[Snyk] Upgrade semver from 7.3.7 to 7.6.0 #42
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This PR was automatically created by Snyk using the credentials of a real user.
Snyk has created this PR to upgrade semver from 7.3.7 to 7.6.0.
ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.
The recommended version fixes:
SNYK-JS-SEMVER-3247795
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
(*) Note that the real score may have changed since the PR was raised.
Release notes
Package name: semver
7.6.0 (2024-01-31)
Features
a7ab13a
#671 preserve pre-release and build parts of a version on coerce (#671) (@ madtisa, madtisa, @ wraithgar)Chores
816c7b2
#667 postinstall for dependabot template-oss PR (@ lukekarrys)0bd24d9
#667 bump @ npmcli/template-oss from 4.21.1 to 4.21.3 (@ dependabot[bot])e521932
#652 postinstall for dependabot template-oss PR (@ lukekarrys)8873991
#652 chore: chore: postinstall for dependabot template-oss PR (@ lukekarrys)f317dc8
#652 bump @ npmcli/template-oss from 4.19.0 to 4.21.0 (@ dependabot[bot])7303db1
#658 add clean() test for build metadata (#658) (@ jethrodaniel)6240d75
#656 add missing quotes in README.md (#656) (@ zyxkad)14d263f
#625 postinstall for dependabot template-oss PR (@ lukekarrys)7c34e1a
#625 bump @ npmcli/template-oss from 4.18.1 to 4.19.0 (@ dependabot[bot])123e0b0
#622 postinstall for dependabot template-oss PR (@ lukekarrys)737d5e1
#622 bump @ npmcli/template-oss from 4.18.0 to 4.18.1 (@ dependabot[bot])cce6180
#598 postinstall for dependabot template-oss PR (@ lukekarrys)b914a3d
#598 bump @ npmcli/template-oss from 4.17.0 to 4.18.0 (@ dependabot[bot])7.5.4 (2023-07-07)
Bug Fixes
cc6fde2
#588 trim each range set before parsing (@ lukekarrys)99d8287
#583 correctly parse long build ids as valid (#583) (@ lukekarrys)7.5.3 (2023-06-22)
Bug Fixes
abdd93d
#571 set max lengths in regex for numeric and build identifiers (#571) (@ lukekarrys)Documentation
bf53dd8
#569 add example for>
comparator (#569) (@ mbtools)7.5.2 (2023-06-15)
Bug Fixes
58c791f
#566 diff when detecting major change from prerelease (#566) (@ lukekarrys)5c8efbc
#565 preserve build in raw after inc (#565) (@ lukekarrys)717534e
#564 better handling of whitespace (#564) (@ lukekarrys)7.5.1 (2023-05-12)
Bug Fixes
d30d25a
#559 show type on invalid semver error (#559) (@ tjenkinson)7.5.0 (2023-04-17)
Features
503a4e5
#548 allow identifierBase to be false (#548) (@ lsvalina)Bug Fixes
e219bb4
#552 throw on bad version with correct error message (#552) (@ wraithgar)fc2f3df
#546 incorrect results from diff sometimes with prerelease versions (#546) (@ tjenkinson)2781767
#547 avoid re-instantiating SemVer during diff compare (#547) (@ macno)Read more
7.3.8 (2022-10-04)
Bug Fixes
d8ef32c
#383 add support for node.js esm auto exports (#383) (@ MylesBorins)Documentation
7209b14
#477 update range.js comments to clarify the caret ranges examples (#477) (@ amitse)Commit messages
Package name: semver
Compare
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.
For more information:
🧐 View latest project report
🛠 Adjust upgrade PR settings
🔕 Ignore this dependency or unsubscribe from future upgrade PRs