Skip to content

Conversation

snyk-bot
Copy link
Contributor

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

merge advice

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • package.json
    • package-lock.json

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
medium severity 479/1000
Why? Has a fix available, CVSS 5.3
Regular Expression Denial of Service (ReDoS)
SNYK-JS-JSBEAUTIFY-2311652
No No Known Exploit

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: js-beautify The new version differs by 71 commits.

See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Learn about vulnerability in an interactive lesson of Snyk Learn.

@parse-github-assistant
Copy link

I will reformat the title to use the proper commit message syntax.

@parse-github-assistant parse-github-assistant bot changed the title [Snyk] Security upgrade js-beautify from 1.14.0 to 1.14.1 refactor: security upgrade js-beautify from 1.14.0 to 1.14.1 Mar 30, 2022
@mtrezza mtrezza changed the title refactor: security upgrade js-beautify from 1.14.0 to 1.14.1 fix: security upgrade js-beautify from 1.14.0 to 1.14.1 Mar 30, 2022
@parse-github-assistant
Copy link

Thanks for opening this pull request!

  • ❌ Please edit your post and use the provided template when creating a new pull request. This helps everyone to understand your post better and asks for essential information to quicker review the pull request.

@mtrezza mtrezza merged commit 74aa7d0 into alpha Mar 30, 2022
@mtrezza mtrezza deleted the snyk-fix-8ef4079f24a2ae50002678c3644cd9b7 branch March 30, 2022 16:28
parseplatformorg pushed a commit that referenced this pull request Mar 30, 2022
# [4.1.0-alpha.3](4.1.0-alpha.2...4.1.0-alpha.3) (2022-03-30)

### Bug Fixes

* security upgrade js-beautify from 1.14.0 to 1.14.1 ([#2077](#2077)) ([74aa7d0](74aa7d0))
@parseplatformorg
Copy link
Contributor

🎉 This change has been released in version 4.1.0-alpha.3

@parseplatformorg parseplatformorg added the state:released-alpha Released as alpha version label Mar 30, 2022
mtrezza pushed a commit to mtrezza/parse-dashboard that referenced this pull request Apr 3, 2022
mtrezza pushed a commit to mtrezza/parse-dashboard that referenced this pull request Apr 3, 2022
parseplatformorg pushed a commit that referenced this pull request Apr 3, 2022
## [4.1.1-beta.1](4.1.0...4.1.1-beta.1) (2022-04-03)

### Bug Fixes

* security upgrade js-beautify from 1.14.0 to 1.14.1 ([#2077](#2077)) ([e4ea787](e4ea787))
* security vulnerability bump minimist from 1.2.5 to 1.2.6 ([#2070](#2070)) ([3d0407e](3d0407e))
parseplatformorg pushed a commit that referenced this pull request Apr 4, 2022
## [4.1.1-alpha.1](4.1.0...4.1.1-alpha.1) (2022-04-04)

### Bug Fixes

* security upgrade js-beautify from 1.14.0 to 1.14.1 ([#2077](#2077)) ([e4ea787](e4ea787))
* security vulnerability bump minimist from 1.2.5 to 1.2.6 ([#2070](#2070)) ([3d0407e](3d0407e))
parseplatformorg pushed a commit that referenced this pull request May 1, 2022
## [4.1.1](4.1.0...4.1.1) (2022-05-01)

### Bug Fixes

* security upgrade js-beautify from 1.14.0 to 1.14.1 ([#2077](#2077)) ([e4ea787](e4ea787))
* security vulnerability bump minimist from 1.2.5 to 1.2.6 ([#2070](#2070)) ([3d0407e](3d0407e))
mtrezza pushed a commit that referenced this pull request May 1, 2022
## [4.1.1-alpha.1](4.1.0...4.1.1-alpha.1) (2022-04-04)

### Bug Fixes

* security upgrade js-beautify from 1.14.0 to 1.14.1 ([#2077](#2077)) ([e4ea787](e4ea787))
* security vulnerability bump minimist from 1.2.5 to 1.2.6 ([#2070](#2070)) ([3d0407e](3d0407e))
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
state:released-alpha Released as alpha version
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants