npm-updater
npm-updater copied to clipboard
[Snyk] Fix for 1 vulnerabilities
Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.
Changes included in this PR
- Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
- package.json
Vulnerabilities that will be fixed
With an upgrade:
| Severity | Issue | Breaking Change | Exploit Maturity |
|---|---|---|---|
| Prototype Pollution SNYK-JS-DOTPROP-543489 |
Yes | Proof of Concept |
Commit messages
Package name: configstore
The new version differs by 11 commits.- 310f25f 5.0.0
- b05129a Require Node.js 8
- 6138851 Tidelift tasks
- da89479 Create funding.yml
- f075bc5 Meta tweaks
- 0b26655 Add Tidelift mention in the readme
- 0df1ec9 Mention `conf` in the readme (#62)
- fca8373 4.0.0
- d9b3257 Require Node.js 6
- b8d6372 Do not create a file on read if it doesn't exist (#57)
- 0dc1a8f Add `configPath` option (#58)
Check the changes in this PR to ensure they won't cause issues with your project.
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.
For more information: