[Snyk] Upgrade semver from 7.3.8 to 7.5.4 #4
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This PR was automatically created by Snyk using the credentials of a real user.
Snyk has created this PR to upgrade semver from 7.3.8 to 7.5.4.
ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.
The recommended version fixes:
SNYK-JS-SEMVER-3247795
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
(*) Note that the real score may have changed since the PR was raised.
Release notes
Package name: semver
7.5.4 (2023-07-07)
Bug Fixes
cc6fde2
#588 trim each range set before parsing (@ lukekarrys)99d8287
#583 correctly parse long build ids as valid (#583) (@ lukekarrys)7.5.3 (2023-06-22)
Bug Fixes
abdd93d
#571 set max lengths in regex for numeric and build identifiers (#571) (@ lukekarrys)Documentation
bf53dd8
#569 add example for>
comparator (#569) (@ mbtools)7.5.2 (2023-06-15)
Bug Fixes
58c791f
#566 diff when detecting major change from prerelease (#566) (@ lukekarrys)5c8efbc
#565 preserve build in raw after inc (#565) (@ lukekarrys)717534e
#564 better handling of whitespace (#564) (@ lukekarrys)7.5.1 (2023-05-12)
Bug Fixes
d30d25a
#559 show type on invalid semver error (#559) (@ tjenkinson)7.5.0 (2023-04-17)
Features
503a4e5
#548 allow identifierBase to be false (#548) (@ lsvalina)Bug Fixes
e219bb4
#552 throw on bad version with correct error message (#552) (@ wraithgar)fc2f3df
#546 incorrect results from diff sometimes with prerelease versions (#546) (@ tjenkinson)2781767
#547 avoid re-instantiating SemVer during diff compare (#547) (@ macno)7.4.0 (2023-04-10)
Features
113f513
#532 identifierBase parameter for .inc (#532) (@ wraithgar, @ b-bly)48d8f8f
#530 export new RELEASE_TYPES constant (@ hcharley)Bug Fixes
940723d
#538 intersects with v0.0.0 and v0.0.0-0 (#538) (@ wraithgar)aa516b5
#535 faster parse options (#535) (@ H4ad)61e6ea1
#536 faster cache key factory for range (#536) (@ H4ad)f8b8b61
#541 optimistic parse (#541) (@ H4ad)796cbe2
#533 semver.diff prerelease to release recognition (#533) (@ wraithgar, @ dominique-blockchain)3f222b1
#537 reuse comparators on subset (#537) (@ H4ad)f66cc45
#539 faster diff (#539) (@ H4ad)Documentation
c5d29df
#530 Add "Constants" section to README (@ hcharley)7.3.8 (2022-10-04)
Bug Fixes
d8ef32c
#383 add support for node.js esm auto exports (#383) (@ MylesBorins)Documentation
7209b14
#477 update range.js comments to clarify the caret ranges examples (#477) (@ amitse)Commit messages
Package name: semver
npm publish
uses different registry thennpm unpublish
npm/cli#559)npm install -g npm
may break npm installation npm/cli#555)Compare
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.
For more information:
🧐 View latest project report
🛠 Adjust upgrade PR settings
🔕 Ignore this dependency or unsubscribe from future upgrade PRs