php-assistant
php-assistant copied to clipboard
[Snyk] Fix for 1 vulnerabilities
Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.
Changes included in this PR
- Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
- app/package.json
- app/package-lock.json
Vulnerabilities that will be fixed
With an upgrade:
| Severity | Issue | Breaking Change | Exploit Maturity |
|---|---|---|---|
| Prototype Pollution SNYK-JS-DOTPROP-543489 |
Yes | Proof of Concept |
Commit messages
Package name: configstore
The new version differs by 25 commits.- 310f25f 5.0.0
- b05129a Require Node.js 8
- 6138851 Tidelift tasks
- da89479 Create funding.yml
- f075bc5 Meta tweaks
- 0b26655 Add Tidelift mention in the readme
- 0df1ec9 Mention `conf` in the readme (#62)
- fca8373 4.0.0
- d9b3257 Require Node.js 6
- b8d6372 Do not create a file on read if it doesn't exist (#57)
- 0dc1a8f Add `configPath` option (#58)
- f09f067 3.1.2
- d213757 Add license file
- 35d46bb 3.1.1
- 7bd5030 Pass options object to makeDir.sync (#55)
- 0108c44 Update renamed `electron-config` → `electron-store`
- fbb075d 3.1.0
- a4067fd Bump dependencies and switch to `make-dir`
- f48ba06 Add note about Electron
- 7ce00b4 3.0.0
- 66f605d Simplify the XDG config fallback
- 76fea84 Bump dependencies
- 383b09f Remove the deprecated `.del()` method
- 9ed0378 ES2015ify
Check the changes in this PR to ensure they won't cause issues with your project.
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.
For more information: