Skip to content

Conversation

@amalsgit
Copy link
Owner

@amalsgit amalsgit commented Jan 9, 2023

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • package.json
    • package-lock.json

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
low severity 461/1000
Why? Recently disclosed, Has a fix available, CVSS 3.5
Regular Expression Denial of Service (ReDoS)
SNYK-JS-DEBUG-3227433
No No Known Exploit

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: snyk The new version differs by 250 commits.
  • 8987918 Merge pull request #1781 from snyk/fix/replace-proxy
  • eec11b7 test: raise timeout for snyk protect tests hitting real Snyk API
  • 8045ceb test: update proxy tests for the new proxy global-agent
  • 0d0c76a feat: support lowercase http_proxy envvars
  • e597846 test(proxy): acceptance test for Proxy envvar settings
  • 6d67579 fix: replace vulnerable proxy dependency
  • 1449c57 Merge pull request #1707 from snyk/feat/snyk-fix
  • 3d872fb test: assert exact errors for unsupported
  • 5ebd685 Merge pull request #1777 from snyk/feat/fix-with-version-provenance
  • 17e3431 Merge pull request #1778 from snyk/feat/dont-force-https
  • fdd7f1a docs: update SNYK_HTTP_PROTOCOL_UPGRADE description
  • 165b4b9 feat: introduce envvar to control HTTP-HTTPS upgrade behavior
  • 77e6665 chore: lerna release with exact version
  • f14819f Merge pull request #1760 from snyk/feat/support-critical-in-sarif
  • b286418 feat: v1 support for previously fixed reqs.txt
  • 0384020 feat: basic pip fix -r support
  • f94c558 feat: include pins optionally
  • 66ca77a feat: do not skip files with -r directive
  • bc44f9a refactor: fix individual reqs manifest
  • 6e84322 feat: fix individual file with provenance
  • 9ed99f3 Merge pull request #1764 from snyk/feat/update-code-client
  • c92599b Merge pull request #1774 from snyk/refactor/change-binaries-release-script
  • ca508ac test: smoke test for `snyk fix`
  • c68c7da feat: add @ snyk/fix as a dep

See the full diff

Package name: testcafe The new version differs by 250 commits.
  • bc367e8 Bump version (v1.11.0) (#5953)
  • d01f6f7 [docs] Add v1.11 changelog (#5951)
  • c1127c7 [docs] Write a `decrease test execution time` article (#5895)
  • 9ab6679 [docs] Remove beta mentions for multiple browser windows (#5947)
  • 108e9bd Revert "Revert : (#5925)" (#5952)
  • f463eac [Docs] Describe multiple browser windows mode limitations (#5943)
  • 8fd4988 Fix wrong request timeout options overriding (#5945)
  • 8cb4446 Fix typeText replacing issue (fix #5921) (#5942)
  • f1eef26 Bump version (v1.11.0-rc.1) (#5936)
  • a49a7f0 Switch var to const (#5931)
  • de0cf8a [docs] add ag-2021 announcement (#5938)
  • 64e67aa fix broken links (#5934)
  • a130719 renaming according to HH changes + update hammerhead (#5928)
  • 46460d1 Update Firefox Docker source (#5926)
  • afdb38f Revert : (#5925)
  • 5bc8a99 Fix wrong option passing from command-line interface (close #5913) (#5914)
  • 38308a7 1.10.2-alpha.2 (#5903)
  • dbb730a Cache resourses between tests (#5888)
  • 4c2ab63 fix(selectors): withText can't find existing element (#5887)
  • 7be176d Update label-actions.yml
  • a2d6e38 [docs] Describe ajax/page request timeouts (#5877)
  • 2450697 [docs] Document the `browser-init-timeout` feature (#5878)
  • 9b2a5f0 Fix 'Type: Question' label casing
  • f1df750 [docs] Update the contribution guide (#5856)

See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Regular Expression Denial of Service (ReDoS)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants