Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Snyk] Fix for 1 vulnerabilities #24

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

snyk-bot
Copy link

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • package.json

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
high severity 696/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
Regular Expression Denial of Service (ReDoS)
SNYK-JS-ANSIREGEX-1583908
Yes Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: ember-cli-babel The new version differs by 250 commits.
  • 0b83e42 7.0.0
  • fcf317f Merge pull request #140 from babel/babel-7
  • d01d724 Prevent issues with @ babel/preset-env getting unknown options.
  • 1ea60c3 Merge branch 'master' into babel-7
  • 6955f46 Drop support for ember-cli < 2.13.
  • eb03764 Merge changes from master...
  • c58ae85 6.17.0
  • 5486b3e Add recent releases to changelog...
  • ec3f25c Merge pull request #241 from arthirm/master
  • af16202 Bumping broccoli-babel-transpiler
  • b4528ff Update test to properly match plugin style.
  • 2ea0e47 Remove brittle (and unneeded) tests.
  • 9671601 7.0.0-beta.5
  • 1167211 Remove stray .only.
  • cf8f7ee Fix issue with @ babel/polyfill update.
  • b4ea00d 7.0.0-beta.4
  • e53e927 Update dependencies.
  • 1e494d6 Update babel-polyfill -> @ babel/polyfill.
  • 7008a5f Use release version of broccoli-babel-transpiler.
  • 932a1d0 Merge pull request #239 from dfreeman/green-tests
  • a185133 Get tests passing with throwUnlessParallelizable: true
  • 6d11f44 Merge pull request #237 from babel/rwjblue-patch-1
  • b96e5cb Use correct preset env...
  • f9e4f17 Fix file: reference in package.json.

See the full diff

Package name: ember-cli-htmlbars-inline-precompile The new version differs by 30 commits.
  • ae552eb 0.4.0
  • 133cd0a Release 0.4.0 final.
  • 705f173 0.4.0-beta.2
  • 335e4c5 Update CHANGELOG.
  • 62e44bd Update minimum version of babel plugin.
  • d86edac 0.4.0-beta.1
  • 74fd184 Merge pull request #69 from rwjblue/babel-6
  • ffafb16 Remove welcome page.
  • 99aad43 Add ember-cli-shims back to ember-source scenario.
  • 3ae7891 Update min engine version.
  • d8cb4a1 Make function properly for babel@6 version.
  • f68e8b6 Update minimum versions of deps and devDeps.
  • c18f6d3 fixup! Add babel@6 to devDeps for test harness.
  • 8f92b23 Remove unused directories.
  • 1e9f66e Set ember-cli to 2.11.1.
  • edeceaa Add babel@6 to devDeps for test harness.
  • c113ff3 fixup! Update minimum node version.
  • 06f4fc7 ES6ify
  • 1f9d121 Update for babel@6.
  • e157867 Update minimum node version.
  • a8e851b Merge pull request #68 from samselikoff/patch-1
  • d1763d7 Ensure super call is bounded
  • 083ae62 Merge pull request #67 from Turbo87/ci-deploy
  • 5fa9b15 CI: Enable automatic NPM deployment for tags

See the full diff

Package name: ember-cli-qunit The new version differs by 91 commits.
  • ce97b77 4.0.0
  • a047c12 Update yarn.lock.
  • 03d7c2c Update CHANGELOG for 4.0.0.
  • b5dbd09 Update minimum version of ember-qunit.
  • f16f4d1 Merge pull request #180 from mminkoff/patch-1
  • f91e04b don't cover open Module drop-down
  • c9c0bbf 4.0.0-beta.1
  • c9385f2 Add basic upgrading info to README.
  • 127600d Update CHANGELOG.
  • e1e96a7 Merge pull request #177 from rwjblue/stuff
  • 8f77efd Update associated dependencies to Babel 6.
  • 99b18ba Death to `var`!
  • a1929f2 Merge pull request #175 from rwjblue/update-babel-6
  • ea52fd4 Merge pull request #176 from rwjblue/manual-start
  • cf5c5a5 Replace autostart behavior with hook to start tests.
  • df6a0e9 Update allowed engines in package.json.
  • 4b46471 Update to Babel 6.
  • fb8127a 3.1.2
  • 1714541 Update CHANGELOG for v3.1.2.
  • 8adb7ab Merge pull request #173 from rwjblue/prevent-clobbering
  • 161ab87 Bump to node@4 in CI.
  • 893d0ff Prevent clobbering custom `this.options.babel`.
  • f4cbeb9 3.1.1
  • f2f997c Merge pull request #170 from hidnasio/override-height-in-fullscreen

See the full diff

Package name: ember-export-application-global The new version differs by 7 commits.

See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Learn about vulnerability in an interactive lesson of Snyk Learn.

The following vulnerabilities are fixed with an upgrade:
- https://snyk.io/vuln/SNYK-JS-ANSIREGEX-1583908
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant