Skip to content

Conversation

@snyk-bot
Copy link

@snyk-bot snyk-bot commented Apr 7, 2022

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

merge advice

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • package.json

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
high severity 768/1000
Why? Proof of Concept exploit, Recently disclosed, Has a fix available, CVSS 7.5
Prototype Pollution
SNYK-JS-ASYNC-2441827
No Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: johnny-five The new version differs by 20 commits.
  • 3a7baca v0.9.1
  • 194e480 Fix appveyor badge url
  • ae7646e Run travis on modern infra
  • 59cc1c9 Cull the garbage from package.json
  • 76c7504 Read the long message.
  • ba41155 v0.9.0
  • 5005ab0 Appveyor badge
  • fddb28c Appveyor.yml
  • 440b95b Travis: test several versions of node
  • abb2f3a Remove bogus `null` arguments from emitters. Fixes gh-561
  • 5868321 Let's try win-spawn because fucking windows
  • 33e1c8d If Firmata installed serialport successfully, just steal it so we both can use it.
  • bfb3204 process.env.* will not work as expected.
  • f11d2e4 Cool typo spazz
  • fa77a72 delete process.ENV.SERIAL_PORT_INSTALLED;
  • d6c1bc2 Set ENV flag in preinstall, instead of attempting to install. Moves sp install back to postinstall
  • 9ae3157 Deps: do serialport installation before deps (allow firmata to bail out)
  • 7c1919f Deps: work in progress, temp switch to firmata.js repo
  • 3866a77 Deps: work in progress, update to latest firmata.js
  • e75078b Deps: work in progress, postinstall script for serialport installation

See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Prototype Pollution

The following vulnerabilities are fixed with an upgrade:
- https://snyk.io/vuln/SNYK-JS-ASYNC-2441827
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants