[Snyk] Fix for 1 vulnerabilities #130
Open
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This PR was automatically created by Snyk using the credentials of a real user.
Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.
Changes included in this PR
Vulnerabilities that will be fixed
With an upgrade:
Why? Confidentiality impact: None, Integrity impact: None, Availability impact: High, Scope: Unchanged, Exploit Maturity: No data, User Interaction (UI): None, Privileges Required (PR): None, Attack Complexity: Low, Attack Vector: Network, EPSS: 0.01055, Social Trends: No, Days since published: 0, Reachable: No, Transitive dependency: Yes, Is Malicious: No, Business Criticality: High, Provider Urgency: High, Package Popularity Score: 99, Impact: 5.99, Likelihood: 2.08, Score Version: V5
SNYK-JS-INFLIGHT-6095116
(*) Note that the real score may have changed since the PR was raised.
Release notes
Package name: add-asset-html-webpack-plugin
-
5.0.0 - 2022-03-08
- update globby to v11 (#248) (7265aba), closes #231
-
4.0.1 - 2022-03-08
- include src in npm package (c1cf189)
-
4.0.0 - 2022-03-08
- update micromatch to v4 (#199) (4073291)
- Drops support for Node v6, v8, v10 and v15
-
3.2.2 - 2022-03-08
- remove the hash calculation if hash exists (#159) (8387886)
-
3.2.1 - 2022-03-08
- fix "compilation.emitAsset" with more than 1 HtmlWebpackPlugins (#236) (e84e7d5)
-
3.2.0 - 2021-02-20
- add support for webpack@5 and html-webpack-plugin@5 (#187) (a3c0134)
-
3.1.3 - 2019-01-27
- do not add trailing commas to compiled output (1e6fb04), closes #147
- upgrade dependencies (60c10f0)
-
3.1.2 - 2018-10-31
- add webpack to peer dependencies (08ace07), closes #141
-
3.1.1 - 2018-10-13
- update TS definition (6f74d9c)
-
3.1.0 - 2018-10-13
- add
-
3.0.1 - 2018-09-16
-
3.0.0 - 2018-09-15
from add-asset-html-webpack-plugin GitHub release notes5.0.0 (2022-03-08)
Bug Fixes
BREAKING CHANGES
filenameno longer accepts a glob pattern, that must be passed asglobinstead.4.0.1 (2022-03-08)
Bug Fixes
4.0.0 (2022-03-08)
Bug Fixes
BREAKING CHANGES
3.2.2 (2022-03-08)
Bug Fixes
3.2.1 (2022-03-08)
Bug Fixes
3.2.0 (2021-02-20)
Features
3.1.3 (2019-01-27)
Bug Fixes
3.1.2 (2018-10-31)
Bug Fixes
3.1.1 (2018-10-13)
Bug Fixes
3.1.0 (2018-10-13)
Features
attributesoption (cfb247a)Package name: cacache
-
17.0.5 - 2023-03-21
-
17.0.4 - 2022-12-15
-
17.0.3 - 2022-12-07
-
17.0.2 - 2022-11-04
-
17.0.1 - 2022-10-17
-
17.0.0 - 2022-10-13
⚠️ BREAKING CHANGES
- this module no longer attempts to change file ownership automatically
- this package is now async only, all synchronous methods have been removed
-
16.1.3 - 2022-08-23
- bump unique-filename from 1.1.1 to 2.0.0 (#123) (6235554)
-
16.1.2 - 2022-08-15
- linting (#121) (a683cff)
-
16.1.1 - 2022-06-02
- read: change lstat to stat to correctly evaluate file size (#114) (e3a2928)
-
16.1.0 - 2022-05-17
- allow external integrity/size source (#110) (61785e1)
- move to async functions where possible (#106) (71d4389)
-
16.0.7 - 2022-04-27
-
16.0.6 - 2022-04-21
-
16.0.5 - 2022-04-20
-
16.0.4 - 2022-04-05
-
16.0.3 - 2022-03-22
-
16.0.2 - 2022-03-17
-
16.0.1 - 2022-03-15
-
16.0.0 - 2022-03-14
-
15.3.0 - 2021-08-26
-
15.2.0 - 2021-05-25
-
15.1.0 - 2021-05-19
-
15.0.6 - 2021-03-22
-
15.0.5 - 2020-07-11
-
15.0.4 - 2020-06-03
-
15.0.3 - 2020-04-28
-
15.0.2 - 2020-04-28
-
15.0.1 - 2020-04-28
-
15.0.0 - 2020-02-18
-
14.0.0 - 2020-01-28
-
13.0.1 - 2019-09-30
-
13.0.0 - 2019-09-25
-
12.0.4 - 2020-03-24
-
12.0.3 - 2019-08-19
-
12.0.2 - 2019-07-19
-
12.0.1 - 2019-07-19
-
12.0.0 - 2019-07-15
-
11.3.3 - 2019-06-17
-
11.3.2 - 2018-12-21
-
11.3.1 - 2018-11-05
-
11.3.0 - 2018-11-05
-
11.2.0 - 2018-08-08
-
11.1.0 - 2018-08-01
-
11.0.3 - 2018-08-01
-
11.0.2 - 2018-05-07
-
11.0.1 - 2018-04-10
-
11.0.0 - 2018-04-09
-
10.0.4 - 2018-02-16
from cacache GitHub release notes17.0.5 (2023-03-21)
Dependencies
a6dd005#176 bump glob from 8.1.0 to 9.3.1 (#176)17.0.4 (2022-12-14)
Dependencies
fe71fab#159 bump fs-minipass from 2.1.0 to 3.0.017.0.3 (2022-12-07)
Dependencies
0dc98f7#156 bump minipass from 3.3.6 to 4.0.017.0.2 (2022-11-04)
Bug Fixes
4a7382f#152 replace @ npmcli/move-file with @ npmcli/fs (@ lukekarrys)17.0.1 (2022-10-17)
Dependencies
d3515de#146 bump unique-filename from 2.0.1 to 3.0.0e57ebd9#143 bump ssri from 9.0.1 to 10.0.09dd537a#144 bump @ npmcli/move-file from 2.0.1 to 3.0.017.0.0 (2022-10-13)
cacacheis now compatible with the following semver range for node:^14.17.0 || ^16.13.0 || >=18.0.0Features
479b135#141 do not alter file ownership (#141) (@ nlf)f57bb4d#140 remove sync methods (#140) (@ nlf)cfebcde#133 postinstall for dependabot template-oss PR (@ lukekarrys)16.1.3 (2022-08-23)
Dependencies
16.1.2 (2022-08-15)
Bug Fixes
16.1.1 (2022-06-02)
Bug Fixes
16.1.0 (2022-05-17)
Features
Bug Fixes
Package name: compression-webpack-plugin
-
7.0.0 - 2020-12-02
- minimum supported webpack version is
- the
-
6.1.1 - 2020-11-12
- compatibility with child compilations (5e3bb95)
-
6.1.0 - 2020-11-09
- added the
-
6.0.5 - 2020-11-02
- allowed compressed assets to overwrite original assets using the
-
6.0.4 - 2020-10-26
- always set compression level to maximum for the custom
-
6.0.3 - 2020-10-09
- update
-
6.0.2 - 2020-09-19
- cache invalidation (2284b0c)
-
6.0.1 - 2020-09-16
- respect directories in output (#200) (91382cf)
-
6.0.0 - 2020-09-14
- default value of the
- removed the
- the
- added
- caching (#194) (9de2a88)
- respect
-
5.0.2 - 2020-09-02
- do not crash when the
-
5.0.1 - 2020-08-22
-
5.0.0 - 2020-08-17
-
4.0.1 - 2020-08-12
-
4.0.0 - 2020-05-12
from compression-webpack-plugin GitHub release notes7.0.0 (2020-12-02)
⚠ BREAKING CHANGES
^5.1.0cacheoption was removed, the plugin respects caching from configurations, please read6.1.1 (2020-11-12)
Bug Fixes
6.1.0 (2020-11-09)
Features
keep-source-mapsvalue to thedeleteOriginalAssetsoption (#216) (bd60650)6.0.5 (2020-11-02)
Bug Fixes
deleteOriginalAssetsoption (62d3d0a)6.0.4 (2020-10-26)
Bug Fixes
algorithm(483f328)6.0.3 (2020-10-09)
Chore
schema-utils6.0.2 (2020-09-19)
Bug Fixes
6.0.1 (2020-09-16)
Bug Fixes
⚠ BREAKING CHANGES
filenameoption was changed to"[path][base].gz"[dir]placeholder, please use the[path]placeholderFunctiontype of thefilenameoption should return value with placeholders, please see an exampleFeatures
[fragment],[base]and[path]placeholders for thefilenameoptionBug Fixes
immutableflag for assets5.0.2 (2020-09-02)
Bug Fixes
algorithmoption return nonBuffer(#190) (81bf601)Package name: del
-
6.0.0 - 2020-09-26
- Require Node.js 10 6c99805
- Update dependencies 6c99805
-
5.1.0 - 2019-08-23
- Allow non-glob patterns with backslash on Windows (like v4) (#100) 01da91f
- Make deletion more reliable on Windows by retrying when Windows is being difficult (#108) 1299747
- Sort removed files, so the returned array is always stable (#102) ca05c65
- Fix the
- Prevent race condition on macOS when deleting files (#95) 8efdbcd
-
5.0.0 - 2019-07-02
- Require Node.js 8 42e67a8
- You can no longer pass in paths with backward-slashes. If you need to construct a glob pattern, use
- Update globby from version 6 to version 10 (#64) 6f96d2d
-
4.1.1 - 2019-04-28
- Fix missing TypeScript import 0361dcc
-
4.1.0 - 2019-04-01
- Refactor TypeScript definition to CommonJS compatible export (#82) 3f0d604
-
4.0.0 - 2019-03-03
- Require Node.js 6 434c9f6
- Add TypeScript definition (#81) 34c771e
- Fix typo in error message (#80) e73cc8a
-
3.0.0 - 2017-06-09
- Drops support for Node.js 0.10 and 0.12.
- Adds a
-
2.2.2 - 2016-08-13
from del GitHub release notesBreaking
Improvements
v5.1.0...v6.0.0
Enhancements:
Fixes:
cwdoption (#96) ffbf4c4v5.0.0...v5.1.0
Shoutout to @ chrisblossom for doing most of the work on this release 🙌
This release changes the underlying globbing engine, so you are strongly recommended to use the
dryRunoption to ensuredelstill does what you expect before you run it on the real files.Breaking:
path.posix.join()instead ofpath.join(). You can useslashto transform backward-slash paths to forward-slash paths.Important: If you used any of the
globbyoptions, please note thatglobbyswitched from using theglobpackage tofast-glob, so almost all the option names changed. Here's how to migrate the options.v4.1.1...v5.0.0
For TypeScript users only:
v4.1.0...v4.1.1
v4.0.0...v4.1.0
Breaking:
Enhancements:
v3.0.0...v4.0.0
concurrencyoption.v2.2.2...v3.0.0
2.2.2
Package name: eslint
81aa06bUpgrade: [email protected] (#11869) (Teddy Katz)5f022bcFix: no-else-return autofix produces name collisions (fixes #11069) (#11867) (Milos Djermanovic)ded9548Fix: multiline-comment-style incorrect message (#11864) (golopot)cad074dDocs: Add JSHint W047 compat to no-floating-decimal (#11861) (Timo Tijhof)41f6304Upgrade: sinon (#11855) (Toru Nagashima)167ce87Chore: remove unuseable profile command (#11854) (Toru Nagashima)c844c6fFix: max-len properly ignore trailing comments (fixes #11838) (#11841) (ZYSzys)1b5661aFix: no-var should not fix variables named 'let' (fixes #11830) (#11832) (Milos Djermanovic)4d75956Build: CI with Azure Pipelines (#11845) (Toru Nagashima)1db3462Chore: rm superfluous argument & fix perf-multifiles-targets (#11834) (薛定谔的猫)c57a4a4Upgrade: @ babel/polyfill => core-js v3 (#11833) (薛定谔的猫)65faa04Docs: Clarify prefer-destructuring array/object difference (fixes #9970) (#11851) (Oliver Sieweke)81c3823Fix: require-atomic-updates reports parameters (fixes #11723) (#11774) (Toru Nagashima)aef8ea1Sponsors: Sync README with website (ESLint Jenkins)f403b07Update: introduce minKeys option to sort-keys rule (fixes #11624) (#11625) (Christian)87451f4Fix: no-octal should report NonOctalDecimalIntegerLiteral (fixes #11794) (#11805) (Milos Djermanovic)e4ab053Update: support "bigint" in valid-typeof rule (#11802) (Colin Ihrig)e0fafc8Chore: removes unnecessary assignment in loop (#11780) (Dimitri Mitropoulos)20908a3Docs: removed '>' prefix from from docs/working-with-rules (#11818) (Alok Takshak)1c43eefSponsors: Sync README with website (ESLint Jenkins)21f3131Fix:overrideshandle relative paths as expected (fixes #11577) (#11799) (Toru Nagashima)5509cdfFix: fails the test case if autofix made syntax error (fixes #11615) (#11798) (Toru Nagashima)cb1922bFix: show custom message for namespace import (fixes #11580) (#11791) (Pig Fang)37e5193Update: addendColumnto no-useless-escape (fixes #11629) (#11790) (Pig Fang)ad4b048Build: Fix typo in blog post template (fixes #11614) (#11782) (Kai Cataldo)9590587Update: improve reported location of arrow-parens (fixes #11773) (#11775) (Pig Fang)d662b17New: Add classname attribute to JUnit testcase (refs #11068) (#11683) (Fabio Pitino)8eaa9b2Chore: remove incorrect comment (#11769) (薛定谔的猫)4039a49Chore: add .github/funding.yml (#11764) (Toru Nagashima)9b87feeChore: Fix formatter documentation generation (#11767) (Ilya Volodin)f116208Chore: Fix site generation script for releases (#11766) (Ilya Volodin)cf9cce8Update: Add never option for new-parens (refs #10034) (#11379) (pfgithub)b5fa149New: multiple processors support (fixes #11035, fixes #11725) (#11552) (Toru Nagashima)2d32a9eBreaking: stricter rule config validating (fixes #9505) (#11742) (薛定谔的猫)71716ebUpdate: add fixer for no-div-regex rule (fixes #11355) (#11744) (joe-re)53f7f4cUpdate: Uniform messages for the rules in "complexity" section (#11759) (Igor Novozhilov)0a801d7Chore: improve perf test (#11756) (薛定谔的猫)45bd336Docs: add about RuleTester's parser to migration guide (fixes #11728) (