Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Snyk] Upgrade eslint-plugin-jest from 24.1.3 to 24.3.6 #27

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

snyk-bot
Copy link
Contributor

@snyk-bot snyk-bot commented Jun 7, 2021

Snyk has created this PR to upgrade eslint-plugin-jest from 24.1.3 to 24.3.6.

merge advice
ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


  • The recommended version is 16 versions ahead of your current version.
  • The recommended version was released a month ago, on 2021-04-26.

The recommended version fixes:

Severity Issue PriorityScore (*) Exploit Maturity
Command Injection
SNYK-JS-LODASH-1040724
467/1000
Why? Proof of Concept exploit, CVSS 7.2
Proof of Concept
Regular Expression Denial of Service (ReDoS)
SNYK-JS-LODASH-1018905
467/1000
Why? Proof of Concept exploit, CVSS 7.2
Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Release notes
Package name: eslint-plugin-jest from eslint-plugin-jest GitHub release notes
Commit messages
Package name: eslint-plugin-jest
  • 4859391 chore(release): 24.3.6 [skip ci]
  • 7b7a396 fix(valid-expect): support async `expect` in ternary statements (#833)
  • 1fee973 fix(no-conditional-expect): check for expects in `catch`s on promises (#819)
  • 040c605 fix: improve handling of `.each` calls and with tagged literals (#814)
  • 6536594 docs: add eslint plugin istanbul (#831)
  • 127c12a chore(ci): add Node v16 (#829)
  • 913bc73 chore(deps): lock file maintenance (#827)
  • 004a9cb docs(expect-expect): change suggested rule config (#825)
  • fb5eb5e chore(deps): update actions/cache action to v2.1.5 (#824)
  • 0ca3d39 chore(deps): lock file maintenance (#823)
  • 96dfa33 chore(deps): lock file maintenance (#812)
  • 9c31a8d chore(release): 24.3.5 [skip ci]
  • cbdbcef fix(valid-describe): support using `each` with modifiers (#820)
  • ce76579 docs(no-focused-tests): remove references to `ftest` method (#816)
  • 72fe0c6 chore(deps): update codecov/codecov-action action to v1.3.2 (#815)
  • 3b8c36c chore(release): 24.3.4 [skip ci]
  • 0968b55 fix: support all variations of `describe`, `it`, & `test` (#792)
  • d68093b test(no-identical-title): use `dedent` instead of `join('\n')` (#808)
  • aeb267f chore(deps): lock file maintenance (#805)
  • 7a1ab7a chore(release): 24.3.3 [skip ci]
  • f758243 fix(prefer-expect-assertions): support `.each` (#798)
  • 243cb4f fix(no-duplicate-hooks): support `describe.each` (#797)
  • 5945772 chore(deps): update dependency husky to v6 (#806)
  • 1b9d57d chore(deps): update danger/danger-js action to v10.6.4 (#800)

Compare


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

🧐 View latest project report

🛠 Adjust upgrade PR settings

🔕 Ignore this dependency or unsubscribe from future upgrade PRs

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant