Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Snyk] Fix for 1 vulnerabilities #3

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

snyk-bot
Copy link

@snyk-bot snyk-bot commented Sep 2, 2021

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • package.json

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
medium severity 636/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 6.3
Prototype Pollution
npm:hoek:20180212
Yes Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: hapi The new version differs by 156 commits.
  • 0c8109e Allow disabling ranges support. Closes #3015
  • 81f5f58 Another test for #2979
  • ce695c4 Cleanup for #3072
  • 9471e34 Merge pull request #3072 from geek/master
  • 8b51062 Merge pull request #3069 from craigswatman/master
  • 138881d Merge upstream
  • b96a8c6 Merge pull request #3057 from gergoerdosi/initialize
  • 6fdbf6e Cleanup for #3034
  • e2553fe Merge pull request #3034 from pra85/patch-1
  • be547a9 Support late cache provision. Closes #3077. Closes #3078. Closes #3079. Closes #3080. Closes #3081. Closes #3082. Closes #3083
  • 6804ac2 Merge pull request #3074 from mattii/master
  • da2bf26 Update API.md: updated request.app description
  • a63746e Update API.md: fixed line-break
  • 72b135e Update API.md: added a more precise description for `request.app`
  • 9b4d8da Better test and document reply realm
  • 6e550bb Demonstrate issue with realm and plugin options
  • 4795b39 Merge pull request #3071 from rluba/patch-1
  • 1eb9ec0 Fix description of server.state option ignoreErrors
  • 0eadc7d Merge branch 'master' of github.com:hapijs/hapi
  • e0bb076 Minor shuffle
  • 9c6b287 Pass through cookie options when calling reply.unstate()
  • 0b7acac Merge pull request #3062 from gergoerdosi/server-stop-callback
  • 121ed53 Fix callback function signature
  • 65a4ad0 Rename errorCallback to NextTickCallback

See the full diff

Package name: inert The new version differs by 23 commits.

See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic

The following vulnerabilities are fixed with an upgrade:
- https://snyk.io/vuln/npm:hoek:20180212
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant