-
Notifications
You must be signed in to change notification settings - Fork 1
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[Snyk] Upgrade uglify-js from 3.4.7 to 3.13.4 #39
Conversation
Snyk has created this PR to upgrade uglify-js from 3.4.7 to 3.13.4. See this package in npm: https://www.npmjs.com/package/uglify-js See this project in Snyk: https://app.snyk.io/org/kadirselcuk/project/28ac5072-f66b-4183-bbda-99b4324cbf96?utm_source=github&utm_medium=upgrade-pr
Thanks for your submission. It appears that you've created a pull request using one of our repository's branches. Since this is Thanks again! |
*Ruff* 🐶 I wasn't able to find any Docker Compose files in your repository at any of the given paths in the Files checked:
What is this?Pull Dog is a GitHub app that makes test environments for your pull requests using Docker, from a Visit our website to learn more. Commands
TroubleshootingNeed help? Don't hesitate to file an issue in our repository Configuration {
"isLazy": false,
"dockerComposeYmlFilePaths": [
"docker-compose.yml"
],
"expiry": "00:00:00",
"conversationMode": "singleComment"
} Trace ID |
Mode: paranoid | Total findings: 118 | Considered vulnerability: 0 Hard-Coded Secrets (2)
More info on how to fix Hard-Coded Secrets in General. Insecure File Management (41)
More info on how to fix Insecure File Management in JavaScript and PHP. Insecure Use of Regular Expressions (48)
More info on how to fix Insecure Use of Regular Expressions in JavaScript. Insecure Use of Dangerous Function (2)
More info on how to fix Insecure Use of Dangerous Function in JavaScript. Information Disclosure (1)
More info on how to fix Information Disclosure in JavaScript. Vulnerable Libraries (1)
More info on how to fix Vulnerable Libraries in JavaScript. Insecure Processing of Data (21)
More info on how to fix Insecure Processing of Data in PHP. Insecure Use of Language/Framework API (1)
More info on how to fix Insecure Use of Language/Framework API in PHP. Insecure Use of Crypto (1)
More info on how to fix Insecure Use of Crypto in PHP. 👉 Go to the dashboard for detailed results. 📥 Happy? Share your feedback with us. |
Snyk has created this PR to upgrade uglify-js from 3.4.7 to 3.13.4.
ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.
Release notes
Package name: uglify-js
Features
class
definition (aed758e)class
field and method (10fbf8e)Bug Fixes
class
literal (1947a21)for
loop (a37ca55)import.meta
(cf38b52)try
statement (ca49f6f)Features
Bug Fixes
function
literal (39df3a1)class
field (03c5ecb)Features
__PURE__
through newannotations
option (3b5d501)class
names viakeep_fnames
(997d09b)beautify
(7d595e2)import/export { foo as foo };
➡️import/export { foo };
(2411132)var f = async function*() { ... };
➡️async function* f() { ... }
(b244b4e)Bug Fixes
arguments
object (9faee3b)async
function (c36c3cb)BigInt
literal (3016a78)delete
operator (48c46fa, 2508481)export
statement (6f3ab09, b872ffe)new.target
(352a944, 2508481)super
keyword (77c9116)var
statement (9a95430)Commit messages
Package name: uglify-js
Compare
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.
For more information:
🧐 View latest project report
🛠 Adjust upgrade PR settings
🔕 Ignore this dependency or unsubscribe from future upgrade PRs