Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Snyk] Upgrade: minimatch, glob, , , underscore-plus, fs-plus, temp, async, pathwatcher, atom-keymap, etch, atom-select-list, resolve, first-mate, chart.js, color, marked, devtron, find-parent-dir, focus-trap, fs-admin, fstream, git-utils, tree-sitter-css, less-cache, mocha, mocha-junit-reporter, mocha-multi-reporters, normalize-package-data, nslog, postcss, postcss-selector-parser, scandal, scrollbar-style, sinon, text-buffer, tree-sitter, typescript-simple, winreg #328

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

ryanmichaelfabayos
Copy link
Owner

snyk-top-banner

Snyk has created this PR to upgrade multiple dependencies.

👯 The following dependencies are linked and will therefore be updated together.

ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.

Name Versions Released on

minimatch
from 3.0.4 to 3.1.2 | 7 versions ahead of your current version | 3 years ago
on 2022-02-15
glob
from 7.1.2 to 7.2.3 | 8 versions ahead of your current version | 2 years ago
on 2022-05-15
@atom/nsfw
from 1.0.18 to 1.0.28 | 12 versions ahead of your current version | 3 years ago
on 2021-07-05
@atom/watcher
from 1.0.8 to 1.3.5 | 14 versions ahead of your current version | 4 years ago
on 2020-11-25
underscore-plus
from 1.6.8 to 1.7.0 | 1 version ahead of your current version | 5 years ago
on 2019-03-29
fs-plus
from 3.0.2 to 3.1.1 | 3 versions ahead of your current version | 6 years ago
on 2018-12-19
temp
from 0.8.3 to 0.9.4 | 5 versions ahead of your current version | 4 years ago
on 2020-11-10
async
from 0.2.6 to 0.9.2 | 15 versions ahead of your current version | 9 years ago
on 2015-05-19
pathwatcher
from 8.0.1 to 8.1.2 | 4 versions ahead of your current version | 3 years ago
on 2021-07-06
atom-keymap
from 8.2.12 to 8.2.15 | 4 versions ahead of your current version | 3 years ago
on 2021-07-07
etch
from 0.12.8 to 0.14.1 | 3 versions ahead of your current version | 4 years ago
on 2020-09-23
atom-select-list
from 0.7.2 to 0.8.1 | 2 versions ahead of your current version | 3 years ago
on 2021-05-21
resolve
from 1.8.1 to 1.22.8 | 34 versions ahead of your current version | a year ago
on 2023-10-10
first-mate
from 7.1.3 to 7.4.3 | 6 versions ahead of your current version | 3 years ago
on 2021-07-06
chart.js
from 2.7.2 to 2.9.4 | 8 versions ahead of your current version | 4 years ago
on 2020-10-18
color
from 0.7.3 to 0.11.4 | 9 versions ahead of your current version | 8 years ago
on 2016-11-01
marked
from 0.3.19 to 0.8.2 | 12 versions ahead of your current version | 4 years ago
on 2020-03-22
devtron
from 1.3.0 to 1.4.0 | 1 version ahead of your current version | 8 years ago
on 2016-10-07
find-parent-dir
from 0.3.0 to 0.3.1 | 1 version ahead of your current version | 3 years ago
on 2021-05-14
focus-trap
from 2.4.5 to 2.4.6 | 1 version ahead of your current version | 6 years ago
on 2018-06-10
fs-admin
from 0.1.7 to 0.20.0 | 19 versions ahead of your current version | 3 years ago
on 2022-02-10
fstream
from 0.1.24 to 0.1.31 | 7 versions ahead of your current version | 10 years ago
on 2014-08-04
git-utils
from 5.2.1 to 5.7.3 | 12 versions ahead of your current version | 3 years ago
on 2021-07-08
tree-sitter-css
from 0.13.7 to 0.21.1 | 6 versions ahead of your current version | 22 days ago
on 2024-08-17
less-cache
from 1.1.0 to 1.1.1 | 1 version ahead of your current version | 4 years ago
on 2020-12-11
mocha
from 2.5.1 to 2.5.3 | 2 versions ahead of your current version | 8 years ago
on 2016-05-25
mocha-junit-reporter
from 1.17.0 to 1.23.3 | 9 versions ahead of your current version | 5 years ago
on 2020-01-16
mocha-multi-reporters
from 1.1.7 to 1.5.1 | 2 versions ahead of your current version | 4 years ago
on 2020-11-04
normalize-package-data
from 2.4.0 to 2.5.0 | 3 versions ahead of your current version | 6 years ago
on 2019-02-05
nslog
from 3.0.0 to 3.2.0 | 2 versions ahead of your current version | 5 years ago
on 2019-06-06
postcss
from 5.2.4 to 5.2.18 | 14 versions ahead of your current version | 7 years ago
on 2017-10-04
postcss-selector-parser
from 2.2.1 to 2.2.3 | 2 versions ahead of your current version | 8 years ago
on 2017-02-23
scandal
from 3.1.0 to 3.2.0 | 2 versions ahead of your current version | 5 years ago
on 2019-06-17
scrollbar-style
from 3.2.0 to 3.2.3 | 3 versions ahead of your current version | 4 years ago
on 2020-12-10
sinon
from 1.17.4 to 1.17.7 | 3 versions ahead of your current version | 8 years ago
on 2016-12-31
text-buffer
from 13.15.1 to 13.18.6 | 20 versions ahead of your current version | 3 years ago
on 2021-04-28
tree-sitter
from 0.13.23 to 0.21.1 | 37 versions ahead of your current version | 5 months ago
on 2024-03-28
typescript-simple
from 1.0.0 to 1.0.3 | 5 versions ahead of your current version | 9 years ago
on 2015-04-16
winreg
from 1.2.4 to 1.2.5 | 1 version ahead of your current version | a year ago
on 2023-10-20

Issues fixed by the recommended upgrade:

Issue Score Exploit Maturity
high severity Prototype Pollution
SNYK-JS-CHARTJS-1018716
696 Proof of Concept
high severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-HAWK-2808852
696 No Known Exploit
critical severity Authentication Bypass
SNYK-JS-HAWK-6969142
696 Proof of Concept
high severity Regular Expression Denial of Service (ReDoS)
npm:diff:20180305
696 Proof of Concept
high severity Prototype Pollution
npm:extend:20180424
696 No Known Exploit
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-PATHPARSE-1077067
696 Proof of Concept
medium severity Time of Check Time of Use (TOCTOU)
npm:chownr:20180731
696 No Known Exploit
medium severity Prototype Pollution
npm:hoek:20180212
696 Proof of Concept
Release notes
Package name: minimatch from minimatch GitHub release notes
Package name: glob from glob GitHub release notes
Package name: @atom/nsfw
  • 1.0.28 - 2021-07-05
  • 1.0.27 - 2020-11-25
  • 1.0.26 - 2019-11-29
  • 1.0.25 - 2019-06-14
  • 1.0.24 - 2019-06-13
  • 1.0.23 - 2019-05-23
  • 1.0.23-1 - 2019-05-21
  • 1.0.23-0 - 2019-05-21
  • 1.0.22 - 2019-05-06
  • 1.0.21 - 2019-02-06
  • 1.0.20 - 2018-09-06
  • 1.0.19 - 2018-08-10
  • 1.0.18 - 2017-10-27
from @atom/nsfw GitHub release notes
Package name: @atom/watcher from @atom/watcher GitHub release notes
Package name: underscore-plus from underscore-plus GitHub release notes
Package name: fs-plus from fs-plus GitHub release notes
Package name: temp
  • 0.9.4 - 2020-11-10
    No content.
  • 0.9.2 - 2020-10-26

    v0.9.2

  • 0.9.1 - 2019-10-30
    No content.
  • 0.9.0 - 2018-12-15

    Bumps version 0.9.0 and resolves minor bugs with package.

  • 0.8.4 - 2019-10-30
  • 0.8.3 - 2015-06-08

    Adds os.tmpdir() polyfill changes from sindresorhus

from temp GitHub release notes
Package name: async
  • 0.9.2 - 2015-05-19
  • 0.9.0 - 2014-05-16
  • 0.8.0 - 2014-04-29
  • 0.7.0 - 2014-04-07
  • 0.6.2 - 2014-03-31
  • 0.6.1 - 2014-03-30
  • 0.6.0 - 2014-03-30
  • 0.5.0 - 2014-03-30
  • 0.4.1 - 2014-03-30
  • 0.4.0 - 2014-03-28
  • 0.3.0 - 2014-03-28
  • 0.2.10 - 2014-01-23
  • 0.2.9 - 2013-05-28
  • 0.2.8 - 2013-05-01
  • 0.2.7 - 2013-04-09
  • 0.2.6 - 2013-03-03
from async GitHub release notes
Package name: pathwatcher from pathwatcher GitHub release notes
Package name: atom-keymap from atom-keymap GitHub release notes
Package name: etch from etch GitHub release notes
Package name: atom-select-list
  • 0.8.1 - 2021-05-21
  • 0.8.0 - 2021-01-12
  • 0.7.2 - 2018-08-20

    0.7.2

from atom-select-list GitHub release notes
Package name: resolve
  • 1.22.8 - 2023-10-10
    • [Tests] rename innocent test project to avoid flawed security scanners
    • [Tests] skip some tests for a broken require.resolve in node v8.9, v9.0-v9.2
  • 1.22.7 - 2023-10-10
    • [Tests] avoid publishing "malformed package.json" test to avoid flawed security scanners
  • 1.22.6 - 2023-09-15
    • [Fix] allow npx resolve to work (#316)
    • [actions] use reusable rebase action
  • 1.22.5 - 2023-09-14
    • [Fix] fix npx resolve by handling symlinks (#315)
    • [Dev Deps] update array.prototype.map
  • 1.22.4 - 2023-08-04
    • Revert "[Refactor] deprecated lib/core.js now uses data from is-core-module also"
    • [Deps] update is-core-module
    • [Dev Deps] update @ ljharb/eslint-config, aud, semver, tape
    • [meta] commit published core.json data
  • 1.22.3 - 2023-04-14
    • [Refactor] deprecated lib/core.js now uses data from is-core-module also
    • [Deps] update is-core-module
  • 1.22.2 - 2023-04-05
    • [Refactor] deprecated lib/core.js now uses is-core-module
    • [meta] cp core.json on prepack instead of prepublishOnly
    • [Deps] update is-core-module
    • [Dev Deps] update @ ljharb/eslint-config, aud, tape, array.prototype.map
  • 1.22.1 - 2022-06-17
    • [Fix] support windows virtual drive paths (#284)
    • [Deps] update is-core-module
    • [meta] use npmignore to autogenerate an npmignore file
    • [meta] do not publish appveyor.yml
    • [Dev Deps] update eslint, @ ljharb/eslint-config, tape
    • [Test] add tests for "main": false
    • [Tests] fix tests on node v12.0-12.2
    • [Test] add some sync coverage
    • [Test] fix incorrect require.resolve paths logic; enable these tests
    • [Tests] avoid tests breaking on node 11.11 - 11.13
  • 1.22.0 - 2022-01-22
    • [New] add default support for paths to include $HOME/.node_{modules,libraries} (#273)
    • [Deps] update is-core-module
  • 1.21.1 - 2022-01-21
  • 1.21.0 - 2022-01-03
  • 1.20.0 - 2021-02-11
  • 1.19.0 - 2020-11-10
  • 1.18.1 - 2020-10-19
  • 1.18.0 - 2020-10-19
  • 1.17.0 - 2020-04-22
  • 1.16.1 - 2020-04-17
  • 1.16.0 - 2020-04-15
  • 1.15.1 - 2020-02-05
  • 1.15.0 - 2020-01-22
  • 1.14.2 - 2020-01-07
  • 1.14.1 - 2019-12-19
  • 1.14.0 - 2019-12-18
  • 1.13.1 - 2019-11-26
  • 1.13.0 - 2019-11-25
  • 1.12.3 - 2019-11-26
  • 1.12.2 - 2019-11-22
  • 1.12.1 - 2019-11-22
  • 1.12.0 - 2019-08-01
  • 1.11.1 - 2019-06-03
  • 1.11.0 - 2019-05-15
  • 1.10.1 - 2019-04-24
  • 1.10.0 - 2019-01-21
  • 1.9.0 - 2018-12-17
  • 1.8.1 - 2018-06-17
from resolve GitHub release notes
Package name: first-mate from first-mate GitHub release notes
Package name: chart.js
  • 2.9.4 - 2020-10-18

    This is the last release of v2 and focused on fixing bugs identified in the v2.9.3 release.

    Bugs Fixed

    • #7404 - Preserve prototypes when cloning. Thanks @ iddings
    • #7587 - Fix docs for external moment.js. Thanks @ mojoaxel
    • #7853 - Fix box recursion when dimensions are NaN. Thanks @ alessandroasm
    • #7883 - Fix call stack exception when computing label sizes. Thanks @ silentmatt
    • #7918 - Prevent global prototype pollution via the merge helper
    • #7920 - Use Object.create(null) as merge target, to prevent prototype pollution
  • 2.9.3 - 2019-11-14

    Bug Fixes

    • #6698 Fix undefined variable
    • #6719 Don't make legend empty when fill is false

    Thanks to the maintainers and collaborators for their help to improve and test Chart.js (@ kurkle, @ benmccann, and @ etimberg).

  • 2.9.2 - 2019-11-02

    Bug Fixes

    • #6641 IE11 & Edge compatible style injection
    • #6655 Backwards compatible default fill for radar charts
    • #6660 Improve clipping of line charts when border widths are large
    • #6661 When a legend item is clicked, make sure the correct item is hidden
    • #6663 Refresh package-lock file to pick up new dependency

    Performance

    • #6671 Stop unnecessary line calculations

    Documentation

    • #6643 Combine performance documentation sections

    Thanks to the maintainers and collaborators for their help to improve and test Chart.js (@ nagix, @ kurkle, @ benmccann, @ etimberg and @ simonbrunel).

  • 2.9.1 - 2019-10-27

    Bug Fixes

    • #6603 Fix deprecation warnings for horizontal bar charts
    • #6608 Fix zoom plugin by no longer clipping scale.getDecimalForPixel to the chart area
    • #6617 Non numeric Y axes did not work

    Documentation

    • #6613 Add link to performance documentation

    Development

    • #6609 - Tests no longer use deprecated options

    Thanks to the maintainers and collaborators for their help to improve and test Chart.js (@ nagix, @ kurkle, @ benmccann, @ etimberg and @ simonbrunel).

  • 2.9.0 - 2019-10-26
  • 2.8.0 - 2019-03-14
  • 2.8.0-rc.1 - 2019-03-04
  • 2.7.3 - 2018-10-15
  • 2.7.2 - 2018-03-01
from chart.js GitHub release notes
Package name: color
  • 0.11.4 - 2016-11-01
  • 0.11.3 - 2016-06-24
  • 0.11.2 - 2016-06-21
  • 0.11.1 - 2016-01-03
  • 0.11.0 - 2016-01-02
  • 0.10.1 - 2015-07-02
  • 0.10.0 - 2015-07-02
  • 0.9.0 - 2015-06-21
  • 0.8.0 - 2015-03-03
  • 0.7.3 - 2014-10-17
from color GitHub release notes
Package name: marked
  • 0.8.2 - 2020-03-22

    Fixes

    • Add html to TextRenderer for html in headings #1622
    • Remove html tags in heading ids #1622

    Docs

    • Update comment about GitHub breaks #1620
  • 0.8.1 - 2020-03-18

    Fixes

    • Fix marked --help #1588
    • Fix GFM Example 116 code fences #1600
    • Send inline html to renderer #1602 (fixes #1601)
    • Improve docs example for invoking highlight.js #1603
    • Fix block-level elements breaking tables #1598 (fixes #1467)
    • break nptables on block-level structures #1617
  • 0.8.0 - 2019-12-12

    Breaking changes

    Fixes

    • Fix relative urls in baseUrl option #1526
    • Loose task list #1535
    • Fix image parentheses #1557
    • remove module field & update devDependencies #1581

    Docs

    • Update examples with es6+ #1521
    • Fix link to USING_PRO.md page #1552
    • Fix typo in USING_ADVANCED.md #1558
    • Node worker threads are stable #1555

    Dev Dependencies

    • Update deps #1516
    • Update eslint #1542
    • Update htmldiffer async matcher #1543
  • 0.7.0 - 2019-07-06

    Security

    • Sanitize paragraph and text tokens #1504
    • Fix ReDOS for links with backticks (issue #1493) #1515

    Breaking Changes

    • Deprecate sanitize and sanitizer options #1504
    • Move fences to CommonMark #1511
    • Move tables to GFM #1511
    • Remove tables option #1511
    • Single backtick in link text needs to be escaped #1515

    Fixes

    Tests

    • Run tests with correct options #1511
  • 0.6.3 - 2019-06-30

    Fixes

    Docs

    • add docs for workers #1432
    • Add security policy #1492
    • Update supported spec versions #1491
    • Update test folder descriptions #1506

    DevOps

    • Use latest commit for demo master #1457
    • Update tests to commonmark 0.29 #1465
    • Update tests to GFM 0.29 #1470
    • Fix commonmark spec 57 and 40 (headings) #1475
  • 0.6.2 - 2019-04-05

    Security

    Fixes

    • Links parens #1435
    • New line after table with escaped pipe #1439
    • List item tables #1446

    Enhancements

    • Pass token boolean to the listitem function ...

Snyk has created this PR to upgrade:
  - minimatch from 3.0.4 to 3.1.2.
    See this package in npm: https://www.npmjs.com/package/minimatch
  - glob from 7.1.2 to 7.2.3.
    See this package in npm: https://www.npmjs.com/package/glob
  - @atom/nsfw from 1.0.18 to 1.0.28.
    See this package in npm: https://www.npmjs.com/package/@atom/nsfw
  - @atom/watcher from 1.0.8 to 1.3.5.
    See this package in npm: https://www.npmjs.com/package/@atom/watcher
  - underscore-plus from 1.6.8 to 1.7.0.
    See this package in npm: https://www.npmjs.com/package/underscore-plus
  - fs-plus from 3.0.2 to 3.1.1.
    See this package in npm: https://www.npmjs.com/package/fs-plus
  - temp from 0.8.3 to 0.9.4.
    See this package in npm: https://www.npmjs.com/package/temp
  - async from 0.2.6 to 0.9.2.
    See this package in npm: https://www.npmjs.com/package/async
  - pathwatcher from 8.0.1 to 8.1.2.
    See this package in npm: https://www.npmjs.com/package/pathwatcher
  - atom-keymap from 8.2.12 to 8.2.15.
    See this package in npm: https://www.npmjs.com/package/atom-keymap
  - etch from 0.12.8 to 0.14.1.
    See this package in npm: https://www.npmjs.com/package/etch
  - atom-select-list from 0.7.2 to 0.8.1.
    See this package in npm: https://www.npmjs.com/package/atom-select-list
  - resolve from 1.8.1 to 1.22.8.
    See this package in npm: https://www.npmjs.com/package/resolve
  - first-mate from 7.1.3 to 7.4.3.
    See this package in npm: https://www.npmjs.com/package/first-mate
  - chart.js from 2.7.2 to 2.9.4.
    See this package in npm: https://www.npmjs.com/package/chart.js
  - color from 0.7.3 to 0.11.4.
    See this package in npm: https://www.npmjs.com/package/color
  - marked from 0.3.19 to 0.8.2.
    See this package in npm: https://www.npmjs.com/package/marked
  - devtron from 1.3.0 to 1.4.0.
    See this package in npm: https://www.npmjs.com/package/devtron
  - find-parent-dir from 0.3.0 to 0.3.1.
    See this package in npm: https://www.npmjs.com/package/find-parent-dir
  - focus-trap from 2.4.5 to 2.4.6.
    See this package in npm: https://www.npmjs.com/package/focus-trap
  - fs-admin from 0.1.7 to 0.20.0.
    See this package in npm: https://www.npmjs.com/package/fs-admin
  - fstream from 0.1.24 to 0.1.31.
    See this package in npm: https://www.npmjs.com/package/fstream
  - git-utils from 5.2.1 to 5.7.3.
    See this package in npm: https://www.npmjs.com/package/git-utils
  - tree-sitter-css from 0.13.7 to 0.21.1.
    See this package in npm: https://www.npmjs.com/package/tree-sitter-css
  - less-cache from 1.1.0 to 1.1.1.
    See this package in npm: https://www.npmjs.com/package/less-cache
  - mocha from 2.5.1 to 2.5.3.
    See this package in npm: https://www.npmjs.com/package/mocha
  - mocha-junit-reporter from 1.17.0 to 1.23.3.
    See this package in npm: https://www.npmjs.com/package/mocha-junit-reporter
  - mocha-multi-reporters from 1.1.7 to 1.5.1.
    See this package in npm: https://www.npmjs.com/package/mocha-multi-reporters
  - normalize-package-data from 2.4.0 to 2.5.0.
    See this package in npm: https://www.npmjs.com/package/normalize-package-data
  - nslog from 3.0.0 to 3.2.0.
    See this package in npm: https://www.npmjs.com/package/nslog
  - postcss from 5.2.4 to 5.2.18.
    See this package in npm: https://www.npmjs.com/package/postcss
  - postcss-selector-parser from 2.2.1 to 2.2.3.
    See this package in npm: https://www.npmjs.com/package/postcss-selector-parser
  - scandal from 3.1.0 to 3.2.0.
    See this package in npm: https://www.npmjs.com/package/scandal
  - scrollbar-style from 3.2.0 to 3.2.3.
    See this package in npm: https://www.npmjs.com/package/scrollbar-style
  - sinon from 1.17.4 to 1.17.7.
    See this package in npm: https://www.npmjs.com/package/sinon
  - text-buffer from 13.15.1 to 13.18.6.
    See this package in npm: https://www.npmjs.com/package/text-buffer
  - tree-sitter from 0.13.23 to 0.21.1.
    See this package in npm: https://www.npmjs.com/package/tree-sitter
  - typescript-simple from 1.0.0 to 1.0.3.
    See this package in npm: https://www.npmjs.com/package/typescript-simple
  - winreg from 1.2.4 to 1.2.5.
    See this package in npm: https://www.npmjs.com/package/winreg

See this project in Snyk:
https://app.snyk.io/org/yaelxfabayos/project/f49937dc-4c67-4ab4-8d93-08ebbd3730e8?utm_source=github&utm_medium=referral&page=upgrade-pr
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
2 participants