Skip to content

Conversation

@snyk-bot
Copy link

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • package.json

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
high severity 589/1000
Why? Has a fix available, CVSS 7.5
Regular Expression Denial of Service (ReDoS)
SNYK-JS-MINIMATCH-1019388
Yes No Known Exploit

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: vinyl-fs The new version differs by 100 commits.
  • de7bf7b 2.0.0
  • 59620dc update vinyl
  • 5b056f6 update object-assign dep
  • 27983ef merge
  • 7ca959e remove watch #92
  • b9b9469 Merge pull request #90 from davidbarrows/with-updated-merge-stream-to-1.0.0
  • 22e5e13 Updated merge-stream version to 1.0.0
  • 5192dec Merge pull request #88 from kketch/fix-event-name
  • 65445ec fix wrong event name in README.md
  • cb22635 Merge pull request #85 from Klowner/symlink-passthru-support
  • 9f5f6e8 Add symlink copy with `followSymlinks` option
  • fa184c4 Merge pull request #82 from stevemao/patch-2
  • 0b3eed2 symlink opt.base should be the same as dest
  • 3e2a5ef base can be a function now, also add better error messaging. closes #78
  • c7887c1 Merge pull request #81 from silverwind/patch-1
  • 69090c4 use valid semver range for `engine`
  • 65090b8 Merge branch 'master' of https://github.com/wearefractal/vinyl-fs
  • b481130 fix filter-since
  • 30a8507 Merge pull request #79 from stevemao/improvements
  • 8e8135c update vinyl-filter-since
  • cb86d86 add missing test for f7516ebac102104ad0f39437f7739bf5aedec165
  • a8161c8 update vinyl filter since
  • 99db7de add sourcemaps to dest, clear up some dead src code now that empty arrays arent valid globs, dep updates
  • d32876f update deps

See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic

The following vulnerabilities are fixed with an upgrade:
- https://snyk.io/vuln/SNYK-JS-MINIMATCH-1019388
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants