Skip to content

Conversation

@adrukh
Copy link
Owner

@adrukh adrukh commented Oct 18, 2022

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • package.json

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
medium severity 551/1000
Why? Recently disclosed, Has a fix available, CVSS 5.3
Regular Expression Denial of Service (ReDoS)
SNYK-JS-MINIMATCH-3050818
Yes No Known Exploit

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: sqlite3 The new version differs by 74 commits.
  • e66d5a8 prepublish [skip ci]
  • 58fa526 update changelog [skip ci]
  • f1a2500 v3.0.4
  • 4dfdb15 restore matrix [skip ci]
  • a476768 [publish binary]
  • 9f85d0e restore matrix [skip ci]
  • b5268de quick hack to get node v0.11.14 binaries published [publish binary]
  • 2b3af9b [publish binary]
  • 435c411 Merge pull request jsbin and mysql jsbin/jsbin#363 from mapbox/visual-studio-2014
  • 2ef7028 build for both node 0.11.13 and 0.11.14 [publish binary]
  • 01973c5 use node-pre-gyp@0.6.0
  • 495bd5e use node v0.10.32
  • 64a491a try to put dumpbin on PATH
  • 1612ce9 also report dll deps of node.exe
  • 7741257 display DLL depedencies - thanks @ bergwerkgis (https://snyk.io/redirect/github/mapbox/mason/wiki/cpp-build-error-notes#discover-dynamic-shared-library-dependencies)
  • f52dfe4 [publish binary]
  • 54f2588 enable c++11 exceptions
  • d1519e1 show http logging
  • 723c5d7 [publish binary]
  • b4ff729 debug whether dist-url is working
  • 70a3663 try unpublishing before publish [publish binary]
  • 0a0d02f [publish binary]
  • 9dc5417 appveyor: os is only respected at top-level
  • e9512b4 install msvs 2014 vcredist so that our custom node.exe can run

See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Regular Expression Denial of Service (ReDoS)

The following vulnerabilities are fixed with an upgrade:
- https://snyk.io/vuln/SNYK-JS-MINIMATCH-3050818
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants