Skip to content

Conversation

@snyk-bot
Copy link

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

merge advice

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • package.json
    • package-lock.json

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
high severity 731/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 8.2
Prototype Pollution
SNYK-JS-LODASH-567746
No Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: modernizr The new version differs by 250 commits.

See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Learn about vulnerability in an interactive lesson of Snyk Learn.

@atomist atomist bot added auto-branch-delete:on-close Delete branch when pull request gets closed auto-merge-method:merge Auto-merge with merge commit auto-merge:on-bpr-success Auto-merge on passed branch protection rule labels Mar 26, 2022
npm audit fix updated the following npm dependencies:

 * acorn > 5.7.4
 * codemirror > 5.65.2
 * jquery-ui > 1.13.1
 * mkdirp > 0.5.6
 * moment > 2.29.1
 * underscore > 1.13.2

[atomist:generated]
[atomist-skill:atomist/npm-vulnerability-scanner-skill]
[atomist:generated]
[atomist-skill:atomist/npm-vulnerability-scanner-skill]
npm audit fix updated the following npm dependencies:

 * jquery > 3.6.0
 * nunjucks > 3.2.3
 * react > 17.0.2

[atomist:generated]
[atomist-skill:atomist/npm-vulnerability-scanner-skill]
Development Dependencies

* @babel/cli > 7.17.6
* @babel/core > 7.17.8
* @babel/preset-env > 7.16.11
* @babel/preset-react > 7.16.7
* @babel/register > 7.17.7
* autoprefixer > 9.8.8
* browser-sync > 2.27.9
* concurrently > 5.3.0
* cssnano > 4.1.11
* kss > 3.0.1
* onchange > 6.1.1
* postcss-custom-properties > 9.2.0
* sass > 1.49.9
* stylelint-scss > 3.21.0

[atomist:generated]
[atomist-skill:atomist/npm-vulnerability-scanner-skill]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

auto-branch-delete:on-close Delete branch when pull request gets closed auto-merge:on-bpr-success Auto-merge on passed branch protection rule auto-merge-method:merge Auto-merge with merge commit

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants