Skip to content

chore(deps): Fix for 3 vulnerabilities - #129

Merged
sy-records merged 1 commit into
masterfrom
snyk-fix-f2b10bf8fd8d7c41343630a9a107855f
Jan 10, 2021
Merged

chore(deps): Fix for 3 vulnerabilities#129
sy-records merged 1 commit into
masterfrom
snyk-fix-f2b10bf8fd8d7c41343630a9a107855f

Conversation

@snyk-bot

@snyk-bot snyk-bot commented Jan 7, 2021

Copy link
Copy Markdown
Contributor

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

✨ Snyk has automatically assigned this pull request, set who gets assigned.

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • package.json
    • package-lock.json

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
high severity 691/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 7.4
Cross-site Scripting (XSS)
SNYK-JS-DOCSIFY-567099
No Proof of Concept
medium severity 520/1000
Why? Has a fix available, CVSS 5.9
Regular Expression Denial of Service (ReDoS )
SNYK-JS-MARKED-584281
No No Known Exploit
medium severity 520/1000
Why? Has a fix available, CVSS 5.9
Denial of Service
SNYK-JS-NODEFETCH-674311
No No Known Exploit

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: docsify The new version differs by 206 commits.
  • e474ea8 chore: add changelog 4.11.5
  • dfa5616 [build] 4.11.5
  • d439bac fix: packages/docsify-server-renderer/package.json & packages/docsify-server-renderer/package-lock.json to reduce vulnerabilities (#1250)
  • 1dc754a fix typo (#1345)
  • 5037f0b chore: Remove the src directory from packages.json's files (#1344)
  • 59d090f fix: upgrade tinydate from 1.2.0 to 1.3.0 (#1341)
  • cc071c5 Docs: added carbon ads using docsify-plugin-carbon (#1337)
  • 13cefa9 Merge pull request #1338 from docsifyjs/snyk-upgrade-7969cf0f96a9957be6302d7d7a5f9666
  • 3beaa66 fix: upgrade medium-zoom from 1.0.5 to 1.0.6
  • 1dbb547 chore(deps): bump websocket-extensions from 0.1.3 to 0.1.4 (#1205)
  • 086c285 [Snyk] Security upgrade marked from 0.7.0 to 1.1.1 (#1313)
  • f7be0b0 chore(deps): bump prismjs from 1.19.0 to 1.21.0 (#1331)
  • 8fe83cf chore(deps): bump prismjs in /packages/docsify-server-renderer (#1332)
  • 2bceabc fix: fallback page should use path not file location (#1301)
  • 750663e docs: update other cdn (#1325)
  • 2048610 fix: {docsify-updated} in the sample code is parsed into time (#1321)
  • 9150678 fix typo (#1309)
  • 90d283d fix: convert {docsify-ignore} and {docsify-ignore-all} to HTML comments (#1318)
  • 952f4c9 fix: the uncaught typeerror when el is null (#1308)
  • 1a64dc8 chore: grammatical changes (#1296)
  • aec03d4 Merge pull request #1307 from palkan/feat/search-path-namespaces
  • d179dde feat(search): add pathNamespaces option
  • 78775b6 fix: Search plugin: matched text is replaced with search text (#1298)
  • 9f4f79e fix typo (#1302)

See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report

👩‍💻 Set who automatically gets assigned

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

3 participants