Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Snyk] Fix for 1 vulnerabilities #39

Closed
wants to merge 1 commit into from

Conversation

snyk-bot
Copy link
Contributor

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • package.json

Vulnerabilities that will be fixed

With an upgrade:
Severity Issue Breaking Change Exploit Maturity
medium severity Prototype Pollution
SNYK-JS-MINIMIST-559764
Yes Proof of Concept
Commit messages
Package name: del-cli The new version differs by 3 commits.

See the full diff

Package name: knex The new version differs by 250 commits.
  • eb136f1 Merge branch 'master' of https://github.com/tgriesser/knex
  • 2072163 Update version in changelog (#3138)
  • f28ae7a Merge branch 'master' of https://github.com/tgriesser/knex
  • f757e36 Bump version to 0.16.4 (#3137)
  • 18532b2 Bump version to 0.16.4
  • 286d84b Prepare for 0.16.4-next3 release (#3136)
  • 1948c3d Add boolean as a column name in join (#3121)
  • fe6083e Support nullable timestamps on MySQL (#3100)
  • b15ee3d make unionAll()'s call signature match union() (#3055)
  • e7ed005 Fix queryContext not being passed to raw queries (#3111)
  • 11fdc0c Add missing clearOrder & clearCounters types (#3109)
  • 7ecbcd5 Update changelog and version number (#3108)
  • 5fea86e Update dependencies (#3107)
  • 19926d8 [#3033] fix: sqlite3 drop/renameColumn() breaks with postProcessResponse (#3040)
  • 24fcf27 Fix transaction support for migrations (#3084)
  • de1c934 Include 'string' as accepted Knex constructor type definition (#3105)
  • 0aacab5 Fix for #2998 - Migrator & TypeScript (#3041)
  • fcd21d9 Add command for executing tests on SQLite (#3101)
  • 1da56a3 Update mssql dev dep to v5 stable (#3096)
  • b9a648c Format code (#3088)
  • 0db7859 add test that clearing offset (#2954)
  • f3f0750 Make TS stubs modern (#3080)
  • 68723e0 Update changelog (#3086)
  • 1b39d67 Tests for drop-and-recreate with async/await (#3083)

See the full diff

Package name: minimist The new version differs by 10 commits.

See the full diff

Package name: mkdirp The new version differs by 12 commits.

See the full diff

Package name: nodemon The new version differs by 28 commits.
  • 6a4803d test: skip a test
  • 32aed42 chore: linting errors
  • f6a8b3d chore: update test envs
  • 205ba1b chore: tidy commit lint rules
  • 2af6391 fix: add commit lint
  • 8cf5128 docs: update small formatting issue
  • 0e4b310 Fix: nodemon can't read config files encoded with BOM e.g. UTF-8-BOM #1031
  • fb5da38 feat: nodemonConfig support in package.json
  • 63e8606 fix: exit when fail to parse the config file (#921)
  • facc8cb fix: exit with code 1 on crash if --exitcrash (#946)
  • 481dc8f fix: executable path handling under windows (#962)
  • 3c352f2 fix: support signal on CLI (#1061)
  • abc138f fix: help truncation on node 6.2 (#842) (#843)
  • f6eff97 docs: process.exit() hint (#976)
  • f7d8a2b docs: npx to run dev dependencies (#1071)
  • 9f6a47d docs: updated an error condition in FAQ (#1048)
  • 4c81e9a fix: catch module.parent.filename === undefined (#1053)
  • 1613394 chore: remove io.js references (#1070)
  • 8204b69 chore: update update-notifier (#1083)
  • 5321a2b chore: touch@3.1.0 (#1085)
  • 8ef739a docs: typo (#1059)
  • 3426224 fix: update readme
  • 7b39b45 docs: vertical rhythm (#1055)
  • f9fc962 Delete CNAME

See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:

🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic

The following vulnerabilities are fixed with an upgrade:
- https://snyk.io/vuln/SNYK-JS-MINIMIST-559764
@Saeris Saeris closed this May 17, 2021
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

2 participants