Skip to content

[Snyk] Upgrade pprof from 3.2.0 to 3.2.1#157

Open
jugnu-appveen wants to merge 1 commit intomainfrom
snyk-upgrade-3b4661cdb86c8f144df932fac7c0f332
Open

[Snyk] Upgrade pprof from 3.2.0 to 3.2.1#157
jugnu-appveen wants to merge 1 commit intomainfrom
snyk-upgrade-3b4661cdb86c8f144df932fac7c0f332

Conversation

@jugnu-appveen
Copy link
Contributor

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to upgrade pprof from 3.2.0 to 3.2.1.

ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


  • The recommended version is 1 version ahead of your current version.
  • The recommended version was released 21 days ago, on 2023-07-24.

The recommended version fixes:

Severity Issue PriorityScore (*) Exploit Maturity
Prototype Pollution
SNYK-JS-PROTOBUFJS-5756498
751/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 8.6
Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Release notes
Package name: pprof
  • 3.2.1 - 2023-07-24

    Security

    • Upgraded protobufjs to ~7.2.4

    What's Changed

    • chore: cherry pick security fixes for v3.2.1 backport [security] by @ aabmass in #263

    Full Changelog: v3.2.0...v3.2.1

  • 3.2.0 - 2021-07-12

    Features

    506c81c feat: add pre-built binaries and support for Node 16 (#172)

    Dependencies

    4f29226 chore(deps): update dependency @ types/tmp to v0.2.1 (#178)
    5e12fc1 build(deps): bump css-what from 5.0.0 to 5.0.1 (#176)
    c2976ca build(deps): bump trim-newlines from 3.0.0 to 3.0.1 (#175)
    002fddc chore(deps): update dependency typescript to ~4.3.0 (#173)
    1c80574 chore(deps): update golang docker tag to v1.16 (#163)
    ff51bc6 chore(deps): update sinon and @ types/sinon (#169)
    4c8f16b chore(deps): update @ types/node to v15 (#167)
    02bc102 chore: run linter (#168)
    43c3f0b fix(deps): update dependency protobufjs to ~6.11.0 (#162)

from pprof GitHub release notes
Commit messages
Package name: pprof
  • d42aaa3 v3.2.1 (#265)
  • 50ebc63 chore: cherry pick security fixes for v3.2.1 backport [security] (#263)

Compare


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

🧐 View latest project report

🛠 Adjust upgrade PR settings

🔕 Ignore this dependency or unsubscribe from future upgrade PRs

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants