Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Snyk] Upgrade nodegit from 0.4.1 to 0.26.4 #1

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

snyk-bot
Copy link

Snyk has created this PR to upgrade nodegit from 0.4.1 to 0.26.4.

ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.
  • The recommended version is 78 versions ahead of your current version.
  • The recommended version was released a month ago, on 2020-01-14.

The recommended version fixes:

Severity Issue Exploit Maturity
Arbitrary File Write
SNYK-JS-NPM-537606
Proof of Concept
Arbitrary File Overwrite
SNYK-JS-NPM-537603
Proof of Concept
Improper Link Resolution Before File Access
SNYK-JS-NODEGIT-542723
Mature
Improper Handling of Alternate Data Stream
SNYK-JS-NODEGIT-542722
No Known Exploit
Improper Handling of Alternate Data Stream
SNYK-JS-NODEGIT-542721
Mature
Directory Traversal
SNYK-JS-NODEGIT-542720
No Known Exploit
Time of Check Time of Use (TOCTOU)
npm:chownr:20180731
No Known Exploit
Access Restriction Bypass
npm:npm:20180222
No Known Exploit
Unauthorized File Access
SNYK-JS-NPM-537604
Proof of Concept
Release notes
Package name: nodegit from nodegit GitHub release notes
Commit messages
Package name: nodegit
  • 8ad3e37 Bump to v0.26.4
  • f3a66d6 Merge pull request #1751 from implausible/fixup/template-input-data
  • 59437a8 Fix some issues from the libgit2 bump
  • 24a9fc4 Merge pull request #1748 from ianhattendorf/feature/longpaths
  • a4fe703 Merge pull request #1749 from implausible/patch/libssh2
  • b22ae75 Remove appveyor.yml and .travis.yml
  • 2a79ce9 Default option return value to undefined
  • 8ae2436 Longpaths options should take/return boolean values
  • fcdb122 Bring in libssh2#402
  • e4e66f4 Add longpath options to NodeGit.Libgit2.OPT
  • 22d94f1 Format opts.cc
  • 743b7a9 Remove unused libgit2 files
  • 80698b4 Update to latest libgit2 master
  • ef0c27c Expose git_libgit2_opts
  • 0598d40 Merge in libgit2 longpaths PR
  • ec694ba Update libgit2 to latest master
  • 7bd5a8c Merge pull request #1730 from implausible/fix/timing-bug-in-generate
  • bdae091 Fix workflow for node 8 npm issue
  • 0de3294 Bump to v0.26.3
  • 36856a1 Merge pull request #1743 from implausible/security-fixes
  • b5769a2 Bring in security patches from libgit2
  • ce6f816 Wait for copy and remove promises to finish
  • 1047f66 Bupm to v0.26.2
  • 0683f2b Update README.md for inactive maintainers

Compare


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

🧐 View latest project report

🛠 Adjust upgrade PR settings

🔕 Ignore this dependency or unsubscribe from future upgrade PRs

[//]: # (snyk:metadata:{"dependencies":[{"name":"nodegit","from":"0.4.1","to":"0.26.4"}],"packageManager":"npm","type":"auto","projectUrl":"https://app.snyk.io/org/saurabharch/project/26898d8a-35aa-4227-8b51-13786273a2ea?utm_source=github&utm_medium=upgrade-pr","projectPublicId":"26898d8a-35aa-4227-8b51-13786273a2ea","env":"prod","prType":"upgrade","vulns":["SNYK-JS-NPM-537606","SNYK-JS-NPM-537603","SNYK-JS-NODEGIT-542723","SNYK-JS-NODEGIT-542722","SNYK-JS-NODEGIT-542721","SNYK-JS-NODEGIT-542720","npm:chownr:20180731","npm:npm:20180222","SNYK-JS-NPM-537604"],"issuesToFix":[{"issueId":"SNYK-JS-NPM-537606","severity":"high","title":"Arbitrary File Write","exploitMaturity":"proof-of-concept"},{"issueId":"SNYK-JS-NPM-537603","severity":"high","title":"Arbitrary File Overwrite","exploitMaturity":"proof-of-concept"},{"issueId":"SNYK-JS-NODEGIT-542723","severity":"high","title":"Improper Link Resolution Before File Access","exploitMaturity":"mature"},{"issueId":"SNYK-JS-NODEGIT-542722","severity":"high","title":"Improper Handling of Alternate Data Stream","exploitMaturity":"no-known-exploit"},{"issueId":"SNYK-JS-NODEGIT-542721","severity":"high","title":"Improper Handling of Alternate Data Stream","exploitMaturity":"mature"},{"issueId":"SNYK-JS-NODEGIT-542720","severity":"high","title":"Directory Traversal","exploitMaturity":"no-known-exploit"},{"issueId":"npm:chownr:20180731","severity":"medium","title":"Time of Check Time of Use (TOCTOU)","exploitMaturity":"no-known-exploit"},{"issueId":"npm:npm:20180222","severity":"medium","title":"Access Restriction Bypass","exploitMaturity":"no-known-exploit"},{"issueId":"SNYK-JS-NPM-537604","severity":"low","title":"Unauthorized File Access","exploitMaturity":"proof-of-concept"}],"upgrade":["SNYK-JS-NPM-537606","SNYK-JS-NPM-537603","SNYK-JS-NODEGIT-542723","SNYK-JS-NODEGIT-542722","SNYK-JS-NODEGIT-542721","SNYK-JS-NODEGIT-542720","npm:chownr:20180731","npm:npm:20180222","SNYK-JS-NPM-537604"],"upgradeInfo":{"versionsDiff":78,"publishedDate":"2020-01-14T19:23:53.762Z"},"templateVariants":[],"hasFixes":true,"isMajorUpgrade":false,"isBreakingChange":false})

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant