Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Snyk] Upgrade: babel-jest, , , , , , , airbnb-browser-shims, awesome-node-loader, azure-storage, codecov, cross-env, css-loader, eslint, eslint-config-prettier, eslint-plugin-prettier, eslint-plugin-react, fake-indexeddb, jest-extended, jest-localstorage-mock, jszip, mini-css-extract-plugin, parallel-webpack, prettier, request, sass, sass-loader, style-loader, ts-jest, ts-node, tslint, typescript, typescript-tslint-plugin, webpack, webpack-bundle-analyzer, webpack-dev-middleware, webpack-hot-middleware, xml2js #24

Open
wants to merge 1 commit into
base: development
Choose a base branch
from

Conversation

scatools-demo
Copy link
Owner

snyk-top-banner

Snyk has created this PR to upgrade multiple dependencies.

👯‍♂ The following dependencies are linked and will therefore be updated together.

ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.

Name Versions Released on

babel-jest
from 23.4.2 to 23.6.0 | 1 version ahead of your current version | 6 years ago
on 2018-09-10
@primer/octicons
from 10.0.0 to 10.1.0 | 15 versions ahead of your current version | 4 years ago
on 2020-08-24
@types/marked
from 3.0.1 to 3.0.4 | 3 versions ahead of your current version | a year ago
on 2023-09-27
@types/plist
from 3.0.2 to 3.0.5 | 3 versions ahead of your current version | 10 months ago
on 2023-11-07
@types/react-color
from 3.0.4 to 3.0.12 | 8 versions ahead of your current version | 7 months ago
on 2024-02-26
@typescript-eslint/eslint-plugin
from 3.8.0 to 3.10.1 | 25 versions ahead of your current version | 4 years ago
on 2020-08-25
@typescript-eslint/parser
from 3.8.0 to 3.10.1 | 25 versions ahead of your current version | 4 years ago
on 2020-08-25
airbnb-browser-shims
from 3.0.0 to 3.3.0 | 4 versions ahead of your current version | 5 years ago
on 2019-08-21
awesome-node-loader
from 1.1.0 to 1.1.1 | 1 version ahead of your current version | 6 years ago
on 2018-06-28
azure-storage
from 2.10.4 to 2.10.7 | 3 versions ahead of your current version | 3 years ago
on 2022-01-04
codecov
from 3.7.1 to 3.8.2 | 4 versions ahead of your current version | 3 years ago
on 2021-05-03
cross-env
from 5.1.1 to 5.2.1 | 7 versions ahead of your current version | 5 years ago
on 2019-08-31
css-loader
from 2.1.0 to 2.1.1 | 1 version ahead of your current version | 6 years ago
on 2019-03-07
eslint
from 7.6.0 to 7.32.0 | 28 versions ahead of your current version | 3 years ago
on 2021-07-30
eslint-config-prettier
from 6.11.0 to 6.15.0 | 4 versions ahead of your current version | 4 years ago
on 2020-10-27
eslint-plugin-prettier
from 3.1.4 to 3.4.1 | 5 versions ahead of your current version | 3 years ago
on 2021-08-20
eslint-plugin-react
from 7.20.5 to 7.35.0 | 53 versions ahead of your current version | 2 months ago
on 2024-07-20
fake-indexeddb
from 2.0.4 to 2.1.1 | 4 versions ahead of your current version | 5 years ago
on 2019-06-05
jest-extended
from 0.11.2 to 0.11.5 | 3 versions ahead of your current version | 5 years ago
on 2020-01-27
jest-localstorage-mock
from 2.3.0 to 2.4.26 | 27 versions ahead of your current version | 2 years ago
on 2023-01-04
jszip
from 3.7.1 to 3.10.1 | 5 versions ahead of your current version | 2 years ago
on 2022-08-02
mini-css-extract-plugin
from 0.4.0 to 0.12.0 | 19 versions ahead of your current version | 4 years ago
on 2020-10-07
parallel-webpack
from 2.3.0 to 2.6.0 | 3 versions ahead of your current version | 4 years ago
on 2020-04-08
prettier
from 2.0.5 to 2.8.8 | 26 versions ahead of your current version | a year ago
on 2023-04-23
request
from 2.83.0 to 2.88.2 | 6 versions ahead of your current version | 5 years ago
on 2020-02-11
sass
from 1.27.0 to 1.77.8 | 145 versions ahead of your current version | 2 months ago
on 2024-07-11
sass-loader
from 10.0.3 to 10.5.2 | 13 versions ahead of your current version | 8 months ago
on 2024-01-04
style-loader
from 0.21.0 to 0.23.1 | 4 versions ahead of your current version | 6 years ago
on 2018-10-08
ts-jest
from 26.4.4 to 26.5.6 | 7 versions ahead of your current version | 3 years ago
on 2021-05-05
ts-node
from 7.0.0 to 7.0.1 | 1 version ahead of your current version | 6 years ago
on 2018-08-11
tslint
from 5.11.0 to 5.20.1 | 12 versions ahead of your current version | 5 years ago
on 2019-11-05
typescript
from 3.9.5 to 3.9.10 | 5 versions ahead of your current version | 3 years ago
on 2021-06-16
typescript-tslint-plugin
from 0.0.6 to 0.5.5 | 15 versions ahead of your current version | 5 years ago
on 2019-11-12
webpack
from 4.43.0 to 4.47.0 | 6 versions ahead of your current version | a year ago
on 2023-09-06
webpack-bundle-analyzer
from 3.8.0 to 3.9.0 | 1 version ahead of your current version | 4 years ago
on 2020-09-17
webpack-dev-middleware
from 3.7.2 to 3.7.3 | 1 version ahead of your current version | 4 years ago
on 2020-12-15
webpack-hot-middleware
from 2.25.0 to 2.26.1 | 6 versions ahead of your current version | 7 months ago
on 2024-02-01
xml2js
from 0.4.19 to 0.6.2 | 8 versions ahead of your current version | a year ago
on 2023-07-26

Issues fixed by the recommended upgrade:

Issue Score Exploit Maturity
high severity Asymmetric Resource Consumption (Amplification)
SNYK-JS-BODYPARSER-7926860
646 No Known Exploit
high severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-HAWK-2808852
646 No Known Exploit
high severity Prototype Poisoning
SNYK-JS-QS-3153490
646 Proof of Concept
high severity Prototype Poisoning
SNYK-JS-QS-3153490
646 Proof of Concept
medium severity Uninitialized Memory Exposure
npm:stringstream:20180511
646 Mature
critical severity Authentication Bypass
SNYK-JS-HAWK-6969142
646 Proof of Concept
high severity Prototype Poisoning
SNYK-JS-QS-3153490
646 Proof of Concept
high severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-ANSIHTML-1296849
646 Proof of Concept
high severity Prototype Pollution
SNYK-JS-LODASH-567746
646 Proof of Concept
high severity Prototype Pollution
SNYK-JS-LODASH-567746
646 Proof of Concept
high severity Prototype Pollution
SNYK-JS-LODASH-567746
646 Proof of Concept
medium severity Arbitrary File Write via Archive Extraction (Zip Slip)
SNYK-JS-JSZIP-3188562
646 No Known Exploit
medium severity Open Redirect
SNYK-JS-EXPRESS-6474509
646 No Known Exploit
medium severity Cross-site Scripting
SNYK-JS-EXPRESS-7926867
646 No Known Exploit
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-VALIDATOR-1090599
646 Proof of Concept
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-VALIDATOR-1090601
646 Proof of Concept
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-VALIDATOR-1090602
646 Proof of Concept
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-MINIMATCH-3050818
646 No Known Exploit
low severity Cross-site Scripting
SNYK-JS-SEND-7926862
646 No Known Exploit
low severity Cross-site Scripting
SNYK-JS-SERVESTATIC-7926865
646 No Known Exploit
Release notes
Package name: babel-jest
  • 23.6.0 - 2018-09-10

    Features

    • [jest-cli] Add changedSince to allowed watch mode configs (#6955)
    • [babel-jest] Add support for babel.config.js added in Babel 7.0.0 (#6911)
    • [jest-resolve] Add support for an experimental mapper option (Watchman crawler only) that adds virtual files to the Haste map (#6940)

    Fixes

    • [jest-resolve] Only resolve realpath once in try-catch (#6925)
    • [expect] Fix TypeError in toBeInstanceOf on null or undefined (#6912)
    • [jest-jasmine2] Throw a descriptive error if the first argument supplied to a hook was not a function (#6917) and (#6931)
    • [jest-circus] Throw a descriptive error if the first argument supplied to a hook was not a function (#6917) and (#6931)
    • [expect] Fix variadic custom asymmetric matchers (#6898)
    • [jest-cli] Fix incorrect testEnvironmentOptions warning (#6852)
    • [jest-each] Prevent done callback being supplied to describe (#6843)
    • [jest-config] Better error message for a case when a preset module was found, but no jest-preset.js or jest-preset.json at the root (#6863)
    • [jest-haste-map] Catch crawler error when unsuccessfully reading directories (#6761)

    Chore & Maintenance

    • [docs] Add custom toMatchSnapshot matcher docs (#6837)
    • [docs] Improve the documentation regarding preset configuration (#6864)
    • [docs] Clarify usage of --projects CLI option (#6872)
    • [docs] Correct failure-change notification mode (#6878)
    • [scripts] Don’t remove node_modules from subdirectories of presets in e2e tests (#6948)
    • [diff-sequences] Double-check number of differences in tests (#6953)
  • 23.4.2 - 2018-07-27

    Performance

    • [jest-changed-files] limit git and hg commands to specified roots (#6732)

    Fixes

    • [jest-circus] Fix retryTimes so errors are reset before re-running (#6762)
    • [docs] Update expect.objectContaining() description (#6754)
    • [babel-jest] Make getCacheKey() take into account createTransformer options (#6699)
    • [jest-jasmine2] Use prettier through require instead of localRequire. Fixes matchInlineSnapshot where prettier dependencies like path and fs are mocked with jest.mock. (#6776)
    • [docs] Fix contributors link (#6711)
    • [website] Fix website versions page to link to correct language (#6734)
    • [expect] Update toContain suggestion to contain equal message (#6792)
from babel-jest GitHub release notes
Package name: @primer/octicons
  • 10.1.0 - 2020-08-24
  • 10.1.0-rc.f8dcead - 2020-08-24
  • 10.1.0-rc.ee3d3d6 - 2020-08-24
  • 10.1.0-rc.ed280d4 - 2020-08-24
  • 10.1.0-rc.b8ebc4a - 2020-08-24
  • 10.1.0-rc.b6dbe56 - 2020-08-24
  • 10.1.0-rc.97c6b85 - 2020-08-24
  • 10.1.0-rc.961270a - 2020-08-24
  • 10.1.0-rc.8fbc115 - 2020-08-24
  • 10.1.0-rc.8d865ba - 2020-08-24
  • 10.1.0-rc.782a7e4 - 2020-08-24
  • 10.1.0-rc.73eea64 - 2020-08-24
  • 10.1.0-rc.48628a9 - 2020-08-24
  • 10.1.0-rc.2f6fb16 - 2020-08-24
  • 10.1.0-rc.9512409 - 2020-08-24
  • 10.0.0 - 2020-06-10
from @primer/octicons GitHub release notes
Package name: @types/plist
  • 3.0.5 - 2023-11-07
  • 3.0.4 - 2023-10-18
  • 3.0.3 - 2023-09-24
  • 3.0.2 - 2019-04-16
from @types/plist GitHub release notes
Package name: @types/react-color
  • 3.0.12 - 2024-02-26
  • 3.0.11 - 2024-01-02
  • 3.0.10 - 2023-11-07
  • 3.0.9 - 2023-10-18
  • 3.0.8 - 2023-10-18
  • 3.0.7 - 2023-09-27
  • 3.0.6 - 2021-10-20
  • 3.0.5 - 2021-07-07
  • 3.0.4 - 2020-06-26
from @types/react-color GitHub release notes
Package name: @typescript-eslint/eslint-plugin
  • 3.10.1 - 2020-08-25
  • 3.10.1-alpha.1 - 2020-08-25
  • 3.10.1-alpha.0 - 2020-08-24
  • 3.10.0 - 2020-08-24
  • 3.9.2-alpha.10 - 2020-08-24
  • 3.9.2-alpha.9 - 2020-08-24
  • 3.9.2-alpha.8 - 2020-08-21
  • 3.9.2-alpha.7 - 2020-08-21
  • 3.9.2-alpha.5 - 2020-08-21
  • 3.9.2-alpha.4 - 2020-08-20
  • 3.9.2-alpha.3 - 2020-08-20
  • 3.9.2-alpha.2 - 2020-08-19
  • 3.9.2-alpha.1 - 2020-08-19
  • 3.9.2-alpha.0 - 2020-08-17
  • 3.9.1 - 2020-08-17
  • 3.9.1-alpha.3 - 2020-08-14
  • 3.9.1-alpha.2 - 2020-08-13
  • 3.9.1-alpha.1 - 2020-08-12
  • 3.9.1-alpha.0 - 2020-08-10
  • 3.9.0 - 2020-08-10
  • 3.8.1-alpha.4 - 2020-08-10
  • 3.8.1-alpha.3 - 2020-08-10
  • 3.8.1-alpha.2 - 2020-08-09
  • 3.8.1-alpha.1 - 2020-08-09
  • 3.8.1-alpha.0 - 2020-08-03
  • 3.8.0 - 2020-08-03
from @typescript-eslint/eslint-plugin GitHub release notes
Package name: @typescript-eslint/parser
  • 3.10.1 - 2020-08-25
  • 3.10.1-alpha.1 - 2020-08-25
  • 3.10.1-alpha.0 - 2020-08-24
  • 3.10.0 - 2020-08-24
  • 3.9.2-alpha.10 - 2020-08-24
  • 3.9.2-alpha.9 - 2020-08-24
  • 3.9.2-alpha.8 - 2020-08-21
  • 3.9.2-alpha.7 - 2020-08-21
  • 3.9.2-alpha.5 - 2020-08-21
  • 3.9.2-alpha.4 - 2020-08-20
  • 3.9.2-alpha.3 - 2020-08-20
  • 3.9.2-alpha.2 - 2020-08-19
  • 3.9.2-alpha.1 - 2020-08-19
  • 3.9.2-alpha.0 - 2020-08-17
  • 3.9.1 - 2020-08-17
  • 3.9.1-alpha.3 - 2020-08-14
  • 3.9.1-alpha.2 - 2020-08-13
  • 3.9.1-alpha.1 - 2020-08-12
  • 3.9.1-alpha.0 - 2020-08-10
  • 3.9.0 - 2020-08-10
  • 3.8.1-alpha.4 - 2020-08-10
  • 3.8.1-alpha.3 - 2020-08-10
  • 3.8.1-alpha.2 - 2020-08-09
  • 3.8.1-alpha.1 - 2020-08-09
  • 3.8.1-alpha.0 - 2020-08-03
  • 3.8.0 - 2020-08-03
from @typescript-eslint/parser GitHub release notes
Package name: airbnb-browser-shims from airbnb-browser-shims GitHub release notes
Package name: azure-storage
  • 2.10.7 - 2022-01-04
  • 2.10.6 - 2021-12-17
  • 2.10.5 - 2021-10-11
  • 2.10.4 - 2021-05-20
from azure-storage GitHub release notes
Package name: codecov
  • 3.8.2 - 2021-05-03

    3.8.2

    Fixes

    • #304 Add coverage-final.json as a possible coverage file during file lookup
  • 3.8.1 - 2020-11-03

    v3.8.1

    Fixes

    • #246 Revert "Bump teeny-request from 6.0.1 to 7.0.0"
  • 3.8.0 - 2020-10-05

    v3.8.0

    Features

    • #160 Add Github Actions support

    Fixes

    • #173 Fix broken gcov command
    • #195 Update Node testing versions
    • #200 Remove flaky tests
    • #204 Create CHANGELOG and remove flaky v4 test
    • #208 Add license scan report and status
    • #220 Remove errant bitly

    Dependencies

    • #189 Bump lint-staged from 10.0.7 to 10.2.11
    • #190 [Security] Bump handlebars from 4.5.3 to 4.7.6
    • #191 Bump prettier from 1.19.1 to 2.0.5
    • #192 Bump mock-fs from 4.10.4 to 4.12.0
    • #196 Bump teeny-request from 6.0.1 to 7.0.0
    • #197 Bump eslint-config-prettier from 4.3.0 to 6.11.0
    • #198 Bump js-yaml from 3.13.1 to 3.14.0
    • #199 Bump husky from 4.2.1 to 4.2.5
    • #202 Bump eslint from 5.16.0 to 7.7.0
    • #203 Bump jest from 24.9.0 to 26.4.1
    • #205 Bump mock-fs from 4.12.0 to 4.13.0
    • #206 Bump jest from 26.4.1 to 26.4.2
    • #207 Bump prettier from 2.0.5 to 2.1.0
    • #209 Bump lint-staged from 10.2.11 to 10.2.13
    • #210 Bump prettier from 2.1.0 to 2.1.1
    • #212 Bump eslint from 7.7.0 to 7.8.1
    • #214 Bump lint-staged from 10.2.13 to 10.3.0
    • #215 Bump husky from 4.2.5 to 4.3.0
    • #216 Bump node-fetch from 2.6.0 to 2.6.1
    • #217 Bump eslint from 7.8.1 to 7.9.0
    • #218 Bump prettier from 2.1.1 to 2.1.2
    • #219 Bump lint-staged from 10.3.0 to 10.4.0
    • #222 Bump eslint-config-prettier from 6.11.0 to 6.12.0
    • #223 Bump eslint from 7.9.0 to 7.10.0
    • #224 Bump teeny-request from 7.0.0 to 7.0.1
  • 3.7.2 - 2020-07-22
    No content.
  • 3.7.1 - 2020-07-17

    3.7.1

from codecov GitHub release notes
Package name: cross-env from cross-env GitHub release notes
Package name: css-loader from css-loader GitHub release notes
Package name: eslint

Snyk has created this PR to upgrade:
  - babel-jest from 23.4.2 to 23.6.0.
    See this package in npm: https://www.npmjs.com/package/babel-jest
  - @primer/octicons from 10.0.0 to 10.1.0.
    See this package in npm: https://www.npmjs.com/package/@primer/octicons
  - @types/marked from 3.0.1 to 3.0.4.
    See this package in npm: https://www.npmjs.com/package/@types/marked
  - @types/plist from 3.0.2 to 3.0.5.
    See this package in npm: https://www.npmjs.com/package/@types/plist
  - @types/react-color from 3.0.4 to 3.0.12.
    See this package in npm: https://www.npmjs.com/package/@types/react-color
  - @typescript-eslint/eslint-plugin from 3.8.0 to 3.10.1.
    See this package in npm: https://www.npmjs.com/package/@typescript-eslint/eslint-plugin
  - @typescript-eslint/parser from 3.8.0 to 3.10.1.
    See this package in npm: https://www.npmjs.com/package/@typescript-eslint/parser
  - airbnb-browser-shims from 3.0.0 to 3.3.0.
    See this package in npm: https://www.npmjs.com/package/airbnb-browser-shims
  - awesome-node-loader from 1.1.0 to 1.1.1.
    See this package in npm: https://www.npmjs.com/package/awesome-node-loader
  - azure-storage from 2.10.4 to 2.10.7.
    See this package in npm: https://www.npmjs.com/package/azure-storage
  - codecov from 3.7.1 to 3.8.2.
    See this package in npm: https://www.npmjs.com/package/codecov
  - cross-env from 5.1.1 to 5.2.1.
    See this package in npm: https://www.npmjs.com/package/cross-env
  - css-loader from 2.1.0 to 2.1.1.
    See this package in npm: https://www.npmjs.com/package/css-loader
  - eslint from 7.6.0 to 7.32.0.
    See this package in npm: https://www.npmjs.com/package/eslint
  - eslint-config-prettier from 6.11.0 to 6.15.0.
    See this package in npm: https://www.npmjs.com/package/eslint-config-prettier
  - eslint-plugin-prettier from 3.1.4 to 3.4.1.
    See this package in npm: https://www.npmjs.com/package/eslint-plugin-prettier
  - eslint-plugin-react from 7.20.5 to 7.35.0.
    See this package in npm: https://www.npmjs.com/package/eslint-plugin-react
  - fake-indexeddb from 2.0.4 to 2.1.1.
    See this package in npm: https://www.npmjs.com/package/fake-indexeddb
  - jest-extended from 0.11.2 to 0.11.5.
    See this package in npm: https://www.npmjs.com/package/jest-extended
  - jest-localstorage-mock from 2.3.0 to 2.4.26.
    See this package in npm: https://www.npmjs.com/package/jest-localstorage-mock
  - jszip from 3.7.1 to 3.10.1.
    See this package in npm: https://www.npmjs.com/package/jszip
  - mini-css-extract-plugin from 0.4.0 to 0.12.0.
    See this package in npm: https://www.npmjs.com/package/mini-css-extract-plugin
  - parallel-webpack from 2.3.0 to 2.6.0.
    See this package in npm: https://www.npmjs.com/package/parallel-webpack
  - prettier from 2.0.5 to 2.8.8.
    See this package in npm: https://www.npmjs.com/package/prettier
  - request from 2.83.0 to 2.88.2.
    See this package in npm: https://www.npmjs.com/package/request
  - sass from 1.27.0 to 1.77.8.
    See this package in npm: https://www.npmjs.com/package/sass
  - sass-loader from 10.0.3 to 10.5.2.
    See this package in npm: https://www.npmjs.com/package/sass-loader
  - style-loader from 0.21.0 to 0.23.1.
    See this package in npm: https://www.npmjs.com/package/style-loader
  - ts-jest from 26.4.4 to 26.5.6.
    See this package in npm: https://www.npmjs.com/package/ts-jest
  - ts-node from 7.0.0 to 7.0.1.
    See this package in npm: https://www.npmjs.com/package/ts-node
  - tslint from 5.11.0 to 5.20.1.
    See this package in npm: https://www.npmjs.com/package/tslint
  - typescript from 3.9.5 to 3.9.10.
    See this package in npm: https://www.npmjs.com/package/typescript
  - typescript-tslint-plugin from 0.0.6 to 0.5.5.
    See this package in npm: https://www.npmjs.com/package/typescript-tslint-plugin
  - webpack from 4.43.0 to 4.47.0.
    See this package in npm: https://www.npmjs.com/package/webpack
  - webpack-bundle-analyzer from 3.8.0 to 3.9.0.
    See this package in npm: https://www.npmjs.com/package/webpack-bundle-analyzer
  - webpack-dev-middleware from 3.7.2 to 3.7.3.
    See this package in npm: https://www.npmjs.com/package/webpack-dev-middleware
  - webpack-hot-middleware from 2.25.0 to 2.26.1.
    See this package in npm: https://www.npmjs.com/package/webpack-hot-middleware
  - xml2js from 0.4.19 to 0.6.2.
    See this package in npm: https://www.npmjs.com/package/xml2js

See this project in Snyk:
https://app.snyk.io/org/monica-a-nbcu/project/6a27c232-9510-4494-b4a1-82c77c81c600?utm_source=github&utm_medium=referral&page=upgrade-pr
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment