Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Snyk] Upgrade semantic-release from 17.1.1 to 17.1.2 #50

Merged
merged 1 commit into from Sep 22, 2020

Conversation

snyk-bot
Copy link
Contributor

Snyk has created this PR to upgrade semantic-release from 17.1.1 to 17.1.2.

merge advice
ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


  • The recommended version is 1 version ahead of your current version.
  • The recommended version was released a day ago, on 2020-09-17.

The recommended version fixes:

Severity Issue PriorityScore (*) Exploit Maturity
Prototype Pollution
SNYK-JS-DOTPROP-543489
422/1000
Why? Proof of Concept exploit, CVSS 6.3
Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Release notes
Package name: semantic-release from semantic-release GitHub release notes
Commit messages
Package name: semantic-release
  • b4c5d0a fix: add logging for when ssh falls back to http (#1639)
  • c982249 docs(contributing): typo fix (#1638)
  • 9635f50 docs: improve github actions recipe on git plugin (#1626)
  • d036a89 ci(docs): use actions/checkout@v2 (#1620)
  • 9303d1d docs(resources.md): added more sematnic release article (#1610)
  • b72cdb3 docs(configuration.md): Updated documentation for dry-run feature of semantic Release (#1607)
  • ee44ee8 docs(github-actions): suggest action_dispatch as trigger (#1605)
  • b24d247 docs: add `semantic-release-rubygem` to community plugins (#1602)
  • 6d118c6 docs: be clear about what module of semantic-release handles updating the package.json (#1601)
  • b5c9dea docs: update github documentation to `docs.github.com`
  • 1405b94 docs: added recipe for Jenkins CI configuration (Add support for custom localization schemes #1) (#1591)

Compare


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

🧐 View latest project report

🛠 Adjust upgrade PR settings

🔕 Ignore this dependency or unsubscribe from future upgrade PRs

@pull-assistant
Copy link

Score: 1.00

Best reviewed: commit by commit


Optimal code review plan

     fix: upgrade semantic-release from 17.1.1 to 17.1.2

Powered by Pull Assistant. Last update 2fc5a3d ... 2fc5a3d. Read the comment docs.

@codeclimate
Copy link

codeclimate bot commented Sep 19, 2020

Code Climate has analyzed commit 2fc5a3d and detected 0 issues on this pull request.

The test coverage on the diff in this pull request is 100.0% (50% is the threshold).

This pull request will bring the total coverage in the repository to 100.0%.

View more on Code Climate.

@codecov
Copy link

codecov bot commented Sep 19, 2020

Codecov Report

Merging #50 into master will not change coverage.
The diff coverage is n/a.

Impacted file tree graph

@@            Coverage Diff            @@
##            master       #50   +/-   ##
=========================================
  Coverage   100.00%   100.00%           
=========================================
  Files            2         2           
  Lines           68        68           
=========================================
  Hits            68        68           

Continue to review full report at Codecov.

Legend - Click here to learn more
Δ = absolute <relative> (impact), ø = not affected, ? = missing data
Powered by Codecov. Last update a2b1da7...2fc5a3d. Read the comment docs.

@randytarampi randytarampi merged commit b037ba2 into master Sep 22, 2020
@randytarampi randytarampi deleted the snyk-upgrade-c594085ad19094290b41ed9ce4000315 branch September 22, 2020 18:50
@randytarampi
Copy link
Owner

🎉 This PR is included in version 2.13.8 🎉

The release is available on:

Your semantic-release bot 📦🚀

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

2 participants