Skip to content

Conversation

@snyk-bot
Copy link

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

merge advice

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • package.json
    • package-lock.json

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
low severity 416/1000
Why? Recently disclosed, Has a fix available, CVSS 2.6
Information Exposure
SNYK-JS-FOLLOWREDIRECTS-2396346
No No Known Exploit

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: github-api The new version differs by 76 commits.
  • c8ab54b 3.4.0
  • 844bf23 Merge pull request #637 from github-tools/fix-broken-tests
  • 606bcc8 Update markdown response.
  • b118395 Fixed auth message.
  • 6027f56 Merge pull request #599 from otaviocx/feature/list-commits-on-pull-request
  • 8a4691f Merge pull request #597 from hazmah0/fix-lint-error
  • c80c0ed Merge pull request #623 from jivthesh/patch-1
  • 61a4fd6 Merge pull request #635 from njlynch/master
  • dfe3df4 chore: update axios due to CVE
  • 3b4b7b0 added code of conduct
  • ba74ee2 test(repository): add specs to test the new listCommitsOnPR function
  • 95fb236 improve(repository): add list commits on pull request function
  • bc36194 test(repository): fixes linting errors
  • 5af1e07 Merge pull request #588 from hazmah0/fix-repo-write-file
  • 0234b39 test(repository): updates test to use promise instead of callback
  • d89a0b0 Merge pull request #574 from github-tools/j-rewerts-test-info
  • a8b9f62 Fixed test user name.
  • eb2b4f3 fix(repository): prevents lib from crashing when not providing optional arguments
  • 29c3c7a Merge pull request #582 from tamer1an/patch-1
  • e807fc3 regexp compatible with both: ?page=, &page=
  • 172979f RegExp Fix for _requestAllPages
  • 4fccb10 Updated version to 3.3.0.
  • 3bb02d6 Fixed lint.
  • 598d2c7 Merge pull request #580 from bfeldkamp3/master

See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic

@atomist atomist bot added auto-branch-delete:on-close Delete branch when pull request gets closed auto-merge-method:merge Auto-merge with merge commit auto-merge:on-bpr-success Auto-merge on passed branch protection rule labels Feb 10, 2022
[atomist:generated]
[atomist-skill:atomist/npm-vulnerability-scanner-skill]
Dependencies

* @types/classnames > 2.3.1
* @types/node > 8.10.66
* @types/qs > 6.9.7
* @types/react > 16.14.23
* @types/react-dom > 16.9.14
* classnames > 2.3.1
* qs > 6.10.3
* react > 16.14.0
* react-dom > 16.14.0

Development Dependencies

* ts-loader > 5.4.5
* typescript > 3.9.10
* webpack > 4.46.0
* webpack-cli > 3.3.12
* webpack-dev-server > 3.11.3

[atomist:generated]
[atomist-skill:atomist/npm-vulnerability-scanner-skill]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

auto-branch-delete:on-close Delete branch when pull request gets closed auto-merge:on-bpr-success Auto-merge on passed branch protection rule auto-merge-method:merge Auto-merge with merge commit

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants