Skip to content

Conversation

@snyk-bot
Copy link

Snyk has created this PR to upgrade node-notifier from 5.2.1 to 5.4.5.

merge advice
ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


  • The recommended version is 7 versions ahead of your current version.
  • The recommended version was released a year ago, on 2021-03-11.

The recommended version fixes:

Severity Issue PriorityScore (*) Exploit Maturity
Command Injection
SNYK-JS-NODENOTIFIER-1035794
494/1000
Why? Has a fix available, CVSS 5.6
No Known Exploit

(*) Note that the real score may have changed since the PR was raised.

Release notes
Package name: node-notifier
  • 5.4.5 - 2021-03-11

    v5.4.5

  • 5.4.4 - 2021-03-11

    v5.4.4

  • 5.4.3 - 2019-08-19
  • 5.4.2 - 2019-08-04
  • 5.4.1 - 2019-08-04
  • 5.4.0 - 2019-02-03
  • 5.3.0 - 2018-10-19
  • 5.2.1 - 2018-01-13
from node-notifier GitHub release notes
Commit messages
Package name: node-notifier
  • ae03eed v5.4.5
  • 2cdb290 patch: fixes security issue with non-escaping inputs [GHSL-2020-373]
  • 93fa026 v5.4.4
  • c4b8ade patch: fixes possible injection issue for notify-send
  • 1101e6d Update version to v5.4.3
  • d204329 Revert "Fixes tests after mapping change"
  • 9a1fc72 Update lock file after audit
  • 8769921 Revert "Bumps all dependencies"
  • 3ae8fd7 Merge pull request #284 from mikaelbr/revert-271-overwritable-timeout
  • 5c48dc8 Revert "Allow timeout: false to remove a timeout"
  • 722f9d9 Revert "Remove node 6 from travis run"
  • 12d971d Revert "v5.4.2"
  • d907d54 Revert "Revert "Fixes tests after mapping change""
  • b9946dc Merge pull request #271 from jnielson94/overwritable-timeout
  • 698c103 Merge branch 'master' into overwritable-timeout
  • fd851c8 Remove node 6 from travis run
  • c153da9 Updates changelog
  • 378077c v5.4.2
  • 8f136d9 Bumps all dependencies
  • 2bbcc2d Revert "Fixes tests after mapping change"
  • 64decfb v5.4.1
  • e271899 Revert "Adds default timeout to notification center"
  • 3fefdf3 Merge pull request #274 from Aarbel/patch-1
  • ae64c68 Add event doc on notifier.onclick

Compare


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

🧐 View latest project report

🛠 Adjust upgrade PR settings

🔕 Ignore this dependency or unsubscribe from future upgrade PRs

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants