Skip to content

[Snyk] Upgrade semver from 7.3.5 to 7.6.2 - #4

Open
otmaneEH wants to merge 1 commit into
mainfrom
snyk-upgrade-84fc52fa893dba16210d296eac3ced50
Open

[Snyk] Upgrade semver from 7.3.5 to 7.6.2#4
otmaneEH wants to merge 1 commit into
mainfrom
snyk-upgrade-84fc52fa893dba16210d296eac3ced50

Conversation

@otmaneEH

Copy link
Copy Markdown
Owner

snyk-top-banner

Snyk has created this PR to upgrade semver from 7.3.5 to 7.6.2.

ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


  • The recommended version is 12 versions ahead of your current version.

  • The recommended version was released on 3 months ago.

Issues fixed by the recommended upgrade:

IssueScoreExploit Maturity
high severityDenial of Service (DoS)
SNYK-JS-WS-7266574
275Proof of Concept
high severityDenial of Service (DoS)
SNYK-JS-WS-7266574
275Proof of Concept
high severityDenial of Service (DoS)
SNYK-JS-JPEGJS-2859218
275Proof of Concept
high severityRegular Expression Denial of Service (ReDoS)
SNYK-JS-ANSIREGEX-1583908
275Proof of Concept
high severityPrototype Pollution
SNYK-JS-ASYNC-2441827
275Proof of Concept
high severityInefficient Regular Expression Complexity
SNYK-JS-MICROMATCH-6838728
275No Known Exploit
high severityCross-site Request Forgery (CSRF)
SNYK-JS-AXIOS-6032459
275Proof of Concept
high severityUncontrolled resource consumption
SNYK-JS-BRACES-6838727
275Proof of Concept
high severityImproper Verification of Cryptographic Signature
SNYK-JS-BROWSERIFYSIGN-6037026
275No Known Exploit
high severityImproper Input Validation
SNYK-JS-FOLLOWREDIRECTS-6141137
275Proof of Concept
high severityPrototype Poisoning
SNYK-JS-QS-3153490
275Proof of Concept
high severityRegular Expression Denial of Service (ReDoS)
SNYK-JS-SEMVER-3247795
275Proof of Concept
high severityRegular Expression Denial of Service (ReDoS)
SNYK-JS-SEMVER-3247795
275Proof of Concept
high severityRegular Expression Denial of Service (ReDoS)
SNYK-JS-SEMVER-3247795
275Proof of Concept
medium severityRegular Expression Denial of Service (ReDoS)
SNYK-JS-SIDEWAYFORMULA-3317169
275No Known Exploit
medium severityOpen Redirect
SNYK-JS-GOT-2932019
275No Known Exploit
medium severityOpen Redirect
SNYK-JS-GOT-2932019
275No Known Exploit
medium severityRegular Expression Denial of Service (ReDoS)
SNYK-JS-HTTPCACHESEMANTICS-3248783
275Proof of Concept
medium severityMissing Release of Resource after Effective Lifetime
SNYK-JS-INFLIGHT-6095116
275Proof of Concept
medium severityPrototype Pollution
SNYK-JS-JSON5-3182856
275Proof of Concept
medium severityArbitrary File Write via Archive Extraction (Zip Slip)
SNYK-JS-JSZIP-3188562
275No Known Exploit
medium severityRegular Expression Denial of Service (ReDoS)
SNYK-JS-AXIOS-6124857
275Proof of Concept
critical severityIncomplete List of Disallowed Inputs
SNYK-JS-BABELTRAVERSE-5962462
275Proof of Concept
medium severityExposure of Sensitive Information to an Unauthorized Actor
SNYK-JS-PHIN-6598077
275No Known Exploit
medium severityPrototype Pollution
SNYK-JS-XML2JS-5414874
275Proof of Concept
medium severityOpen Redirect
SNYK-JS-EXPRESS-6474509
275No Known Exploit
medium severityInformation Exposure
SNYK-JS-FOLLOWREDIRECTS-6444610
275Proof of Concept
Release notes
Package name: semver from semver GitHub release notes

Important

  • Check the changes in this PR to ensure they won't cause issues with your project.
  • This PR was automatically created by Snyk using the credentials of a real user.
  • Max score is 1000. Note that the real score may have changed since the PR was raised.

Note:You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

Snyk has created this PR to upgrade semver from 7.3.5 to 7.6.2.
See this package in npm:
semver
See this project in Snyk:
https://app.snyk.io/org/otmaneeh/project/46b0f266-ec1d-486a-8924-87dfaf29c479?utm_source=github&utm_medium=referral&page=upgrade-pr
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@otmaneEH@snyk-bot