Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Snyk] Upgrade: , , , babel-jest, jest, chalk, yaml, fs-extra, json5, glob, change-case, commander, docsify, eslint, eslint-plugin-jest, husky, jsdoc-to-markdown, json5-jest, jsonc-parser, less, lint-staged, node-sass, stylus, tinycolor2, tsd #164

Open
wants to merge 1 commit into
base: main
Choose a base branch
from

Conversation

WontonSam
Copy link
Owner

snyk-top-banner

Snyk has created this PR to upgrade multiple dependencies.

👯 The following dependencies are linked and will therefore be updated together.

ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.

⚠️ Warning: This PR contains major version upgrade(s), and may be a breaking change.

Name Versions Released on

@babel/preset-env
from 7.16.11 to 7.25.4 | 50 versions ahead of your current version | 23 days ago
on 2024-08-22
@commitlint/cli
from 16.1.0 to 19.4.0 | 52 versions ahead of your current version
⚠️ This is a major version upgrade, and may be a breaking change | a month ago
on 2024-08-07
@commitlint/config-conventional
from 16.0.0 to 19.2.2 | 36 versions ahead of your current version
⚠️ This is a major version upgrade, and may be a breaking change | 5 months ago
on 2024-04-14
babel-jest
from 27.4.6 to 29.7.0 | 50 versions ahead of your current version
⚠️ This is a major version upgrade, and may be a breaking change | a year ago
on 2023-09-12
jest
from 27.4.7 to 29.7.0 | 51 versions ahead of your current version
⚠️ This is a major version upgrade, and may be a breaking change | a year ago
on 2023-09-12
chalk
from 4.1.2 to 5.3.0 | 7 versions ahead of your current version
⚠️ This is a major version upgrade, and may be a breaking change | a year ago
on 2023-06-29
yaml
from 1.10.2 to 2.5.0 | 39 versions ahead of your current version
⚠️ This is a major version upgrade, and may be a breaking change | 2 months ago
on 2024-07-24
fs-extra
from 10.0.0 to 11.2.0 | 6 versions ahead of your current version
⚠️ This is a major version upgrade, and may be a breaking change | 10 months ago
on 2023-11-28
json5
from 2.2.2 to 2.2.3 | 1 version ahead of your current version | 2 years ago
on 2022-12-31
glob
from 7.2.0 to 11.0.0 | 54 versions ahead of your current version
⚠️ This is a major version upgrade, and may be a breaking change | 2 months ago
on 2024-07-08
change-case
from 4.1.2 to 5.4.4 | 13 versions ahead of your current version
⚠️ This is a major version upgrade, and may be a breaking change | 5 months ago
on 2024-04-03
commander
from 8.3.0 to 12.1.0 | 17 versions ahead of your current version
⚠️ This is a major version upgrade, and may be a breaking change | 4 months ago
on 2024-05-18
docsify
from 4.12.2 to 4.13.1 | 3 versions ahead of your current version | a year ago
on 2023-06-24
eslint
from 8.7.0 to 9.9.1 | 70 versions ahead of your current version
⚠️ This is a major version upgrade, and may be a breaking change | 22 days ago
on 2024-08-23
eslint-plugin-jest
from 26.0.0 to 28.8.0 | 85 versions ahead of your current version
⚠️ This is a major version upgrade, and may be a breaking change | a month ago
on 2024-08-07
husky
from 7.0.4 to 9.1.5 | 21 versions ahead of your current version
⚠️ This is a major version upgrade, and may be a breaking change | 25 days ago
on 2024-08-20
jsdoc-to-markdown
from 7.1.0 to 8.0.3 | 5 versions ahead of your current version
⚠️ This is a major version upgrade, and may be a breaking change | 2 months ago
on 2024-07-24
json5-jest
from 1.0.1 to 2.0.0 | 1 version ahead of your current version
⚠️ This is a major version upgrade, and may be a breaking change | a year ago
on 2023-06-14
jsonc-parser
from 3.0.0 to 3.3.1 | 5 versions ahead of your current version | 3 months ago
on 2024-06-24
less
from 4.1.2 to 4.2.0 | 2 versions ahead of your current version | a year ago
on 2023-08-05
lint-staged
from 12.3.1 to 15.2.9 | 42 versions ahead of your current version
⚠️ This is a major version upgrade, and may be a breaking change | a month ago
on 2024-08-13
node-sass
from 7.0.3 to 9.0.0 | 2 versions ahead of your current version
⚠️ This is a major version upgrade, and may be a breaking change | a year ago
on 2023-05-20
stylus
from 0.56.0 to 0.63.0 | 8 versions ahead of your current version | 6 months ago
on 2024-03-05
tinycolor2
from 1.4.2 to 1.6.0 | 13 versions ahead of your current version | 2 years ago
on 2023-02-03
tsd
from 0.19.1 to 0.31.1 | 23 versions ahead of your current version | 3 months ago
on 2024-06-17

Issues fixed by the recommended upgrade:

Issue Score Exploit Maturity
medium severity Prototype Pollution
SNYK-JS-JSON5-3182856
178 Proof of Concept
critical severity Incomplete List of Disallowed Inputs
SNYK-JS-BABELTRAVERSE-5962462
178 Proof of Concept
high severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-SEMVER-3247795
178 Proof of Concept
high severity Internal Property Tampering
SNYK-JS-TAFFYDB-2992450
178 Proof of Concept
high severity Denial of Service (DoS)
SNYK-JS-WS-7266574
178 Proof of Concept
high severity Infinite loop
SNYK-JS-MARKDOWNIT-6483324
178 Proof of Concept
high severity Inefficient Regular Expression Complexity
SNYK-JS-MICROMATCH-6838728
178 No Known Exploit
high severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-SEMVER-3247795
178 Proof of Concept
high severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-SEMVER-3247795
178 Proof of Concept
high severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-SEMVER-3247795
178 Proof of Concept
high severity Uncontrolled resource consumption
SNYK-JS-BRACES-6838727
178 Proof of Concept
high severity Server-side Request Forgery (SSRF)
SNYK-JS-IP-6240864
178 Proof of Concept
medium severity Uncontrolled Resource Consumption ('Resource Exhaustion')
SNYK-JS-TAR-6476909
178 Proof of Concept
medium severity Prototype Pollution
SNYK-JS-TOUGHCOOKIE-5672873
178 Proof of Concept
medium severity Prototype Pollution
SNYK-JS-TOUGHCOOKIE-5672873
178 Proof of Concept
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-UGLIFYJS-1727251
178 No Known Exploit
medium severity Denial of Service (DoS)
SNYK-JS-NWSAPI-2841516
178 No Known Exploit
medium severity Server-side Request Forgery (SSRF)
SNYK-JS-REQUEST-3361831
178 Proof of Concept
medium severity Template Injection
SNYK-JS-DOMPURIFY-6474511
178 Proof of Concept
medium severity Server-Side Request Forgery (SSRF)
SNYK-JS-IP-7148531
178 Proof of Concept
low severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-WORDWRAP-3149973
178 Proof of Concept
Release notes
Package name: @babel/preset-env
  • 7.25.4 - 2024-08-22

    v7.25.4 (2024-08-22)

    🐛 Bug Fix

    💅 Polish

    • babel-generator, babel-plugin-proposal-decorators, babel-plugin-proposal-destructuring-private, babel-plugin-proposal-pipeline-operator, babel-plugin-transform-class-properties, babel-plugin-transform-destructuring, babel-plugin-transform-optional-chaining, babel-plugin-transform-private-methods, babel-plugin-transform-private-property-in-object, babel-plugin-transform-typescript, babel-runtime-corejs2, babel-runtime, babel-traverse
    • babel-generator, babel-plugin-transform-class-properties
    • babel-generator, babel-plugin-proposal-decorators, babel-plugin-proposal-destructuring-private, babel-plugin-transform-object-rest-spread

    🔬 Output optimization

    Committers: 4

  • 7.25.3 - 2024-07-31

    v7.25.3 (2024-07-31)

    🐛 Bug Fix

    • babel-plugin-bugfix-firefox-class-in-computed-class-key, babel-traverse

    🏠 Internal

    Committers: 2

  • 7.25.2 - 2024-07-30

    v7.25.2 (2024-07-30)

    🐛 Bug Fix

    • babel-core, babel-traverse

    Committers: 2

  • 7.25.0 - 2024-07-26

    v7.25.0 (2024-07-26)

    Thanks @ davidtaylorhq and @ slatereax for your first PR!

    You can find the release blog post with some highlights at https://babeljs.io/blog/2024/07/26/7.25.0.

    👓 Spec Compliance

    • babel-helpers, babel-plugin-proposal-explicit-resource-management, babel-runtime-corejs3
    • babel-plugin-transform-typescript
      • #16602 Ensure enum members syntactically determinable to be strings do not get reverse mappings (@ liuxingbaoyu)

    🚀 New Feature

    • babel-helper-create-class-features-plugin, babel-helper-function-name, babel-helper-plugin-utils, babel-helper-wrap-function, babel-plugin-bugfix-safari-class-field-initializer-scope, babel-plugin-bugfix-safari-id-destructuring-collision-in-function-expression, babel-plugin-transform-classes, babel-plugin-transform-function-name, babel-preset-env, babel-traverse, babel-types
    • babel-helper-hoist-variables, babel-helper-plugin-utils, babel-plugin-proposal-async-do-expressions, babel-plugin-transform-modules-systemjs, babel-traverse
    • babel-helper-create-class-features-plugin, babel-helper-module-transforms, babel-helper-plugin-utils, babel-helper-split-export-declaration, babel-plugin-transform-classes, babel-traverse, babel-types
    • babel-helper-create-class-features-plugin, babel-helper-environment-visitor, babel-helper-module-transforms, babel-helper-plugin-utils, babel-helper-remap-async-to-generator, babel-helper-replace-supers, babel-plugin-bugfix-firefox-class-in-computed-class-key, babel-plugin-bugfix-v8-static-class-fields-redefine-readonly, babel-plugin-transform-async-generator-functions, babel-plugin-transform-classes, babel-traverse
    • babel-core, babel-parser
    • babel-compat-data, babel-plugin-bugfix-safari-class-field-initializer-scope, babel-preset-env
    • babel-plugin-transform-block-scoping, babel-traverse, babel-types
    • babel-helper-import-to-platform-api, babel-plugin-proposal-json-modules
    • babel-helper-transform-fixture-test-runner, babel-node
    • babel-compat-data, babel-helper-create-regexp-features-plugin, babel-plugin-proposal-duplicate-named-capturing-groups-regex, babel-plugin-transform-duplicate-named-capturing-groups-regex, babel-preset-env, babel-standalone
      • #16445 Add duplicate-named-capturing-groups-regex to preset-env (@ JLHwung)

    🐛 Bug Fix

    🏠 Internal

    • Other
    • babel-generator
    • babel-helper-function-name, babel-plugin-transform-arrow-functions, babel-plugin-transform-function-name, babel-preset-env, babel-traverse

    🏃‍♀️ Performance

    • babel-parser, babel-plugin-proposal-pipeline-operator

    🔬 Output optimization

    • babel-plugin-transform-classes
    • babel-helper-create-class-features-plugin, babel-helper-replace-supers, babel-helpers, babel-plugin-proposal-decorators, babel-plugin-transform-class-properties, babel-plugin-transform-classes, babel-plugin-transform-exponentiation-operator, babel-plugin-transform-object-super, babel-plugin-transform-private-methods, babel-runtime-corejs2, babel-runtime-corejs3, babel-runtime
    • babel-plugin-transform-class-properties, babel-plugin-transform-classes

    Committers: 6

  • 7.24.8 - 2024-07-11
  • 7.24.7 - 2024-06-05
  • 7.24.6 - 2024-05-24
  • 7.24.5 - 2024-04-29
  • 7.24.4 - 2024-04-03
  • 7.24.3 - 2024-03-20
  • 7.24.1 - 2024-03-19
  • 7.24.0 - 2024-02-28
  • 7.23.9 - 2024-01-25
  • 7.23.8 - 2024-01-08
  • 7.23.7 - 2023-12-29
  • 7.23.6 - 2023-12-11
  • 7.23.5 - 2023-11-29
  • 7.23.3 - 2023-11-09
  • 7.23.2 - 2023-10-11
  • 7.22.20 - 2023-09-16
  • 7.22.15 - 2023-09-04
  • 7.22.14 - 2023-08-30
  • 7.22.10 - 2023-08-07
  • 7.22.9 - 2023-07-12
  • 7.22.7 - 2023-07-06
  • 7.22.6 - 2023-07-04
  • 7.22.5 - 2023-06-08
  • 7.22.4 - 2023-05-29
  • 7.22.2 - 2023-05-26
  • 7.22.1 - 2023-05-26
  • 7.22.0 - 2023-05-26
  • 7.21.5 - 2023-04-28
  • 7.21.4 - 2023-03-31
  • 7.21.4-esm.4 - 2023-04-04
  • 7.21.4-esm.3 - 2023-04-04
  • 7.21.4-esm.2 - 2023-04-04
  • 7.21.4-esm.1 - 2023-04-04
  • 7.21.4-esm - 2023-04-04
  • 7.20.2 - 2022-11-04
  • 7.19.4 - 2022-10-10
  • 7.19.3 - 2022-09-27
  • 7.19.1 - 2022-09-14
  • 7.19.0 - 2022-09-05
  • 7.18.10 - 2022-08-01
  • 7.18.9 - 2022-07-18
  • 7.18.6 - 2022-06-27
  • 7.18.2 - 2022-05-25
  • 7.18.0 - 2022-05-19
  • 7.17.12 - 2022-05-16
  • 7.17.10 - 2022-04-29
  • 7.16.11 - 2022-01-20
from @babel/preset-env GitHub release notes
Package name: @commitlint/cli

Snyk has created this PR to upgrade:
  - @babel/preset-env from 7.16.11 to 7.25.4.
    See this package in npm: https://www.npmjs.com/package/@babel/preset-env
  - @commitlint/cli from 16.1.0 to 19.4.0.
    See this package in npm: https://www.npmjs.com/package/@commitlint/cli
  - @commitlint/config-conventional from 16.0.0 to 19.2.2.
    See this package in npm: https://www.npmjs.com/package/@commitlint/config-conventional
  - babel-jest from 27.4.6 to 29.7.0.
    See this package in npm: https://www.npmjs.com/package/babel-jest
  - jest from 27.4.7 to 29.7.0.
    See this package in npm: https://www.npmjs.com/package/jest
  - chalk from 4.1.2 to 5.3.0.
    See this package in npm: https://www.npmjs.com/package/chalk
  - yaml from 1.10.2 to 2.5.0.
    See this package in npm: https://www.npmjs.com/package/yaml
  - fs-extra from 10.0.0 to 11.2.0.
    See this package in npm: https://www.npmjs.com/package/fs-extra
  - json5 from 2.2.2 to 2.2.3.
    See this package in npm: https://www.npmjs.com/package/json5
  - glob from 7.2.0 to 11.0.0.
    See this package in npm: https://www.npmjs.com/package/glob
  - change-case from 4.1.2 to 5.4.4.
    See this package in npm: https://www.npmjs.com/package/change-case
  - commander from 8.3.0 to 12.1.0.
    See this package in npm: https://www.npmjs.com/package/commander
  - docsify from 4.12.2 to 4.13.1.
    See this package in npm: https://www.npmjs.com/package/docsify
  - eslint from 8.7.0 to 9.9.1.
    See this package in npm: https://www.npmjs.com/package/eslint
  - eslint-plugin-jest from 26.0.0 to 28.8.0.
    See this package in npm: https://www.npmjs.com/package/eslint-plugin-jest
  - husky from 7.0.4 to 9.1.5.
    See this package in npm: https://www.npmjs.com/package/husky
  - jsdoc-to-markdown from 7.1.0 to 8.0.3.
    See this package in npm: https://www.npmjs.com/package/jsdoc-to-markdown
  - json5-jest from 1.0.1 to 2.0.0.
    See this package in npm: https://www.npmjs.com/package/json5-jest
  - jsonc-parser from 3.0.0 to 3.3.1.
    See this package in npm: https://www.npmjs.com/package/jsonc-parser
  - less from 4.1.2 to 4.2.0.
    See this package in npm: https://www.npmjs.com/package/less
  - lint-staged from 12.3.1 to 15.2.9.
    See this package in npm: https://www.npmjs.com/package/lint-staged
  - node-sass from 7.0.3 to 9.0.0.
    See this package in npm: https://www.npmjs.com/package/node-sass
  - stylus from 0.56.0 to 0.63.0.
    See this package in npm: https://www.npmjs.com/package/stylus
  - tinycolor2 from 1.4.2 to 1.6.0.
    See this package in npm: https://www.npmjs.com/package/tinycolor2
  - tsd from 0.19.1 to 0.31.1.
    See this package in npm: https://www.npmjs.com/package/tsd

See this project in Snyk:
https://app.snyk.io/org/cachiman/project/0fd54fa7-a7da-4e91-a897-5c71f12df1f4?utm_source=github&utm_medium=referral&page=upgrade-pr
Copy link

google-cla bot commented Sep 14, 2024

Thanks for your pull request! It looks like this may be your first contribution to a Google open source project. Before we can look at your pull request, you'll need to sign a Contributor License Agreement (CLA).

View this failed invocation of the CLA check for more information.

For the most up to date status, view the checks section at the bottom of the pull request.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants