Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We鈥檒l occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Snyk] Security upgrade nodegit from 0.26.3 to 0.27.0 #35

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

iTonyYo
Copy link
Owner

@iTonyYo iTonyYo commented Nov 28, 2023

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • package.json
    • package-lock.json

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
medium severity 646/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 6.5
Prototype Pollution
SNYK-JS-TOUGHCOOKIE-5672873
No Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: nodegit The new version differs by 45 commits.
  • 0327c08 Bump to v0.27.0
  • 7f24632 Merge pull request #1785 from nodegit/node-14
  • e71eea7 Upgrade build environments
  • b7c1259 Merge pull request #1784 from themadtitanmathos/fix/remote-callbacks-pointer-cleanup
  • d5ad62c Remote needs to REALLY persist the callback/proxyOpts/headers
  • 69b010a Use a different folder for ssh test keys
  • 8a59c1c Bump to 0.27.0-alpha.1
  • dcb94e9 Merge pull request #1772 from implausible/get-rid-of-promisify-node
  • 5d008e0 Remove promisify-node and remove old callback api remnants
  • be55439 Merge pull request #1771 from implausible/replace-request-with-got
  • 6398d90 Replace deprecated package request with got
  • 65b4350 Merge pull request #1770 from implausible/bump/openssl
  • c007bb7 Bump OpenSSL prebuilt to 1.1.1c
  • f267826 Merge pull request #1767 from implausible/feature/git_remote_rename
  • dd6aa63 Expose git_remote_rename
  • 1018e32 Merge pull request #1766 from implausible/dedupe-fetch
  • 1507003 Dedupe Remote.prototype.fetch
  • f55a66d Bump to v0.26.5
  • bfb4de0 Merge pull request #1758 from implausible/bump/libgit2-fork
  • adb461e Bring in Libgit2 #5384 to NodeGit
  • 6422810 Use github actions for CI status badge in README.md
  • cf10bce Merge pull request #1509 from tniessen/fix-commit-parent-no-repo-prop
  • 06489c7 Merge pull request #1733 from igncp/update-difflist-to-diff
  • b111960 Merge pull request #1508 from tniessen/repository-remove-unnecessary-assignment

See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
馃 View latest project report

馃洜 Adjust project settings

馃摎 Read more about Snyk's upgrade and patch logic


Learn how to fix vulnerabilities with free interactive lessons:

馃 Prototype Pollution

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

2 participants