php-assistant
php-assistant copied to clipboard
[Snyk] Security upgrade configstore from 2.1.0 to 3.1.0
Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.
Changes included in this PR
- Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
- app/package.json
- app/package-lock.json
Vulnerabilities that will be fixed
With an upgrade:
| Severity | Issue | Breaking Change | Exploit Maturity |
|---|---|---|---|
| Prototype Pollution SNYK-JS-MINIMIST-559764 |
Yes | Proof of Concept |
Commit messages
Package name: configstore
The new version differs by 9 commits.- fbb075d 3.1.0
- a4067fd Bump dependencies and switch to `make-dir`
- f48ba06 Add note about Electron
- 7ce00b4 3.0.0
- 66f605d Simplify the XDG config fallback
- 76fea84 Bump dependencies
- 383b09f Remove the deprecated `.del()` method
- 9ed0378 ES2015ify
- 9c62976 Bump minimum supported `node` version to `node@4`. (#49)
Check the changes in this PR to ensure they won't cause issues with your project.
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.
For more information: