Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Snyk has created this PR to upgrade multiple dependencies.
👯♂ The following dependencies are linked and will therefore be updated together.ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.
@actions/core
from 1.6.0 to 1.10.1 | 8 versions ahead of your current version | a year ago
on 2023-09-11
@actions/io
from 1.0.2 to 1.1.3 | 4 versions ahead of your current version | a year ago
on 2023-03-15
@actions/exec
from 1.1.0 to 1.1.1 | 1 version ahead of your current version | 2 years ago
on 2022-03-17
semver
from 6.1.2 to 6.3.1 | 4 versions ahead of your current version | a year ago
on 2023-07-10
@actions/cache
from 1.0.7 to 1.0.11 | 4 versions ahead of your current version | 2 years ago
on 2022-03-24
@actions/glob
from 0.2.0 to 0.5.0 | 4 versions ahead of your current version | a month ago
on 2024-08-15
@actions/tool-cache
from 1.5.4 to 1.7.2 | 6 versions ahead of your current version | 2 years ago
on 2022-03-17
Issues fixed by the recommended upgrade:
SNYK-JS-ACTIONSCORE-2980270
SNYK-JS-ACTIONSCORE-2980270
SNYK-JS-NODEFETCH-2342118
SNYK-JS-XML2JS-5414874
SNYK-JS-TOUGHCOOKIE-5672873
SNYK-JS-TOUGHCOOKIE-5672873
SNYK-JS-ACTIONSCORE-1015402
Release notes
Package name: @actions/core
Package name: @actions/io
Prepend http:// to http(s)_proxy env if missing
Formatting
Fix linting
@ actions/[email protected]
Package name: @actions/exec
Prepend http:// to http(s)_proxy env if missing
Formatting
Fix linting
@ actions/[email protected]
Package name: semver
6.3.1 (2023-07-10)
Bug Fixes
928e56d
#591 better handling of whitespace (#591) (@ lukekarrys, @ joaomoreno, @ nicolo-ribaudo)Package name: @actions/cache
Package name: @actions/glob
Package name: @actions/tool-cache
Important
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.
For more information: