Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Snyk] Security upgrade @babel/preset-env from 7.16.11 to 7.22.6 #267

Merged
merged 1 commit into from
Jul 5, 2023

Conversation

lwc
Copy link
Collaborator

@lwc lwc commented Jul 4, 2023

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • validator/imported/package.json
    • validator/imported/package-lock.json

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
medium severity 658/1000
Why? Proof of Concept exploit, Recently disclosed, Has a fix available, CVSS 5.3
Regular Expression Denial of Service (ReDoS)
SNYK-JS-SEMVER-3247795
No Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Regular Expression Denial of Service (ReDoS)

…k.json to reduce vulnerabilities

The following vulnerabilities are fixed with an upgrade:
- https://snyk.io/vuln/SNYK-JS-SEMVER-3247795
@coveralls
Copy link

Coverage Status

coverage: 88.607%. remained the same when pulling 0fdd1c1 on snyk-fix-4467374313a2fc745380bd5b7e7cf8ec into 35199fc on master.

@StevenACoffman StevenACoffman merged commit b8ec355 into master Jul 5, 2023
5 checks passed
@StevenACoffman StevenACoffman deleted the snyk-fix-4467374313a2fc745380bd5b7e7cf8ec branch July 5, 2023 20:05
mergify bot pushed a commit to infratographer/metadata-api that referenced this pull request Aug 16, 2023
[![Mend
Renovate](https://app.renovatebot.com/images/banner.svg)](https://renovatebot.com)

This PR contains the following updates:

| Package | Type | Update | Change |
|---|---|---|---|
|
[github.com/vektah/gqlparser/v2](https://togithub.com/vektah/gqlparser)
| require | patch | `v2.5.6` -> `v2.5.8` |

---

### Release Notes

<details>
<summary>vektah/gqlparser (github.com/vektah/gqlparser/v2)</summary>

###
[`v2.5.8`](https://togithub.com/vektah/gqlparser/releases/tag/v2.5.8)

[Compare
Source](https://togithub.com/vektah/gqlparser/compare/v2.5.7...v2.5.8)

#### What's Changed

- Put comments behind an option in formatter by
[@&#8203;benjaminjkraft](https://togithub.com/benjaminjkraft) in
[vektah/gqlparser#271

**Full Changelog**:
vektah/gqlparser@v2.5.7...v2.5.8

###
[`v2.5.7`](https://togithub.com/vektah/gqlparser/releases/tag/v2.5.7)

[Compare
Source](https://togithub.com/vektah/gqlparser/compare/v2.5.6...v2.5.7)

#### What's Changed

- \[Snyk] Security upgrade
[@&#8203;babel/preset-env](https://togithub.com/babel/preset-env) from
7.16.11 to 7.22.6 by [@&#8203;lwc](https://togithub.com/lwc) in
[vektah/gqlparser#267
- Bump semver from 5.7.1 to 5.7.2 in /validator/imported by
[@&#8203;dependabot](https://togithub.com/dependabot) in
[vektah/gqlparser#268
- Allow ommitting Directive arguments that are non-null if they have
defaults by
[@&#8203;StevenACoffman](https://togithub.com/StevenACoffman) in
[vektah/gqlparser#270

**Full Changelog**:
vektah/gqlparser@v2.5.6...v2.5.7

</details>

---

### Configuration

📅 **Schedule**: Branch creation - At any time (no schedule defined),
Automerge - At any time (no schedule defined).

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Mend
Renovate](https://www.mend.io/free-developer-tools/renovate/). View
repository job log
[here](https://developer.mend.io/github/infratographer/metadata-api).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiIzNS4xNDEuMyIsInVwZGF0ZWRJblZlciI6IjM2LjQzLjIiLCJ0YXJnZXRCcmFuY2giOiJtYWluIn0=-->

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
github-merge-queue bot pushed a commit to infratographer/x that referenced this pull request Aug 21, 2023
[![Mend
Renovate](https://app.renovatebot.com/images/banner.svg)](https://renovatebot.com)

This PR contains the following updates:

| Package | Type | Update | Change |
|---|---|---|---|
|
[github.com/vektah/gqlparser/v2](https://togithub.com/vektah/gqlparser)
| require | patch | `v2.5.6` -> `v2.5.8` |

---

### Release Notes

<details>
<summary>vektah/gqlparser (github.com/vektah/gqlparser/v2)</summary>

###
[`v2.5.8`](https://togithub.com/vektah/gqlparser/releases/tag/v2.5.8)

[Compare
Source](https://togithub.com/vektah/gqlparser/compare/v2.5.7...v2.5.8)

#### What's Changed

- Put comments behind an option in formatter by
[@&#8203;benjaminjkraft](https://togithub.com/benjaminjkraft) in
[vektah/gqlparser#271

**Full Changelog**:
vektah/gqlparser@v2.5.7...v2.5.8

###
[`v2.5.7`](https://togithub.com/vektah/gqlparser/releases/tag/v2.5.7)

[Compare
Source](https://togithub.com/vektah/gqlparser/compare/v2.5.6...v2.5.7)

#### What's Changed

- \[Snyk] Security upgrade
[@&#8203;babel/preset-env](https://togithub.com/babel/preset-env) from
7.16.11 to 7.22.6 by [@&#8203;lwc](https://togithub.com/lwc) in
[vektah/gqlparser#267
- Bump semver from 5.7.1 to 5.7.2 in /validator/imported by
[@&#8203;dependabot](https://togithub.com/dependabot) in
[vektah/gqlparser#268
- Allow ommitting Directive arguments that are non-null if they have
defaults by
[@&#8203;StevenACoffman](https://togithub.com/StevenACoffman) in
[vektah/gqlparser#270

**Full Changelog**:
vektah/gqlparser@v2.5.6...v2.5.7

</details>

---

### Configuration

📅 **Schedule**: Branch creation - At any time (no schedule defined),
Automerge - At any time (no schedule defined).

🚦 **Automerge**: Disabled by config. Please merge this manually once you
are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Mend
Renovate](https://www.mend.io/free-developer-tools/renovate/). View
repository job log
[here](https://developer.mend.io/github/infratographer/x).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiIzNi41LjMiLCJ1cGRhdGVkSW5WZXIiOiIzNi44LjExIiwidGFyZ2V0QnJhbmNoIjoibWFpbiJ9-->

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

4 participants