Skip to content

[Snyk] Fix for 1 vulnerabilities - #355

Open
riteshgurung wants to merge 1 commit into
1.0.xfrom
snyk-fix-1a169eef8a0a491737e92323678f2889
Open

[Snyk] Fix for 1 vulnerabilities#355
riteshgurung wants to merge 1 commit into
1.0.xfrom
snyk-fix-1a169eef8a0a491737e92323678f2889

Conversation

@riteshgurung

Copy link
Copy Markdown
Contributor

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • pattern-lab/package.json
    • pattern-lab/package-lock.json

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
high severity 661/1000
Why? Recently disclosed, Has a fix available, CVSS 7.5
Missing Release of Resource after Effective Lifetime
SNYK-JS-INFLIGHT-6095116
No No Known Exploit

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: @pattern-lab/cli The new version differs by 110 commits.
  • 9734880 [skip travis] chore(release): publish v5.16.1
  • a4e63b2 [skip travis] chore(release): publish v5.16.0
  • ef0a60f fix(annotations): hiding those correctly (#1415)
  • d303f4d refactor: allow .json extension on annotations file #836 (#1402)
  • b6f18e0 refactor: updated even further dependencies (#1320)
  • 515df95 docs: aligning and describing our Node support policy (#1411)
  • 3f33ce5 fix(annotations): displaying annotation tooltips correctly (#1406)
  • a3ec132 refactor: removed package-lock.json (#1409)
  • f30b21e refactor: always include dimensions on images (#1405)
  • 76ccc8c chore: corrected placeholder image references (#1404)
  • dfb489e chore: corrected some hyperlinks (#1403)
  • 97f1964 refactor: corrected some aspects out of eslint feedback (#1399)
  • 2caac36 refactor(cli): correct the line endings before publishing (#1397)
  • 712c40e refactor: removed polyfill out of codebase (#1398)
  • f0e29e9 refactor: removed unused and unnecessary dependencies (#1396)
  • 1b48c0f chore: adapted those URLs to the pattern lab monorepo (#1395)
  • 5e3273b chore(create): corrected default value (#1394)
  • 853f876 refactor: removing outdated eslint config file (#1393)
  • 58308bf [skip travis] chore(release): publish v5.15.7
  • 4b9da93 refactor: updated dependency prismjs (#1392)
  • 89c0dfb docs: Update the discord invitation link (#1391)
  • 1e07acc [skip travis] chore(release): publish v5.15.6
  • e6f68f4 refactor: pinning dependency to prevent JS error (#1390)
  • 627d6a3 [skip travis] chore(release): publish v5.15.5

See the full diff

Package name: @pattern-lab/engine-twig-php The new version differs by 110 commits.
  • 9734880 [skip travis] chore(release): publish v5.16.1
  • a4e63b2 [skip travis] chore(release): publish v5.16.0
  • ef0a60f fix(annotations): hiding those correctly (#1415)
  • d303f4d refactor: allow .json extension on annotations file #836 (#1402)
  • b6f18e0 refactor: updated even further dependencies (#1320)
  • 515df95 docs: aligning and describing our Node support policy (#1411)
  • 3f33ce5 fix(annotations): displaying annotation tooltips correctly (#1406)
  • a3ec132 refactor: removed package-lock.json (#1409)
  • f30b21e refactor: always include dimensions on images (#1405)
  • 76ccc8c chore: corrected placeholder image references (#1404)
  • dfb489e chore: corrected some hyperlinks (#1403)
  • 97f1964 refactor: corrected some aspects out of eslint feedback (#1399)
  • 2caac36 refactor(cli): correct the line endings before publishing (#1397)
  • 712c40e refactor: removed polyfill out of codebase (#1398)
  • f0e29e9 refactor: removed unused and unnecessary dependencies (#1396)
  • 1b48c0f chore: adapted those URLs to the pattern lab monorepo (#1395)
  • 5e3273b chore(create): corrected default value (#1394)
  • 853f876 refactor: removing outdated eslint config file (#1393)
  • 58308bf [skip travis] chore(release): publish v5.15.7
  • 4b9da93 refactor: updated dependency prismjs (#1392)
  • 89c0dfb docs: Update the discord invitation link (#1391)
  • 1e07acc [skip travis] chore(release): publish v5.15.6
  • e6f68f4 refactor: pinning dependency to prevent JS error (#1390)
  • 627d6a3 [skip travis] chore(release): publish v5.15.5

See the full diff

Package name: @pattern-lab/uikit-workshop The new version differs by 87 commits.
  • 627d6a3 [skip travis] chore(release): publish v5.15.5
  • c9e4151 [skip travis] chore(release): publish v5.15.4
  • 108eb43 Update babel config
  • 7f37e9d fix: corrected some github urls (#1388)
  • b86bf0a chore: code optimizations (#1387)
  • 91d2d3e refactor: updated lerna dependency (#1382)
  • 62901a3 refactor: moved dependencies to devDependencies @ uikit-workshop (#1381)
  • 49cd8f8 refactor: updated 11ty dependencies (#1383)
  • 2939561 refactor: moved dependencies to devDependencies @ cli (#1384)
  • 6fa630e feat: define initial viewport (#1386)
  • 8fb9fb4 refactor: updated http-auth dependency (#1379)
  • e284703 chore: adding simple pattern descriptions (#1378)
  • 57aad3d [skip travis] chore(release): publish v5.15.3
  • a75ee0d refactor: updated our redux version (#1374)
  • 1ebcd53 Includes additional twig syntax featires (#1367)
  • 7c66f8a fix(handlebars-demo): move and modify the icon files (#1377)
  • cfa74c0 feat(vs-code): added recommendations (#1375)
  • 82c5592 refactor: replace node-sass by sass (#1373)
  • 57efccb feat: ensure consistent line endings across files (#1372)
  • d7b428c refactor(docs): added forked plugin to the list (#1371)
  • 384dc89 fix(docs): tiles z-index to not overlay the menu anymore (#1370)
  • acca120 [skip travis] chore(release): publish v5.15.2
  • 3ce13ab fix(core): Subgroup cannot be hidden (#1368)
  • 7495275 refactor: optimized engines directory retrieval #1359 (#1364)

See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Learn about vulnerability in an interactive lesson of Snyk Learn.

…ce vulnerabilities

The following vulnerabilities are fixed with an upgrade:
- https://snyk.io/vuln/SNYK-JS-INFLIGHT-6095116
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants