserve build in raw after inc (#565)
  • 717534e fix: better handling of whitespace (#564)
  • 2f738e9 chore: bump @ npmcli/template-oss from 4.14.1 to 4.15.1 (#558)
  • aa016a6 chore: release 7.5.1
  • d30d25a fix: show type on invalid semver error (#559)
  • 09c69e2 chore: bump @ npmcli/template-oss from 4.13.0 to 4.14.1 (#555)
  • 5b02ad7 chore: release 7.5.0
  • e219bb4 fix: throw on bad version with correct error message (#552)
  • 503a4e5 feat: allow identifierBase to be false (#548)
  • fc2f3df fix: incorrect results from diff sometimes with prerelease versions (#546)
  • 2781767 fix: avoid re-instantiating SemVer during diff compare (#547)
  • 82aa7f6 chore: release 7.4.0
  • 731d896 chore: enable CD (#545)
  • 940723d fix: intersects with v0.0.0 and v0.0.0-0 (#538)
  • aa516b5 fix: faster parse options (#535)
  • 61e6ea1 fix: faster cache key factory for range (#536)
  • f8b8b61 fix: optimistic parse (#541)
  • 796cbe2 fix: semver.diff prerelease to release recognition (#533)
  • 3f222b1 fix: reuse comparators on subset (#537)
  • 113f513 feat: identifierBase parameter for .inc (#532)
  • ea689bc chore: basic type test for RELEASE_TYPES
  • c5d29df docs: Add "Constants" section to README

See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Regular Expression Denial of Service (ReDoS)

The following vulnerabilities are fixed with an upgrade:
- https://snyk.io/vuln/SNYK-JS-SEMVER-3247795
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants