Skip to content

[Snyk] Fix for 5 vulnerabilities#24

Open
enterstudio wants to merge 1 commit intomasterfrom
snyk-fix-1506006781b4fdf3c5c35251d24b7399
Open

[Snyk] Fix for 5 vulnerabilities#24
enterstudio wants to merge 1 commit intomasterfrom
snyk-fix-1506006781b4fdf3c5c35251d24b7399

Conversation

@enterstudio
Copy link
Owner

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • package.json

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
high severity 589/1000
Why? Has a fix available, CVSS 7.5
Denial of Service (DoS)
SNYK-JS-AMMO-548920
Yes No Known Exploit
medium severity 586/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 5.3
Regular Expression Denial of Service (ReDoS)
SNYK-JS-CSSWHAT-3035488
No Proof of Concept
medium severity 479/1000
Why? Has a fix available, CVSS 5.3
Regular Expression Denial of Service (ReDoS)
npm:content:20170908
Yes No Known Exploit
high severity 696/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
Regular Expression Denial of Service (ReDoS)
npm:content:20180305
Yes Proof of Concept
medium severity 636/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 6.3
Prototype Pollution
npm:hoek:20180212
Yes Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: cheerio The new version differs by 56 commits.
  • c3ec1cd Release 0.20.0
  • ef848ca Add coveralls badge, remove link to old report
  • dbcbe90 Merge pull request #808 from leifhanack/lodash4
  • c04ead1 Merge pull request #668 from rwaldin/prop-method
  • b5531bb Merge pull request #671 from twolfson/dev/fallback.select.content.sqwished
  • 9d98bd7 Merge pull request #704 from Rycochet/master
  • 1b9c5c9 Merge pull request #797 from Delgan/641-appendTo_prependTo
  • b12cbe8 Update lodash dependeny to 4.1.0
  • 8c9b2e0 Merge pull request #796 from Delgan/fix_780
  • b09db31 Fix PR #726 adding 'appendTo()' and 'prependTo()'
  • ce8829d Added appendTo and prependTo with tests #641
  • 4779762 Fix #780 by changing options context in '.find()'
  • 8dc1cc9 Add an unit test checking the query of child
  • b27bed6 fix #667: attr({foo: null}) removes attribute foo, like attr('foo', null)
  • 70c5608 Include reference to dedicated "Loading" section
  • fa70a84 Added load method to $
  • 4e8483a update css-select to 1.2.0
  • 5f2777a Merge pull request #732 from jugglinmike/reinstate-toarray
  • 106e42a Merge pull request #776 from dYale/master
  • 97149d3 Fixing Grammatical Error
  • a1367ee Merge pull request #739 from TrySound/npm-files
  • 6c73b7a Merge pull request #773 from JaKXz/patch-1
  • 48bb22d Test against node v0.12 --> v4.2
  • ec2414d Correct output in example

See the full diff

Package name: hapi The new version differs by 236 commits.
  • c4593b6 deps. Closes #2897. Closes #2898. Closes #2899. Closes #2900. Closes #2901. Closes #2902. Closes #2903. Closes #2904. Closes #2905. Closes #2906. Closes #2907. Closes #2908. Closes #2909. Closes #2910. Closes #2911. Closes #2912. Closes #2913. Closes #2914. Closes #2915. Closes #2916. Closes #2917. Closes #2918. Closes #2919. Closes #2920. Closes #2921. Closes #2922. Closes #2923
  • ca4320e Merge pull request #2891 from nlindley/payload-test-typo
  • 02b6ac7 Fix typo in payload test
  • e5da51c Merge branch 'master' of github.com:hapijs/hapi
  • 5a0dc49 Remove compount assignments
  • 375fe30 Merge pull request #2888 from cjihrig/master
  • 05f6a26 style fixes
  • 635089b Merge pull request #2887 from gergoerdosi/node-5
  • 86102c7 Test on node v5
  • fc503f8 lab 7
  • fdf7ed3 Merge pull request #2885 from gergoerdosi/subtext
  • 0cb9143 Update hapijs/subtext to 2.0.2 from 2.0.1
  • d3a6cf8 typo
  • 47373dd Remove bluebird. Closes #2881
  • 98d3404 Skip most lifecycle on not found and bad path. Closes #2867
  • 7041325 CORS error cases. Closes #2868
  • 1696838 Replace function with arrow. Closes #2877
  • 2aedf38 Merge branch 'master' of github.com:hapijs/hapi
  • ca3ee7e Additional => conversions. For #2877
  • 1ef09e8 Merge pull request #2876 from sfabriece/patch-1
  • a7b3ad7 Initial transition to arrow functions. For #2877
  • 7ec0ae3 Update API.md
  • 32cf03c for style change. Closes #2875
  • 38f90bb Replace var with let. Closes #2874

See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Denial of Service (DoS)
🦉 Prototype Pollution

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants