Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Snyk] Fix for 1 vulnerabilities #18

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

snyk-bot
Copy link

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • package.json

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
high severity 768/1000
Why? Proof of Concept exploit, Recently disclosed, Has a fix available, CVSS 7.5
Prototype Pollution
SNYK-JS-ASYNC-2441827
Yes Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: google-auth-library The new version differs by 8 commits.
  • 480ab2d Prepare for 0.10.0 release. (#116)
  • 341e9e3 Fix oauth2 token refresh (#109)
  • 373a741 Add yarn.lock file. (#113)
  • aa7b8a1 Remove unused dependencies and upgrade remaining dependencies.
  • 1f51a86 Improve repo licensing. (#115)
  • aa40bb7 Improve dev scripts. (#114)
  • de0044e bump jws version to 3.1.0 (#108)
  • 968bf1c update dependencies and add david-dm badge (#106)

See the full diff

Package name: googleapis The new version differs by 225 commits.
  • f9336af chore: release 26.0.1 (#997)
  • 7c95fb4 chore(package): update @ types/node to version 9.4.5 (#994)
  • a0f6332 chore(package): update @ types/node to version 9.4.3 (#992)
  • 51a57b9 chore(package): update @ types/node to version 9.4.2 (#990)
  • 9ecd78b chore(package): update @ types/node to version 9.4.1 (#987)
  • ab38db3 chore: unify release notes (#984)
  • 0b42287 chore: fix and run generator (#981)
  • a97d41d chore(package): update @ types/mocha to version 2.2.48 (#980)
  • 2012a59 chore: improve typing (#975)
  • 0ea5654 chore: make a few generator APIs async (#970)
  • cda3604 chore(package): update @ types/node to version 9.4.0 (#973)
  • ca1f910 chore: improve typing (#968)
  • 8d56eac chore: improve typing and build (#967)
  • 0b806da chore: remove .npmignore (#966)
  • 30e8c15 chore(package): update source-map-support to version 0.5.3 (#965)
  • 6258b40 test: fix windows issues with appveyor magic (#962)
  • e6f2a5d test: add test for typescript d.ts (#958)
  • f78d239 chore: enable stricter compilation for the generator (#961)
  • 8318e7e fix: add files section to package.json (#959)
  • 098c2ae docs: update readme to reflect new api (#960)
  • 4de975d Create .appveyor.yml (#954)
  • 619a017 feat: distribute functional d.ts (#943)
  • 48a290b chore(package): update @ types/mocha to version 2.2.47 (#950)
  • eb9e1d9 chore: upgrade to the latest google-auth-library and fix the build (#953)

See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Prototype Pollution

The following vulnerabilities are fixed with an upgrade:
- https://snyk.io/vuln/SNYK-JS-ASYNC-2441827
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant