Skip to content
This repository has been archived by the owner on Sep 13, 2024. It is now read-only.

[Snyk] Fix for 1 vulnerabilities #6

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

127001
Copy link
Member

@127001 127001 commented Mar 15, 2024

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • package.json
    • package-lock.json

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
medium severity 718/1000
Why? Proof of Concept exploit, Recently disclosed, Has a fix available, CVSS 6.5
Information Exposure
SNYK-JS-FOLLOWREDIRECTS-6444610
Yes Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: contentful-management The new version differs by 6 commits.
  • 90c5f85 fix: correct fallbackCode type for Locale (#553)
  • b2be22d chore(deps): bump axios from 0.19.2 to 0.21.0 (#514)
  • 3362149 feat: add editors and sidebar to EditorInterface type (#540)
  • 3ca4e41 feat(roles): add support for query params for getRoles method (#536)
  • 2ced68d Add support for query params for getRoles method (#530)
  • 4f29cd7 fix(test): on cleanup explicitly target environment instead of alias (#533)

See the full diff

Package name: contentful-migration The new version differs by 138 commits.
  • 515d4de Use cma plain client (#572)
  • 60a106c Merge pull request #573 from contentful/dependabot/npm_and_yarn/types/node-14.14.10
  • 3936f8e build(deps-dev): bump @ types/node from 14.14.9 to 14.14.10
  • 8485599 Merge pull request #568 from contentful/use-commitizen
  • de1eccf Merge branch 'master' into use-commitizen
  • e06fb6a Merge pull request #566 from contentful/dependabot/npm_and_yarn/eslint-7.14.0
  • 45f3a61 build(deps-dev): bump eslint from 7.13.0 to 7.14.0
  • c709c9f Merge pull request #569 from contentful/dependabot/npm_and_yarn/eslint-plugin-standard-5.0.0
  • 96d9d0d build(deps-dev): bump eslint-plugin-standard from 4.1.0 to 5.0.0
  • c4042d5 chore: add commitizen to ease semver commits
  • 15e25a1 build(deps-dev): bump semantic-release from 17.2.4 to 17.3.0 (#567)
  • 2396646 Merge pull request #564 from contentful/dependabot/npm_and_yarn/npm-user-validate-1.0.1
  • 1a11594 build(deps): [security] bump npm-user-validate from 1.0.0 to 1.0.1
  • f0bb9e4 Merge pull request #563 from contentful/dependabot/npm_and_yarn/types/node-14.14.9
  • aa931ce build(deps-dev): bump @ types/node from 14.14.8 to 14.14.9
  • d421f3f Merge pull request #561 from contentful/dependabot/npm_and_yarn/semantic-release-17.2.4
  • 69cd6b1 build(deps-dev): bump semantic-release from 17.2.3 to 17.2.4
  • 83b8316 Merge pull request #560 from contentful/dependabot/npm_and_yarn/types/node-14.14.8
  • c1ec06b build(deps-dev): bump @ types/node from 14.14.7 to 14.14.8
  • b57c7d5 Merge pull request #558 from contentful/dependabot/npm_and_yarn/npm-user-validate-1.0.1
  • 94bd396 build(deps): [security] bump npm-user-validate from 1.0.0 to 1.0.1
  • c6d444f build(deps): bump contentful-management from 6.3.0 to 6.3.2 (#559)
  • 00592d3 fix(requestUrl): fix double slashes in requestUrl
  • 9afb205 Merge pull request #548 from contentful/dependabot/npm_and_yarn/types/node-14.14.7

See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Learn about vulnerability in an interactive lesson of Snyk Learn.

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants