Skip to content

[Snyk] Security upgrade gh-release from 3.5.0 to 7.0.0#94

Open
matthewjablack wants to merge 1 commit intodevfrom
snyk-fix-3df0355404a8e29570c7d715b1ea2756
Open

[Snyk] Security upgrade gh-release from 3.5.0 to 7.0.0#94
matthewjablack wants to merge 1 commit intodevfrom
snyk-fix-3df0355404a8e29570c7d715b1ea2756

Conversation

@matthewjablack
Copy link
Contributor

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • package.json
  • package-lock.json

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
high severity 696/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
Regular Expression Denial of Service (ReDoS)
SNYK-JS-ANSIREGEX-1583908
Yes Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: gh-release The new version differs by 172 commits.
  • 7c36813 7.0.0
  • 0ae065b docs(changelog): 7.0.0
  • f8b0410 ci(node): drop 12, add 18
  • 8085747 chore(deps): update gauge requirement from ^v4.0.4 to ^v5.0.0 (#186)
  • 7e244f8 chore(deps): bump @ octokit/rest from 18.12.0 to 19.0.5 (#187)
  • 3b430ee docs: update desc [skip ci]
  • a156a27 docs: fix workpath default
  • 3bd0051 chore: rm site (#178)
  • 91ee3b7 chore: update author site (https)
  • 9c3e22d chore: update domain
  • fd284b8 chore(deps-dev): bump gh-pages from 3.2.3 to 4.0.0 (#176)
  • 6b4a4ec deps(dev): standard@17
  • b11db96 ci: fix bad var name (#172)
  • 591b8a9 6.0.4
  • 5f25872 docs(changelog): fix date & URL for 6.0.4
  • 4d3e2ca docs: changelog@6.0.4
  • 8160275 pkg(engines): set min to 12
  • fad6563 deps(dev): use tap-arc
  • e5e5b65 rm npmrc (#171)
  • b626f4a docs: ditch demo.png, update CLI example
  • 03b352b docs: fix img copy
  • 6ac6b3f docs(readme): update images (#170)
  • 374e024 chore(deps): update gauge requirement from ^v4.0.3 to ^v4.0.4 (#169)
  • 02d655d docs(site): use same icon style as style.css site

See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic


Note: This is a default PR template raised by Snyk. Find out more about how you can customise Snyk PRs in our documentation.

Learn how to fix vulnerabilities with free interactive lessons:

🦉 Regular Expression Denial of Service (ReDoS)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants