Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Snyk] Security upgrade @snyk/code-client from 4.5.0 to 4.12.0 #36

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

snyk-bot
Copy link

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • package.json
    • package-lock.json

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
high severity 768/1000
Why? Proof of Concept exploit, Recently disclosed, Has a fix available, CVSS 7.5
Uncaught Exception
SNYK-JS-YAML-5458867
No Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: @snyk/code-client The new version differs by 32 commits.
  • 6856859 Merge pull request #147 from snyk/snyk-upgrade-126758f4625640472308672ae22c9f75
  • 66c7314 feat: upgrade yaml from 1.10.2 to 2.0.1
  • 9363d10 Merge pull request #145 from snyk/fix/retry-on-500s
  • 59661b1 fix: retry on when getting 500 resp
  • b9dbb0c feat: Support Base64 encoding (#144)
  • 6a582fe Merge pull request #143 from snyk/chore/ownership-change
  • d6cf9b7 chore: Transferring ownership to Zenith
  • 1d2578f Merge pull request #141 from snyk/feat/track-skipped-files-over-max-size
  • ffcee84 feat: track skipped files over max size
  • 8451c7e fix: bundle file path resolution for paths with whitespace (#142)
  • b54323a Merge pull request #140 from snyk/feat/increase-file-limit-and-add-logging
  • d3753ee feat: increase file limit to 1MB
  • f6e4d95 Merge pull request #135 from snyk/chore/add-lint-prettier
  • 506fc9d chore: add-prettier
  • d34fe8d chore: add-lint-to-pipeline
  • 78fd74d Merge pull request Add CodeTriage badge to snyk/snyk snyk/cli#131 from snyk/fix/test-analysis-context
  • 98b10c6 fix: fixed tests and handling of optional argument analysisContext
  • 714c7fe Merge pull request #130 from snyk/feat/cli-support-for-beta-langs
  • aa84f69 feat: adding support for beta language flags in cli
  • 5bfc9dd Merge pull request feat: check that there are actually modules in node_modules snyk/cli#128 from snyk/feat/sync-analysis-context
  • 2d8bf4f feat: align analysis context
  • c43c279 Merge pull request #127 from snyk/fix/monoliths-issue
  • f8a5d2f fix: allowing more time before connection timeouts, fixes monolith problem
  • 714d1d2 Merge pull request #126 from snyk/feat/observibility

See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Learn about vulnerability in an interactive lesson of Snyk Learn.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant