Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Snyk] Security upgrade serverless-offline from 5.12.1 to 6.0.0 #741

Closed
wants to merge 1 commit into from

Conversation

snyk-bot
Copy link
Contributor

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • packages/service/package.json

Vulnerabilities that will be fixed

With an upgrade:
Severity Issue Breaking Change Exploit Maturity
medium severity Prototype Pollution
SNYK-JS-DOTPROP-543489
Yes Proof of Concept
Commit messages
Package name: serverless-offline The new version differs by 250 commits.

See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:

🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic

@pull-assistant
Copy link

Score: 1.00

Best reviewed: commit by commit


Optimal code review plan

     fix: packages/service/package.json to reduce vulnerabilities

Powered by Pull Assistant. Last update c2f381e ... c2f381e. Read the comment docs.

@codeclimate
Copy link

codeclimate bot commented May 15, 2020

Code Climate has analyzed commit c2f381e and detected 0 issues on this pull request.

The test coverage on the diff in this pull request is 100.0% (50% is the threshold).

This pull request will bring the total coverage in the repository to 95.6% (0.0% change).

View more on Code Climate.

@codecov
Copy link

codecov bot commented May 15, 2020

Codecov Report

Merging #741 into master will not change coverage.
The diff coverage is n/a.

Impacted file tree graph

@@           Coverage Diff           @@
##           master     #741   +/-   ##
=======================================
  Coverage   94.26%   94.26%           
=======================================
  Files         363      363           
  Lines        3729     3729           
  Branches      308      308           
=======================================
  Hits         3515     3515           
  Misses        175      175           
  Partials       39       39           

Continue to review full report at Codecov.

Legend - Click here to learn more
Δ = absolute <relative> (impact), ø = not affected, ? = missing data
Powered by Codecov. Last update 22728d2...c2f381e. Read the comment docs.

@coveralls
Copy link

coveralls commented May 15, 2020

Pull Request Test Coverage Report for Build 4144

  • 0 of 0 changed or added relevant lines in 0 files are covered.
  • No unchanged relevant lines lost coverage.
  • Overall coverage remained the same at 94.529%

Totals Coverage Status
Change from base Build 4138: 0.0%
Covered Lines: 3397
Relevant Lines: 3552

💛 - Coveralls

@randytarampi
Copy link
Owner

Closed by 0ac7763

@randytarampi randytarampi deleted the snyk-fix-28ef71a05b04e754b4a1dbf29b6e168b branch August 2, 2020 19:53
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants