Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Snyk] Fix for 1 vulnerabilities #523

Merged
merged 1 commit into from
Feb 18, 2020

Conversation

snyk-bot
Copy link
Contributor

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • package.json
    • package-lock.json

Vulnerabilities that will be fixed

With an upgrade:
Severity Issue Breaking Change
medium severity Denial of Service (DoS)
SNYK-JS-NODESASS-542662
No
Commit messages
Package name: node-sass The new version differs by 24 commits.
  • b54053a Update changelog
  • 01db051 4.13.1
  • 338fd7a Merge pull request from GHSA-f6rp-gv58-9cw3
  • c6f2e5a doc: README example fix (#2787)
  • fbc9ff5 Merge pull request #2754 from saper/no-map-if-not-requested
  • 60fad5f 4.13.0
  • 43db915 Merge pull request #2768 from sass/release-4-13
  • 0c8d308 Update references for v4.13 release
  • f1cc0d3 Use GCC 6 for Node 12 binaries (#2767)
  • 3838eae Use GCC 6 for Node 12 binaries
  • e84c6a9 Merge pull request #2766 from saper/node-modules-79
  • 64b6f32 Node 13 support
  • 8498f70 Fix #2394: sourceMap option should have consistent behaviour
  • 8d0acca Merge pull request #2753 from schwigri/master
  • b0d4d85 Fix broken link to NodeJS docs in README.md
  • 887199a Merge pull request #2730 from kessenich/master
  • b1f54d7 Fix #2614 - Update lodash version
  • 96aa279 Merge pull request #2726 from XhmikosR/master-xmr-typos
  • 8421979 Assorted typo fixes.
  • 2513e6a chore: Remove PR template
  • 7ab387c Merge pull request #2673 from abetomo/remove_sudo_setting_from_travis
  • 15355dd Remove sudo settings from .travis.yml
  • 0c1a49e chore: Add not in PR template about node-gyp 4.0
  • e59f5ba chore: Change note about Node 12 support

See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:

🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic

@codecov
Copy link

codecov bot commented Jan 20, 2020

Codecov Report

Merging #523 into master will not change coverage.
The diff coverage is n/a.

Impacted file tree graph

@@            Coverage Diff            @@
##             master     #523   +/-   ##
=========================================
  Coverage     56.07%   56.07%           
  Complexity      263      263           
=========================================
  Files            17       17           
  Lines           922      922           
=========================================
  Hits            517      517           
  Misses          405      405

Continue to review full report at Codecov.

Legend - Click here to learn more
Δ = absolute <relative> (impact), ø = not affected, ? = missing data
Powered by Codecov. Last update 4725f59...587ad0a. Read the comment docs.

@mmattel mmattel requested a review from micbar February 18, 2020 13:00
@mmattel
Copy link
Contributor

mmattel commented Feb 18, 2020

@micbar wouldn't it be good to fix a vulnerable package before 10.4 gets out?

@micbar
Copy link
Contributor

micbar commented Feb 18, 2020

@IljaN Please review

@mmattel
Copy link
Contributor

mmattel commented Feb 18, 2020

In case of merging, is there a changelog entry necessary?

@phil-davis
Copy link
Contributor

phil-davis commented Feb 18, 2020

yes, we should make a changelog. That changelog automation stuff is not yet in this repo.

This also needs a rebase to pick up the .drone.star change, so that CI runs. I will do...

@phil-davis phil-davis self-assigned this Feb 18, 2020
@phil-davis phil-davis force-pushed the snyk-fix-04b1848dc381d72a85193c9415b6bf60 branch from a38d7ee to 587ad0a Compare February 18, 2020 14:52
@phil-davis phil-davis merged commit aaa713b into master Feb 18, 2020
@delete-merged-branch delete-merged-branch bot deleted the snyk-fix-04b1848dc381d72a85193c9415b6bf60 branch February 18, 2020 15:01
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

5 participants