Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Snyk] Security upgrade vinyl-fs from 0.3.14 to 2.0.0 #7

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

snyk-bot
Copy link

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • package.json

Vulnerabilities that will be fixed

With an upgrade:
Severity Issue Breaking Change Exploit Maturity
medium severity Prototype Pollution
SNYK-JS-LODASH-567746
Yes Proof of Concept
Commit messages
Package name: vinyl-fs The new version differs by 100 commits.
  • de7bf7b 2.0.0
  • 59620dc update vinyl
  • 5b056f6 update object-assign dep
  • 27983ef merge
  • 7ca959e remove watch #92
  • b9b9469 Merge pull request #90 from davidbarrows/with-updated-merge-stream-to-1.0.0
  • 22e5e13 Updated merge-stream version to 1.0.0
  • 5192dec Merge pull request #88 from kketch/fix-event-name
  • 65445ec fix wrong event name in README.md
  • cb22635 Merge pull request #85 from Klowner/symlink-passthru-support
  • 9f5f6e8 Add symlink copy with `followSymlinks` option
  • fa184c4 Merge pull request #82 from stevemao/patch-2
  • 0b3eed2 symlink opt.base should be the same as dest
  • 3e2a5ef base can be a function now, also add better error messaging. closes #78
  • c7887c1 Merge pull request #81 from silverwind/patch-1
  • 69090c4 use valid semver range for `engine`
  • 65090b8 Merge branch 'master' of https://github.com/wearefractal/vinyl-fs
  • b481130 fix filter-since
  • 30a8507 Merge pull request #79 from stevemao/improvements
  • 8e8135c update vinyl-filter-since
  • cb86d86 add missing test for f7516ebac102104ad0f39437f7739bf5aedec165
  • a8161c8 update vinyl filter since
  • 99db7de add sourcemaps to dest, clear up some dead src code now that empty arrays arent valid globs, dep updates
  • d32876f update deps

See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic

The following vulnerabilities are fixed with an upgrade:
- https://snyk.io/vuln/SNYK-JS-LODASH-567746
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant