[Snyk] Fix for 2 vulnerabilities #159
Open
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This PR was automatically created by Snyk using the credentials of a real user.
Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.
Changes included in this PR
Vulnerabilities that will be fixed
With an upgrade:
Why? Confidentiality impact: None, Integrity impact: None, Availability impact: High, Scope: Unchanged, Exploit Maturity: No data, User Interaction (UI): None, Privileges Required (PR): None, Attack Complexity: Low, Attack Vector: Network, EPSS: 0.01055, Social Trends: No, Days since published: 0, Reachable: No, Transitive dependency: Yes, Is Malicious: No, Business Criticality: High, Provider Urgency: High, Package Popularity Score: 99, Impact: 5.99, Likelihood: 2.08, Score Version: V5
SNYK-JS-BRACES-6838727
Why? Confidentiality impact: None, Integrity impact: None, Availability impact: High, Scope: Unchanged, Exploit Maturity: No data, User Interaction (UI): None, Privileges Required (PR): None, Attack Complexity: Low, Attack Vector: Network, EPSS: 0.01055, Social Trends: No, Days since published: 0, Reachable: No, Transitive dependency: Yes, Is Malicious: No, Business Criticality: High, Provider Urgency: High, Package Popularity Score: 99, Impact: 5.99, Likelihood: 2.08, Score Version: V5
SNYK-JS-MICROMATCH-6838728
(*) Note that the real score may have changed since the PR was raised.
Release notes
Package name: @cypress/browserify-preprocessor
-
3.0.2 - 2021-11-04
- deps: update dependency glob-parent to version 5.1.2 🌟 (#84) (61dae70)
-
3.0.1 - 2020-07-14
- Handle function transforms when
-
3.0.0 - 2020-05-21
- This plugin now requires Node.js 8+
- Validate type of typescript option and its existence as a path (3fb7b2c)
- Improve error when attempting to preprocess a TypeScript file but the typescript option is not set (36d77a8)
-
2.2.4 - 2020-05-11
- generate sourcemaps on .ts and .tsx files (#51) (d64122c)
-
2.2.3 - 2020-05-08
- Only enable TypeScript jsx compiling for
-
2.2.2 - 2020-04-23
- Fix TypeScript iterator support. (#43) (f549896)
-
2.2.1 - 2020-04-04
- Fix lib files not being published (#40) (24117d0)
-
2.2.0 - 2020-04-03
- Add out-of-the-tbox typescript support (#38) (344a057)
-
2.1.4 - 2020-02-11
- Fix non-top-level requires (#37) (642a671)
-
2.1.3 - 2020-02-05
- use newer module exports plugin (#35) (8601521)
-
2.1.2 - 2020-02-05
-
2.1.1 - 2019-06-07
from @cypress/browserify-preprocessor GitHub release notes3.0.2 (2021-11-04)
Miscellaneous
3.0.1 (2020-07-14)
Bug Fixes
typescriptis set (#57) (fb2f417), closes #563.0.0 (2020-05-21)
Breaking Changes
Bug Fixes
2.2.4 (2020-05-11)
Bug Fixes
2.2.3 (2020-05-08)
Bug Fixes
.js,.jsx, and.tsxfiles (#45) (00e9be9)2.2.2 (2020-04-23)
Bug Fixes
2.2.1 (2020-04-04)
Bug Fixes
2.2.0 (2020-04-03)
Features
2.1.4 (2020-02-11)
Bug Fixes
2.1.3 (2020-02-05)
Bug Fixes
Package name: anymatch
-
3.0.0 - 2019-04-10
-
2.0.0 - 2017-12-22
- (Breaking) Bump micromatch to ^3
- Move to micromatch organization
from anymatch GitHub release notesRelease 3.0.0.
Package name: babel-plugin-add-module-exports
-
1.0.2 - 2019-04-17
-
1.0.0 - 2018-09-11
- remove
- change v2 tag
from babel-plugin-add-module-exports GitHub release notesDocumentation
[@ next](https://github.com/next)tag (7fd260d)BREAKING CHANGES
@ latestto@ legacyPackage name: chokidar
-
3.0.0 - 2019-04-30
-
2.1.8 - 2019-08-21
-
2.1.6 - 2019-05-15
-
2.1.5 - 2019-03-22
-
2.1.4 - 2019-03-22
-
2.1.3 - 2019-03-22
-
2.1.2 - 2019-02-18
-
2.1.1 - 2019-02-11
-
2.1.0 - 2019-02-05
-
2.0.4 - 2018-06-18
-
2.0.3 - 2018-03-23
-
2.0.2 - 2018-02-14
-
2.0.1 - 2018-02-08
-
2.0.0 - 2017-12-29
from chokidar GitHub release notesPackage name: jest-config
Blog post: https://jestjs.io/blog/2022/04/25/jest-28
Features
[babel-jest]ExportcreateTransformerfunction (#12399)[expect]ExposeAsymmetricMatchers,MatcherFunctionandMatcherFunctionWithStateinterfaces (#12363, #12376)[jest-circus]Support error logging before retry (#12201)[jest-circus, jest-jasmine2]Allowed classes and functions asdescribeandit/testnames (#12484)[jest-cli, jest-config][BREAKING] RemovetestURLconfig, usetestEnvironmentOptions.urlinstead (#10797)[jest-cli, jest-core]Add--shardparameter for distributed parallel test execution (#12546)[jest-cli][BREAKING] Remove undocumented--timersoption (#12572)[jest-config][BREAKING] Stop shippingjest-environment-jsdomby default (#12354)[jest-config][BREAKING] Stop shippingjest-jasmine2by default (#12355)[jest-config, @ jest/types]AddcitoGlobalConfig(#12378)[jest-config][BREAKING] RenamemoduleLoadertoruntime(#10817)[jest-config][BREAKING] RenameextraGlobalstosandboxInjectedGlobals(#10817)[jest-config][BREAKING] Throw an error instead of showing a warning if multiple configs are used (#12510)[jest-config][BREAKING] Do not normalize long deprecated configuration optionspreprocessorIgnorePatterns,scriptPreprocessor,setupTestFrameworkScriptFileandtestPathDirs(#12701)[jest-cli, jest-core]Add--ignoreProjectsCLI argument to ignore test suites by project name (#12620)[jest-core]Pass project config toglobalSetup/globalTeardownfunction as second argument (#12440)[jest-core]Stabilize test runners with event emitters (#12641)[jest-core, jest-watcher][BREAKING] MoveTestWatcherclass tojest-watcherpackage (#12652)[jest-core]Allow using Summary Reporter as stand-alone reporter (#12687)[jest-environment-jsdom][BREAKING] Upgrade jsdom to 19.0.0 (#12290)[jest-environment-jsdom][BREAKING] Add defaultbrowsercondition toexportConditionsforjsdomenvironment (#11924)[jest-environment-jsdom][BREAKING] Pass global config to Jest environment constructor forjsdomenvironment (#12461)[jest-environment-jsdom][BREAKING] Second argumentcontextto constructor is mandatory (#12469)[jest-environment-node][BREAKING] Add defaultnodeandnode-addonconditions toexportConditionsfornodeenvironment (#11924)[jest-environment-node][BREAKING] Pass global config to Jest environment constructor fornodeenvironment (#12461)[jest-environment-node][BREAKING] Second argumentcontextto constructor is mandatory (#12469)[jest-environment-node]Add all available globals to test globals, not just explicit ones (#12642, #12696)[@ jest/expect]New module which extendsexpectwithjest-snapshotmatchers (#12404, #12410, #12418)[@ jest/expect-utils]New module exporting utils forexpect(#12323)[@ jest/fake-timers][BREAKING] Renametimersconfiguration option tofakeTimers(#12572)[@ jest/fake-timers][BREAKING] Allowjest.useFakeTimers()andprojectConfig.fakeTimersto take an options bag (#12572)[jest-haste-map][BREAKING]HasteMap.createnow returns a promise (#12008)[jest-haste-map]Add support fordependencyExtractorwritten in ESM (#12008)[jest-mock][BREAKING] Rename exported utility typesClassLike,FunctionLike,ConstructorLikeKeys,MethodLikeKeys,PropertyLikeKeys; remove exports of utility typesArgumentsOf,ArgsType,ConstructorArgumentsOf- TS builtin utility typesConstructorParametersandParametersshould be used instead (#12435, #12489)[jest-mock]ImproveisMockFunctionto infer types of passed function (#12442)[jest-mock][BREAKING] Improve the usage ofjest.fngeneric type argument (#12489)[jest-mock]Add support for auto-mocking async generator functions (#11080)[jest-mock]Addcontextsmember to mock functions (#12601)[@ jest/reporters]Add GitHub Actions reporter (#11320, #12658)[@ jest/reporters]PassreporterContextto custom reporter constructors as third argument (#12657)[jest-resolve][BREAKING] Add support forpackage.jsonexports(#11961, #12373)[jest-resolve]Support package self-reference (#12682)[jest-resolve, jest-runtime]Add support fordata:URI import and mock (#12392)[jest-resolve, jest-runtime]Add support for async resolver (#11540)[jest-resolve][BREAKING] Removebrowser?: booleanfrom resolver options,conditions: ['browser']should be used instead (#12707)[jest-resolve]ExposeJestResolver,AsyncResolver,SyncResolver,PackageFilter,PathFilterandPackageJSONtypes (#12707, (#12712)[jest-runner]AllowsetupFilesmodule to export an async function (#12042)[jest-runner]Allow passingtestEnvironmentOptionsvia docblocks (#12470)[jest-runner]ExposeCallbackTestRunner,EmittingTestRunnerabstract classes andCallbackTestRunnerInterface,EmittingTestRunnerInterfaceto help typing third party runners (#12646, #12715)[jest-runner]Lock version ofsource-map-supportto 0.5.13 (#12720)[jest-runtime][BREAKING]Runtime.createHasteMapnow returns a promise (#12008)[jest-runtime]Callingjest.resetModulesfunction will clear FS and transform cache (#12531)[jest-runtime][BREAKING] RemoveContexttype export, it must be imported from@ jest/test-result(#12685)[jest-runtime]Addimport.meta.jest(#12698)[@ jest/schemas]New module for JSON schemas for Jest's config (#12384)[@ jest/source-map]Migrate fromsource-mapto@ jridgewell/trace-mapping(#12692)[jest-transform][BREAKING] Make it required forprocess()andprocessAsync()methods to always return structured data (#12638)[jest-test-result]Add duration property to JSON test output (#12518)[jest-watcher][BREAKING] MakePatternPromptclass to takeentityNameas third constructor parameter instead ofthis._entityName(#12591)[jest-worker][BREAKING] Allow only absoluteworkerPath(#12343)[jest-worker][BREAKING] Default to advanced serialization when using child process workers (#10983)[pretty-format]NewmaxWidthparameter (#12402)Fixes
[*]Usesha256instead ofmd5as hashing algortihm for compatibility with FIPS systems (#12722)[babel-jest][BREAKING] PassrootDirasrootin Babel's options (#12689)[expect]Move typings of.not,.rejectsand.resolvesmodifiers outside ofMatchersinterface (#12346)[expect]Throw useful error ifexpect.extendis called with invalid matchers (#12488)[expect]FixiterableEqualityignores other properties (#8359)[expect]Fix print for thecloseTomatcher (#12626)[jest-changed-files]ImprovechangedFilesWithAncestorpattern for Mercurial SCM (#12322)[jest-circus, @ jest/types]Disallow undefined value inTestContexttype (#12507)[jest-config]Correctly detect CI environment and update snapshots accordingly (#12378)[jest-config]PassmoduleTypestots-nodeto enforce CJS when transpiling (#12397)[jest-config][BREAKING] Addmjsandcjsto defaultmoduleFileExtensionsconfig (#12578)[jest-config, jest-haste-map]Allow searching for tests innode_modulesby exposingretainAllFiles(#11084)[jest-core][BREAKING] Exit with status1if no tests are found with--findRelatedTestsflag (#12487)[jest-core]Do not report unref-ed subprocesses as open handles (#12705)[jest-each]%#is not replaced with index of the test case (#12517)[jest-each]Fixes error message with incorrect count of missing arguments (#12464)[jest-environment-jsdom]Makejsdomaccessible to extending environments again (#12232)[jest-environment-jsdom]Log JSDOM errors more cleanly (#12386)[jest-environment-node]AddMessageChannel,MessageEventto globals (#12553)[jest-environment-node]AddstructuredCloneto globals (#12631)[@ jest/expect-utils][BREAKING] Fix false positives when looking forundefinedprop (#8923)[jest-haste-map]Don't use partial results if file crawl errors (#12420)[jest-haste-map]Make watchman existence check lazy+async (#12675)[jest-jasmine2, jest-types][BREAKING] Move alljasminespecific types from@ jest/typesto its own package (#12125)[jest-jasmine2]Do not setdurationto0for skipped tests (#12518)[jest-matcher-utils]Pass maxWidth topretty-formatto avoid printing every element in arrays by default (#12402)[jest-mock]Fix function overloads forspyOnto allow more correct type inference in complex object (#12442)[jest-mock]Handle overriddenFunction.nameproperty (#12674)[@ jest/reporters]Notifications generated by the--notifyflag are no longer persistent in GNOME Shell. (#11733)[@ jest/reporters]Move missing icon file which is needed forNotifyReporterclass. (#12593)[@ jest/reporters]Updatev8-to-istanbul(#12697)[jest-resolver]Call custom resolver with core node.js modules (#12654)[jest-runner]Correctly resolvesource-map-support(#12706)[jest-worker]FixFarmexecution results memory leak (#12497)Chore & Maintenance
[*][BREAKING] Drop support for Node v10 and v15 and target first LTS16.13.0(#12220)[*][BREAKING] Drop support for[email protected], minimum version is now4.3(#11142, #12648)[*]Bundle all.d.tsfiles into a singleindex.d.tsper module (#12345)[*]UseglobalThisinstead ofglobal(#12447)[babel-jest][BREAKING] Only exportcreateTransformer(#12407)[docs]Add note about not mixingdone()with Promises (#11077)[docs, examples]Update React examples to match with the new React guidelines for code examples (#12217)[docs]Add clarity for module factory hoisting limitations (#12453)[docs]Add more information about how code transformers work (#12407)[docs]Add upgrading guide (#12633)[expect][BREAKING] Remove support for importingbuild/utils(#12323)[expect][BREAKING] Migrate to ESM (#12344)[expect][BREAKING] Snapshot matcher types are moved to@ jest/expect(#12404)[jest-cli]Updateyargsto v17 (#12357)[jest-config][BREAKING] RemovegetTestEnvironmentexport (#12353)[jest-config][BREAKING] Rename config optionnametoid(#11981)[jest-create-cache-key-function]Added README.md file with basic usage instructions (#12492)[@ jest/core]Useindex.tsinstead ofjest.tsas main export (#12329)[jest-environment-jsdom][BREAKING] Migrate to ESM (#12340)[jest-environment-node][BREAKING] Migrate to ESM (#12340)[jest-haste-map]Remove legacyisRegExpSupported(#12676)[@ jest/fake-timers]Update@ sinonjs/fake_timersto v9 (#12357)[jest-jasmine2, jest-runtime][BREAKING] UseSymbolto passjest.setTimeoutvalue instead ofjasminespecific logic (#12124)[jest-phabricator][BREAKING] Migrate to ESM (#12341)[jest-resolve][BREAKING] MakerequireResolveFunctionargument mandatory (#12353)[jest-runner][BREAKING] Remove some type exports from@ jest/test-result(#12353)[jest-runner][BREAKING] Second argument to constructor (Context) is not optional (#12640)[jest-serializer][BREAKING] Deprecate package in favour of usingv8APIs directly (#12391)[jest-snapshot][BREAKING] Migrate to ESM (#12342)[jest-transform]Updatewrite-file-atomicto v4 (#12357)[jest-types][BREAKING] RemoveConfig.GlobandConfig.Path(#12406)[jest]Useindex.tsinstead ofjest.tsas main export (#12329)Performance
[jest-haste-map][BREAKING] Default tonodecrawler over shelling out tofindifwatchmanis not enabled (#12320)New Contributors