Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Snyk] Upgrade nodegit from 0.24.3 to 0.26.5 #1

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

snyk-bot
Copy link

@snyk-bot snyk-bot commented May 5, 2020

Snyk has created this PR to upgrade nodegit from 0.24.3 to 0.26.5.

ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.
  • The recommended version is 24 versions ahead of your current version.
  • The recommended version was released 2 months ago, on 2020-02-27.

The recommended version fixes:

Severity Issue Exploit Maturity
Improper Link Resolution Before File Access
SNYK-JS-NODEGIT-542723
Mature
Improper Handling of Alternate Data Stream
SNYK-JS-NODEGIT-542722
No Known Exploit
Improper Handling of Alternate Data Stream
SNYK-JS-NODEGIT-542721
Mature
Directory Traversal
SNYK-JS-NODEGIT-542720
No Known Exploit
Release notes
Package name: nodegit from nodegit GitHub release notes
Commit messages
Package name: nodegit
  • f55a66d Bump to v0.26.5
  • bfb4de0 Merge pull request #1758 from implausible/bump/libgit2-fork
  • adb461e Bring in Libgit2 #5384 to NodeGit
  • 6422810 Use github actions for CI status badge in README.md
  • cf10bce Merge pull request #1509 from tniessen/fix-commit-parent-no-repo-prop
  • 06489c7 Merge pull request #1733 from igncp/update-difflist-to-diff
  • b111960 Merge pull request #1508 from tniessen/repository-remove-unnecessary-assignment
  • e3bb744 Fix behavior of Commit#parent
  • c2b61a2 Remove unnecessary assignment of Commit#repo
  • 8ad3e37 Bump to v0.26.4
  • f3a66d6 Merge pull request #1751 from implausible/fixup/template-input-data
  • 59437a8 Fix some issues from the libgit2 bump
  • 24a9fc4 Merge pull request #1748 from ianhattendorf/feature/longpaths
  • a4fe703 Merge pull request #1749 from implausible/patch/libssh2
  • b22ae75 Remove appveyor.yml and .travis.yml
  • 2a79ce9 Default option return value to undefined
  • 8ae2436 Longpaths options should take/return boolean values
  • fcdb122 Bring in libssh2#402
  • e4e66f4 Add longpath options to NodeGit.Libgit2.OPT
  • 22d94f1 Format opts.cc
  • 743b7a9 Remove unused libgit2 files
  • 80698b4 Update to latest libgit2 master
  • ef0c27c Expose git_libgit2_opts
  • 0598d40 Merge in libgit2 longpaths PR

Compare


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

🧐 View latest project report

🛠 Adjust upgrade PR settings

🔕 Ignore this dependency or unsubscribe from future upgrade PRs

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

1 participant