Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

build(deps): npm audit fix #1237

Merged
merged 2 commits into from
Aug 30, 2023
Merged

build(deps): npm audit fix #1237

merged 2 commits into from
Aug 30, 2023

Conversation

ybiquitous
Copy link
Owner

@ybiquitous ybiquitous commented Aug 29, 2023

This pull request fixes the vulnerable packages via npm 9.8.1.

Updated (6)
Package Version Source Detail
@mdn/browser-compat-data 5.2.595.3.14 github -
browserslist 4.21.54.21.10 github -
caniuse-lite 1.0.300014881.0.30001524 github -
electron-to-chromium 1.4.4021.4.505 github -
eslint-plugin-compat 4.1.44.2.0 github -
node-releases 2.0.102.0.13 github -
Removed (2)
Package Version Source Detail
lru-cache (eslint-plugin-compat/node_modules/lru-cache) 6.0.0 github -
semver (eslint-plugin-compat/node_modules/semver) 7.3.8 github [Moderate] semver vulnerable to Regular Expression Denial of Service (ref)

Created by ybiquitous/npm-audit-fix-action

@ybiquitous ybiquitous added dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code security Pull requests that address a security vulnerability labels Aug 29, 2023
Summary:
- Updated packages: 6
- Added packages: 0
- Removed packages: 2

Fixed vulnerabilities:
- semver: "semver vulnerable to Regular Expression Denial of Service" (GHSA-c2qf-rxjj-qqgw)
@github-actions github-actions bot force-pushed the npm-audit-fix-action/fix branch from ac78186 to 3094eb6 Compare August 30, 2023 00:09
@ybiquitous ybiquitous enabled auto-merge (squash) August 30, 2023 02:10
@ybiquitous ybiquitous merged commit 4d356bc into main Aug 30, 2023
@ybiquitous ybiquitous deleted the npm-audit-fix-action/fix branch August 30, 2023 02:11
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code security Pull requests that address a security vulnerability
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant