Skip to content

Conversation

@snyk-bot
Copy link

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • package.json

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
low severity 471/1000
Why? Recently disclosed, Has a fix available, CVSS 3.7
Prototype Pollution
SNYK-JS-MINIMIST-2429795
Yes No Known Exploit

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: gulp-util The new version differs by 23 commits.
  • f6336c8 3.0.1
  • 1a65071 update deps
  • c5e8da4 3.0.0
  • f7ee76e Merge pull request #58 from mtscout6/properties-message
  • 8ebecbc DRYed up some minor points
  • a2b47fb Added _stack to list of properties not output with details
  • 0e289e4 Removed unnecessary if check
  • bdfe1a6 Fixed tests that ensure the toString call is fast to showStack: true
  • 46f6a81 Fixed issue with "Details:undefined" getting printed if there are no properties to display, added test asserts that the stack is showing up when it should
  • ca5b076 Removed lodash.uniq dep and just using lodash instead
  • 348314e Minor cleanup
  • d18f613 Added additional tests to satisfy code coverage
  • 186e206 Changed tests to truly go off the toString method and fixed resulting failures
  • f88e30a Fixed issue with PluginError.stack property causing stack overflow errors
  • f4a895d Fixed error properties to be output when added after the error is created
  • f371ba7 Merge pull request #59 from saturation/patch-1
  • 33134eb Update README.md
  • 0f92393 Changed error name to be red in console output
  • 20712a9 Included documentation for showProperties flag on PluginError
  • 430b46d Added error properties output by default
  • 94761da Simplified error property copy logic
  • 45c55f4 Merge pull request #53 from mtscout6/plugin-error-properties
  • 2703722 Expose option to override properties included on Plugin Error, copy all properties from original error by default

See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Prototype Pollution

The following vulnerabilities are fixed with an upgrade:
- https://snyk.io/vuln/SNYK-JS-MINIMIST-2429795
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants