Skip to content

[Snyk] Fix for 1 vulnerabilities#83

Open
robdyke wants to merge 1 commit intoremove-custom-frequencyfrom
snyk-fix-00705bf30748706392d882d3cf7c7070
Open

[Snyk] Fix for 1 vulnerabilities#83
robdyke wants to merge 1 commit intoremove-custom-frequencyfrom
snyk-fix-00705bf30748706392d882d3cf7c7070

Conversation

@robdyke
Copy link
Copy Markdown

@robdyke robdyke commented Apr 15, 2024

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • nh_eobs_mobile/static/dev/less/package.json

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
high severity 768/1000
Why? Proof of Concept exploit, Recently disclosed, Has a fix available, CVSS 7.5
Prototype Pollution
SNYK-JS-LODASH-6139239
Yes Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: gulp The new version differs by 243 commits.
  • 55eb23a Release: 4.0.0
  • 173a532 Docs: Fix the installation instructions
  • ec54d09 Docs: Improve note about out-of-date docs
  • 03b7c98 Docs: Update recipes to install gulp@next
  • 2eba29e Docs: Remove run-sequence from recipes
  • 76eb4d6 Docs: Add installation instructions & update badges
  • fbc162f Docs: Remove references to gulp-util
  • 3011cf9 Scaffold: Normalize repository
  • f27be05 Update: Remove graceful-fs from test suite
  • 361ab63 Upgrade: Update glob-watcher
  • 064d100 Build: Avoid broken node 9
  • 057df59 Release: 4.0.0-alpha.3
  • c1ba80c Breaking: Upgrade major versions of glob-watcher, gulp-cli & vinyl-fs
  • 89acc5c Docs: Improve ES2015 task exporting examples (#1999)
  • 0ac9e04 Docs: Add "Project structure" section to CONTRIBUTING.md (#1859)
  • 723cbc4 Docs: Fix syntax in recipe example (#1715)
  • d420a6a Docs: Have gulp.lastRun take a function to avoid task registration (#1828)
  • 29ece6f Upgrade: Update undertaker
  • e931cb0 Docs: Fix changelog typos (#1696)
  • 477db84 Docs: Add a "BrowserSync with Gulp 4" recipe (#1659)
  • d4ed3c7 Docs: Add options.cwd for gulp.src API (#1645)
  • 5dc3b07 Docs: Update gulp.watch API to align with glob-watcher
  • 0c66069 Breaking: Replace chokidar as gulp.watch with glob-watcher wrapper
  • c3dbc10 Docs: Clarify incremental builds example (#1609)

See the full diff

Package name: gulp-less The new version differs by 19 commits.
  • 052aea7 3.2.0
  • c48064c Merge pull request #238 from wolfy1339/less-version-fix
  • c5a391d Updated libraries
  • 6fa258b Make sure we explicitly skip the 2.7.0 release of less
  • 6ebfdeb Merge branch 'master' of github.com:plus3network/gulp-less
  • 772cead 3.1.0
  • 346999e Merge pull request #233 from stevelacy/master
  • a9a1f75 upgrade accord dependency
  • 439d535 Remove recommended css minifier from readme
  • 6daff72 Merge pull request #219 from jkalina/feature/upgrade-less
  • f1bf5cb upgrade less
  • 400f49d Merge pull request #217 from marti1125/master
  • e824ff2 update Minifying CSS gulp plugin
  • 431ce7c Merge pull request #213 from stevelacy/master
  • 299fde6 remove iojs, add node v5
  • ee4f170 update outdated package.json params + add engine version
  • 03b68b8 add package information table
  • 1dfae97 Merge pull request #209 from kennyt/patch-1
  • 591d720 Update README.md

See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Prototype Pollution

@sonarqubecloud
Copy link
Copy Markdown

Quality Gate Passed Quality Gate passed

Issues
0 New issues
0 Accepted issues

Measures
0 Security Hotspots
No data about Coverage
0.0% Duplication on New Code

See analysis details on SonarCloud

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants