vow icon indicating copy to clipboard operation
vow copied to clipboard

[Snyk] Upgrade globby from 8.0.2 to 13.0.0

Open snyk-bot opened this issue 3 years ago • 0 comments

Snyk has created this PR to upgrade globby from 8.0.2 to 13.0.0.

merge advice :information_source: Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


Warning: This is a major version upgrade, and may be a breaking change.

  • The recommended version is 18 versions ahead of your current version.
  • The recommended version was released 21 days ago, on 2022-01-24.

The recommended version fixes:

Severity Issue PriorityScore (*) Exploit Maturity
Regular Expression Denial of Service (ReDoS)
SNYK-JS-GLOBPARENT-1016905
586/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 5.3
Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Release notes
Package name: globby from globby GitHub release notes
Commit messages
Package name: globby
  • 43eccf4 13.0.0
  • b3a9531 Meta tweaks
  • 2e43cc4 Remove `ignore` option for `isGitIgnored` and `isGitIgnoredSync` (#225)
  • 04fbd5b Improve performance with mutiple patterns (#222)
  • f816156 Don't pass `options.ignore` to `isGitIgnored` (#223)
  • 51c8f68 Expose new `generateGlobTasks` and `generateGlobTasksSync` (#221)
  • 93f83f3 Fix `bench` script (#220)
  • 09171d9 Improve task expansion (#219)
  • 65af64f Simplify `expandDirectories` option handling (#218)
  • 128772a Simplify task expansion (#215)
  • e5d6d00 Minor refactoring (#217)
  • c20c630 Improve test coverage (#216)
  • 6cb81ca Apply arguments check logic to `isDynamicPattern` (#214)
  • ffd6b22 Simplify result filter and unique (#213)
  • de3b6fe Remove `array-union` (#211)
  • ac50a7a Fix `generateGlobTasks` call without options (#212)
  • 1852fc5 Fix bug with `objectMode` option (#210)
  • 2c9cc27 Fix typo (#209)
  • 7833ad5 Drop support for checking object with `path` property in function returns by `isGitIgnored` (#208)
  • fc653c7 12.2.0
  • 2e57ffa Fix readme
  • 1224230 Work around TypeScript type problem with `URL` global (#206)
  • a9fc794 Accept `URL` in function returned by `isGitIgnored` (#207)
  • 1be9d02 12.1.0

Compare


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

🧐 View latest project report

🛠 Adjust upgrade PR settings

🔕 Ignore this dependency or unsubscribe from future upgrade PRs

snyk-bot avatar Feb 14 '22 16:02 snyk-bot