ndm
ndm copied to clipboard
[Snyk] Security upgrade npm from 4.6.1 to 5.0.1
Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.
Changes included in this PR
- Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
- package.json
Vulnerabilities that will be fixed
With an upgrade:
| Severity | Priority Score (*) | Issue | Breaking Change | Exploit Maturity |
|---|---|---|---|---|
| 661/1000 Why? Recently disclosed, Has a fix available, CVSS 7.5 |
Regular Expression Denial of Service (ReDoS) SNYK-JS-NPMUSERVALIDATE-1019352 |
Yes | No Known Exploit |
(*) Note that the real score may have changed since the PR was raised.
Commit messages
Package name: npm
The new version differs by 241 commits.- 19397ad 5.0.1
- 45b13d9 update AUTHORS
- 25ebbb1 doc: update changelog for [email protected]
- 7e5ce87 [email protected]
- f3cb84b docs: update cli usage for test command (#16771)
- acbe85b view: wait until write completes to call cb (#16791)
- dc2823a docs: package-lock.json is never allowed in tarballs (#16799)
- 80ab521 deps: pull in dependency updates with bugfixes
- e61e68d publish: adapt config for publish RegClient (#16762)
- 9aac984 finalize: Guard against being unable to compute _requested source
- 3cb8432 standard: minor linter fix
- 9f81483 error-handler: remove unused argument (#16757)
- c3e0b42 docs: preserve same name convention for command (#16296)
- 6612623 ls: remove unused argument (#16756)
- 923fd58 utils: Remove slow assertion from module-name util (#16749)
- ebafe48 hamilton: Talk less, complete more (#16750)
- 39495d0 5.0.0
- 0d91907 doc: update changelog for [email protected]
- 8a173da docs: END OF AN ERA OF CHANGELOGS 😭
- 794c10e pkglock: remove packageIntegrity field of doom
- 674004c lifecycle: added prepack and postpack (#16725)
- db76632 [email protected]
- 0d35975 preinstall: Runs in the final dest, not the staging folder
- a976fa1 pacote: more alwaysAuth logic
Check the changes in this PR to ensure they won't cause issues with your project.
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.
For more information:
🧐 View latest project report