Skip to content

Conversation

@snyk-bot
Copy link

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

merge advice

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • package.json
    • package-lock.json

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
critical severity 704/1000
Why? Has a fix available, CVSS 9.8
Prototype Pollution
SNYK-JS-LODASH-590103
No No Known Exploit

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: modernizr The new version differs by 250 commits.

See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic

@atomist atomist bot added auto-branch-delete:on-close Delete branch when pull request gets closed auto-merge-method:merge Auto-merge with merge commit auto-merge:on-bpr-success Auto-merge on passed branch protection rule labels Jan 16, 2022
npm audit fix updated the following npm dependencies:

 * acorn > 5.7.4
 * codemirror > 5.65.0
 * jquery-ui > 1.13.0
 * mkdirp > 0.5.5
 * modernizr > 3.11.8
 * moment > 2.29.1
 * underscore > 1.13.2

[atomist:generated]
[atomist-skill:atomist/npm-vulnerability-scanner-skill]
npm audit fix updated the following npm dependencies:

 * jquery > 3.6.0
 * nunjucks > 3.2.3
 * react > 17.0.2

[atomist:generated]
[atomist-skill:atomist/npm-vulnerability-scanner-skill]
Development Dependencies

* @babel/cli > 7.16.8
* @babel/core > 7.16.7
* @babel/preset-env > 7.16.8
* @babel/preset-react > 7.16.7
* @babel/register > 7.16.9
* autoprefixer > 9.8.8
* browser-sync > 2.27.7
* concurrently > 5.3.0
* cssnano > 4.1.11
* kss > 3.0.1
* onchange > 6.1.1
* postcss-custom-properties > 9.2.0
* sass > 1.48.0
* stylelint-scss > 3.21.0

[atomist:generated]
[atomist-skill:atomist/npm-vulnerability-scanner-skill]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

auto-branch-delete:on-close Delete branch when pull request gets closed auto-merge:on-bpr-success Auto-merge on passed branch protection rule auto-merge-method:merge Auto-merge with merge commit

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants