Skip to content

Conversation

@snyk-bot
Copy link

Snyk has created this PR to upgrade eslint from 7.21.0 to 7.23.0.

merge advice
ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


  • The recommended version is 2 versions ahead of your current version.
  • The recommended version was released 25 days ago, on 2021-03-26.

The recommended version fixes:

Severity Issue PriorityScore (*) Exploit Maturity
Command Injection
SNYK-JS-LODASH-1040724
467/1000
Why? Proof of Concept exploit, CVSS 7.2
Proof of Concept
Command Injection
SNYK-JS-NODENOTIFIER-1035794
467/1000
Why? Proof of Concept exploit, CVSS 7.2
No Known Exploit
Regular Expression Denial of Service (ReDoS)
SNYK-JS-LODASH-1018905
467/1000
Why? Proof of Concept exploit, CVSS 7.2
Proof of Concept
Regular Expression Denial of Service (ReDoS)
SNYK-JS-HOSTEDGITINFO-1088355
467/1000
Why? Proof of Concept exploit, CVSS 7.2
Proof of Concept
Regular Expression Denial of Service (ReDoS)
SNYK-JS-GLOBPARENT-1016905
467/1000
Why? Proof of Concept exploit, CVSS 7.2
No Known Exploit
Regular Expression Denial of Service (ReDoS)
SNYK-JS-GLOBPARENT-1016905
467/1000
Why? Proof of Concept exploit, CVSS 7.2
No Known Exploit

(*) Note that the real score may have changed since the PR was raised.

Release notes
Package name: eslint
  • 7.23.0 - 2021-03-26
    • 687ccae Update: add option "allowInParentheses" to no-sequences (fixes #14197) (#14199) (Daniel Rentz)
    • dbf2529 Sponsors: Sync README with website (ESLint Jenkins)
    • 4bdf2c1 Sponsors: Sync README with website (ESLint Jenkins)
    • 49d1697 Chore: Upgrade eslint-plugin-jsdoc to v25 and remove --legacy-peer-deps (#14244) (Brandon Mills)
    • 43f1685 Update: --quiet should not supress --max-warnings (fixes #14202) (#14242) (Milos Djermanovic)
    • 909c727 Docs: Add valid example that shows vars in a block scope (#14230) (Ed S)
    • 28583eb Fix: no-mixed-operators false positives with ? : (fixes #14223) (#14226) (Milos Djermanovic)
    • a99eb2d Fix: Clarify line breaks in object-curly-newline (fixes #14024) (#14063) (armin yahya)
    • 8984c91 Update: eslint --env-info output os info (#14059) (薛定谔的猫)
    • 2a79306 Sponsors: Sync README with website (ESLint Jenkins)
    • ebd7026 Docs: Fix typo (#14225) (Greg Finley)
    • a2013fc Sponsors: Sync README with website (ESLint Jenkins)
  • 7.22.0 - 2021-03-12
    • 3a432d8 Docs: Improve documentation for indent rule (#14168) (Serkan Özel)
    • f62ec8d Update: throw error when fix range is invalid (#14142) (Jacob Bandes-Storch)
    • 0eecad2 Upgrade: Update lodash in package.json to V 4.17.21 (#14159) (Basem Al-Nabulsi)
    • 5ad91aa Update: report es2021 globals in no-extend-native (refs #13602) (#14177) (Milos Djermanovic)
    • c295581 Chore: remove leftover JSDoc from lint-result-cache (#14176) (Milos Djermanovic)
    • 0d541f9 Chore: Reduce lodash usage (#14178) (Stephen Wade)
    • 27a67d7 Sponsors: Sync README with website (ESLint Jenkins)
    • 459d821 Chore: upgrade dependencies of browser test (#14127) (Pig Fang)
    • ebfb63a Sponsors: Sync README with website (ESLint Jenkins)
    • 3ba029f Docs: Remove Extraneous Dash (#14164) (Danny Hurlburt)
    • 6f4540e Sponsors: Sync README with website (ESLint Jenkins)
    • ddf361c Docs: Fix Formatting (#14154) (Danny Hurlburt)
    • c0d2ac1 Sponsors: Sync README with website (ESLint Jenkins)
    • a8df03e Docs: Clarify triage process (#14117) (Nicholas C. Zakas)
  • 7.21.0 - 2021-02-27
    • 3cd5440 Upgrade: @ eslint/eslintrc to 0.4.0 (#14147) (Brandon Mills)
    • c0b8c71 Upgrade: Puppeteer to 7.1.0 (#14122) (Tim van der Lippe)
    • 08ae31e New: Implement cacheStrategy (refs eslint/rfcs#63) (#14119) (Manu Chambon)
    • 5e51fd2 Update: do not ignore symbolic links (fixes #13551, fixes #13615) (#14126) (Pig Fang)
    • 87c43a5 Chore: improve a few comments and fix typos (#14125) (Tobias Nießen)
    • e19c51e Sponsors: Sync README with website (ESLint Jenkins)
    • b8aea99 Fix: pluralize 'line' to 'lines' in max-lines-per-function description (#14115) (Trevin Hofmann)
    • f5b53e2 Sponsors: Sync README with website (ESLint Jenkins)
    • eee1213 Sponsors: Sync README with website (ESLint Jenkins)
    • 5c4d7ea Sponsors: Sync README with website (ESLint Jenkins)
from eslint GitHub release notes
Commit messages
Package name: eslint
  • cd2e584 7.23.0
  • 11bdeab Build: changelog update for 7.23.0
  • 687ccae Update: add option "allowInParentheses" to no-sequences (fixes #14197) (#14199)
  • dbf2529 Sponsors: Sync README with website
  • 4bdf2c1 Sponsors: Sync README with website
  • 49d1697 Chore: Upgrade eslint-plugin-jsdoc to v25 and remove --legacy-peer-deps (#14244)
  • 43f1685 Update: `--quiet` should not supress `--max-warnings` (fixes #14202) (#14242)
  • 909c727 Docs: Add valid example that shows vars in a block scope (#14230)
  • 28583eb Fix: no-mixed-operators false positives with `? :` (fixes #14223) (#14226)
  • a99eb2d Fix: Clarify line breaks in object-curly-newline (fixes #14024) (#14063)
  • 8984c91 Update: eslint --env-info output os info (#14059)
  • 2a79306 Sponsors: Sync README with website
  • ebd7026 Docs: Fix typo (#14225)
  • a2013fc Sponsors: Sync README with website
  • 6ee8037 7.22.0
  • a55e8a1 Build: changelog update for 7.22.0
  • 3a432d8 Docs: Improve documentation for indent rule (#14168)
  • f62ec8d Update: throw error when fix range is invalid (#14142)
  • 0eecad2 Upgrade: Update lodash in package.json to V 4.17.21 (#14159)
  • 5ad91aa Update: report es2021 globals in no-extend-native (refs #13602) (#14177)
  • c295581 Chore: remove leftover JSDoc from lint-result-cache (#14176)
  • 0d541f9 Chore: Reduce lodash usage (#14178)
  • 27a67d7 Sponsors: Sync README with website
  • 459d821 Chore: upgrade dependencies of browser test (#14127)

Compare


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

🧐 View latest project report

🛠 Adjust upgrade PR settings

🔕 Ignore this dependency or unsubscribe from future upgrade PRs

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants