[Snyk] Upgrade: node-fetch, xml2js, , dayjs, semver, vscode-tas-client, dockerfile-language-server-nodejs, fs-extra, tar #69
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Snyk has created this PR to upgrade multiple dependencies.
👯♂ The following dependencies are linked and will therefore be updated together.ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.
node-fetch
from 2.6.9 to 2.7.0 | 5 versions ahead of your current version | a year ago
on 2023-08-23
xml2js
from 0.5.0 to 0.6.2 | 3 versions ahead of your current version | a year ago
on 2023-07-26
@azure/storage-blob
from 12.14.0 to 12.24.0 | 112 versions ahead of your current version | 2 months ago
on 2024-07-23
dayjs
from 1.11.7 to 1.11.13 | 6 versions ahead of your current version | 23 days ago
on 2024-08-20
semver
from 7.5.0 to 7.6.3 | 8 versions ahead of your current version | 2 months ago
on 2024-07-16
vscode-tas-client
from 0.1.63 to 0.1.84 | 2 versions ahead of your current version | 7 months ago
on 2024-02-05
dockerfile-language-server-nodejs
from 0.10.2 to 0.13.0 | 3 versions ahead of your current version | 3 months ago
on 2024-06-19
fs-extra
from 11.1.1 to 11.2.0 | 1 version ahead of your current version | 10 months ago
on 2023-11-28
tar
from 6.1.13 to 6.2.1 | 4 versions ahead of your current version | 6 months ago
on 2024-03-21
Issues fixed by the recommended upgrade:
SNYK-JS-AXIOS-6032459
SNYK-JS-FOLLOWREDIRECTS-6141137
SNYK-JS-SEMVER-3247795
SNYK-JS-AXIOS-6124857
SNYK-JS-FOLLOWREDIRECTS-6444610
SNYK-JS-TAR-6476909
Release notes
Package name: node-fetch
2.7.0 (2023-08-23)
Features
AbortError
(#1744) (9b9d458)2.6.13 (2023-08-18)
Bug Fixes
2.6.12 (2023-06-29)
Bug Fixes
2.6.11 (2023-05-09)
Reverts
2.6.10 (2023-05-08)
Bug Fixes
2.6.9 (2023-01-30)
Bug Fixes
Package name: xml2js
New release, 0.6.2
Update version number for release 0.6.1
Release new version
Update package.json with latest PR
Package name: dayjs
1.11.13 (2024-08-20)
Bug Fixes
1.11.12 (2024-07-18)
Bug Fixes
1.11.11 (2024-04-28)
Bug Fixes
1.11.10 (2023-09-19)
Bug Fixes
ar
locale (#2418) (361be5c)1.11.9 (2023-07-01)
Bug Fixes
1.11.8 (2023-06-02)
Bug Fixes
date
parameter as optional (#2222) (b87aa0e)1.11.7 (2022-12-06)
Bug Fixes
Package name: semver
7.6.3 (2024-07-16)
Bug Fixes
73a3d79
#726 optimize Range parsing and formatting (#726) (@ jviide)Documentation
2975ece
#719 fix extra backtick typo (#719) (@ stdavis)7.6.2 (2024-05-09)
Bug Fixes
6466ba9
#713 lru: use map.delete() directly (#713) (@ negezor, @ lukekarrys)7.6.1 (2024-05-04)
Bug Fixes
c570a34
#704 linting: no-unused-vars (@ wraithgar)ad8ff11
#704 use internal cache implementation (@ mbtools)ac9b357
#682 typo in compareBuild debug message (#682) (@ mbtools)Dependencies
988a8de
#709 uninstalllru-cache
(#709)3fabe4d
#704 remove lru-cacheChores
dd09b60
#705 bump @ npmcli/template-oss to 4.22.0 (@ lukekarrys)ec49cdc
#701 chore: chore: postinstall for dependabot template-oss PR (@ lukekarrys)b236c3d
#696 add benchmarks (#696) (@ H4ad)692451b
#688 various improvements to README (#688) (@ mbtools)5feeb7f
#705 postinstall for dependabot template-oss PR (@ lukekarrys)074156f
#701 bump @ npmcli/template-oss from 4.21.3 to 4.21.4 (@ dependabot[bot])7.6.0 (2024-01-31)
Features
a7ab13a
#671 preserve pre-release and build parts of a version on coerce (#671) (@ madtisa, madtisa, @ wraithgar)Chores
816c7b2
#667 postinstall for dependabot template-oss PR (@ lukekarrys)0bd24d9
#667 bump @ npmcli/template-oss from 4.21.1 to 4.21.3 (@ dependabot[bot])e521932
#652 postinstall for dependabot template-oss PR (@ lukekarrys)8873991
#652 chore: chore: postinstall for dependabot template-oss PR (@ lukekarrys)f317dc8
#652 bump @ npmcli/template-oss from 4.19.0 to 4.21.0 (@ dependabot[bot])7303db1
#658 add clean() test for build metadata (#658) (@ jethrodaniel)6240d75
#656 add missing quotes in README.md (#656) (@ zyxkad)14d263f
#625 postinstall for dependabot template-oss PR (@ lukekarrys)7c34e1a
#625 bump @ npmcli/template-oss from 4.18.1 to 4.19.0 (@ dependabot[bot])123e0b0
#622 postinstall for dependabot template-oss PR (@ lukekarrys)737d5e1
#622 bump @ npmcli/template-oss from 4.18.0 to 4.18.1 (@ dependabot[bot])cce6180
#598 postinstall for dependabot template-oss PR (@ lukekarrys)b914a3d
#598 bump @ npmcli/template-oss from 4.17.0 to 4.18.0 (@ dependabot[bot])7.5.4 (2023-07-07)
Bug Fixes
cc6fde2
#588 trim each range set before parsing (@ lukekarrys)99d8287
#583 correctly parse long build ids as valid (#583) (@ lukekarrys)7.5.3 (2023-06-22)
Bug Fixes
abdd93d
#571 set max lengths in regex for numeric and build identifiers (#571) (@ lukekarrys)Documentation
bf53dd8
#569 add example for>
comparator (#569) (@ mbtools)7.5.2 (2023-06-15)
Bug Fixes
58c791f
#566 diff when detecting major change from prerelease (#566) (@ lukekarrys)5c8efbc
#565 preserve build in raw after inc (#565) (@ lukekarrys)717534e
#564 better handling of whitespace (#564) (@ lukekarrys)7.5.1 (2023-05-12)
Bug Fixes
d30d25a
#559 show type on invalid semver error (#559) (@ tjenkinson)Package name: dockerfile-language-server-nodejs
Tag for the v0.13.0 release.
Tag for the v0.12.0 release.
Tag for the v0.11.0 release
Tag for the v0.10.2 release.
Package name: fs-extra
11.2.0
11.1.1
Package name: tar
v6.2.1
6.2.0
6.1.15
6.1.14
6.1.13 (2022-12-07)
Dependencies
cc4e0dd
#343 bump minipass from 3.3.6 to 4.0.0Important
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.
For more information:
[//]: # 'snyk:metadata:{"customTemplate":{"variablesUsed":[],"fieldsUsed":[]},"dependencies":[{"name":"node-fetch","from":"2.6.9","to":"2.7.0"},{"name":"xml2js","from":"0.5.0","to":"0.6.2"},{"name":"","from":"azure/storage-blob","to":"azure/storage-blob"},{"name":"dayjs","from":"1.11.7","to":"1.11.13"},{"name":"semver","from":"7.5.0","to":"7.6.3"},{"name":"vscode-tas-client","from":"0.1.63","to":"0.1.84"},{"name":"dockerfile-language-server-nodejs","from":"0.10.2","to":"0.13.0"},{"name":"fs-extra","from":"11.1.1","to":"11.2.0"},{"name":"tar","from":"6.1.13","to":"6.2.1"}],"env":"prod","hasFixes":true,"isBreakingChange":false,"isMajorUpgrade":false,"issuesToFix":[{"exploit_maturity":"proof-of-concept","id":"SNYK-JS-AXIOS-6032459","issue_id":"SNYK-JS-AXIOS-6032459","priority_score":676,"priority_score_factors":[{"type":"exploit","label":"Proof of Concept","score":107},{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"7.1","score":355},{"type":"scoreVersion","label":"v1","score":1}],"severity":"high","title":"Cross-site Request Forgery (CSRF)"},{"exploit_maturity":"proof-of-concept","id":"SNYK-JS-FOLLOWREDIRECTS-6141137","issue_id":"SNYK-JS-FOLLOWREDIRECTS-6141137","priority_score":686,"priority_score_factors":[{"type":"exploit","label":"Proof of Concept","score":107},{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"7.3","score":365},{"type":"scoreVersion","label":"v1","score":1}],"severity":"high","title":"Improper Input Validation"},{"exploit_maturity":"proof-of-concept","id":"SNYK-JS-SEMVER-3247795","issue_id":"SNYK-JS-SEMVER-3247795","priority_score":696,"priority_score_factors":[{"type":"exploit","label":"Proof of Concept","score":107},{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"7.5","score":375},{"type":"scoreVersion","label":"v1","score":1}],"severity":"high","title":"Regular Expression Denial of Service (ReDoS)"},{"exploit_maturity":"proof-of-concept","id":"SNYK-JS-AXIOS-6124857","issue_id":"SNYK-JS-AXIOS-6124857","priority_score":586,"priority_score_factors":[{"type":"exploit","label":"Proof of Concept","score":107},{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"5.3","score":265},{"type":"scoreVersion","label":"v1","score":1}],"severity":"medium","title":"Regular Expression Denial of Service (ReDoS)"},{"exploit_maturity":"proof-of-concept","id":"SNYK-JS-FOLLOWREDIRECTS-6444610","issue_id":"SNYK-JS-FOLLOWREDIRECTS-6444610","priority_score":646,"priority_score_factors":[{"type":"exploit","label":"Proof of Concept","score":107},{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"6.5","score":325},{"type":"scoreVersion","label":"v1","score":1}],"severity":"medium","title":"Information Exposure"},{"exploit_maturity":"proof-of-concept","id":"SNYK-JS-TAR-6476909","issue_id":"SNYK-JS-TAR-6476909","priority_score":646,"priority_score_factors":[{"type":"exploit","label":"Proof of Concept","score":107},{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"6.5","score":325},{"type":"scoreVersion","label":"v1","score":1}],"severity":"medium","title":"Uncontrolled Resource Consumption ('Resource Exhaustion')"}],"prId":"c057e905-252a-4e77-9a37-6d584d8d122e","prPublicId":"c057e905-252a-4e77-9a37-6d584d8d122e","packageManager":"npm","priorityScoreList":[676,686,696,586,646,646],"projectPublicId":"89fc9fdf-8886-44ee-bb55-53cdb6839141","projectUrl":"https://app.snyk.io/org/sammytezzy/project/89fc9fdf-8886-44ee-bb55-53cdb6839141?utm_source=github&utm_medium=referral&page=upgrade-pr","prType":"upgrade","templateFieldSources":{"branchName":"default","commitMessage":"default","description":"default","title":"default"},"templateVariants":["priorityScore"],"type":"auto","upgrade":["SNYK-JS-AXIOS-6032459","SNYK-JS-FOLLOWREDIRECTS-6141137","SNYK-JS-SEMVER-3247795","SNYK-JS-AXIOS-6124857","SNYK-JS-FOLLOWREDIRECTS-6444610","SNYK-JS-TAR-6476909"],"upgradeInfo":{"versionsDiff":5,"publishedDate":"2023-08-23T17:18:39.396Z"},"vulns":["SNYK-JS-AXIOS-6032459","SNYK-JS-FOLLOWREDIRECTS-6141137","SNYK-JS-SEMVER-3247795","SNYK-JS-AXIOS-6124857","SNYK-JS-FOLLOWREDIRECTS-6444610","SNYK-JS-TAR-6476909"]}'