Skip to content

[Snyk] Upgrade codecov from 3.7.2 to 3.8.1#5

Open
arielkru wants to merge 1 commit intomasterfrom
snyk-upgrade-6fdda2a835493479bc2b976b001b312a
Open

[Snyk] Upgrade codecov from 3.7.2 to 3.8.1#5
arielkru wants to merge 1 commit intomasterfrom
snyk-upgrade-6fdda2a835493479bc2b976b001b312a

Conversation

@arielkru
Copy link
Owner

@arielkru arielkru commented Mar 2, 2021

Snyk has created this PR to upgrade codecov from 3.7.2 to 3.8.1.

merge advice
ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


  • The recommended version is 2 versions ahead of your current version.
  • The recommended version was released 4 months ago, on 2020-11-03.

The recommended version fixes:

Severity Issue PriorityScore (*) Exploit Maturity
Denial of Service
SNYK-JS-NODEFETCH-674311
306/1000
Why? CVSS 5.9
No Known Exploit

(*) Note that the real score may have changed since the PR was raised.

Release notes
Package name: codecov
  • 3.8.1 - 2020-11-03

    v3.8.1

    Fixes

    • #246 Revert "Bump teeny-request from 6.0.1 to 7.0.0"
  • 3.8.0 - 2020-10-05

    v3.8.0

    Features

    • #160 Add Github Actions support

    Fixes

    • #173 Fix broken gcov command
    • #195 Update Node testing versions
    • #200 Remove flaky tests
    • #204 Create CHANGELOG and remove flaky v4 test
    • #208 Add license scan report and status
    • #220 Remove errant bitly

    Dependencies

    • #189 Bump lint-staged from 10.0.7 to 10.2.11
    • #190 [Security] Bump handlebars from 4.5.3 to 4.7.6
    • #191 Bump prettier from 1.19.1 to 2.0.5
    • #192 Bump mock-fs from 4.10.4 to 4.12.0
    • #196 Bump teeny-request from 6.0.1 to 7.0.0
    • #197 Bump eslint-config-prettier from 4.3.0 to 6.11.0
    • #198 Bump js-yaml from 3.13.1 to 3.14.0
    • #199 Bump husky from 4.2.1 to 4.2.5
    • #202 Bump eslint from 5.16.0 to 7.7.0
    • #203 Bump jest from 24.9.0 to 26.4.1
    • #205 Bump mock-fs from 4.12.0 to 4.13.0
    • #206 Bump jest from 26.4.1 to 26.4.2
    • #207 Bump prettier from 2.0.5 to 2.1.0
    • #209 Bump lint-staged from 10.2.11 to 10.2.13
    • #210 Bump prettier from 2.1.0 to 2.1.1
    • #212 Bump eslint from 7.7.0 to 7.8.1
    • #214 Bump lint-staged from 10.2.13 to 10.3.0
    • #215 Bump husky from 4.2.5 to 4.3.0
    • #216 Bump node-fetch from 2.6.0 to 2.6.1
    • #217 Bump eslint from 7.8.1 to 7.9.0
    • #218 Bump prettier from 2.1.1 to 2.1.2
    • #219 Bump lint-staged from 10.3.0 to 10.4.0
    • #222 Bump eslint-config-prettier from 6.11.0 to 6.12.0
    • #223 Bump eslint from 7.9.0 to 7.10.0
    • #224 Bump teeny-request from 7.0.0 to 7.0.1
  • 3.7.2 - 2020-07-22
    No content.
from codecov GitHub release notes
Commit messages
Package name: codecov
  • 7bd62cd Merge pull request #246 from codecov/nodev3.8.1
  • 5a36543 Bump to 3.8.1
  • 62fa885 Revert "Bump teeny-request from 6.0.1 to 7.0.0"
  • a35bd8b Merge pull request #231 from codecov/dependabot/npm_and_yarn/eslint-7.11.0
  • dc49f44 Merge pull request #232 from codecov/dependabot/npm_and_yarn/jest-26.5.3
  • e2b6fcf Bump jest from 26.5.2 to 26.5.3
  • 7afba4e Bump eslint from 7.10.0 to 7.11.0
  • ae1122a Merge pull request #227 from codecov/dependabot/npm_and_yarn/jest-26.5.2
  • fd24a3c Bump jest from 26.5.0 to 26.5.2
  • 1f75d58 Merge pull request #226 from codecov/dependabot/npm_and_yarn/jest-26.5.0
  • 820f676 Bump jest from 26.4.2 to 26.5.0
  • 05188d8 Merge pull request #225 from codecov/3.8.0
  • e84e187 Update changelog
  • 2eed3b8 Merge pull request #222 from codecov/dependabot/npm_and_yarn/eslint-config-prettier-6.12.0
  • 381badf Merge pull request #223 from codecov/dependabot/npm_and_yarn/eslint-7.10.0
  • d323c61 Merge pull request #224 from codecov/dependabot/npm_and_yarn/teeny-request-7.0.1
  • f6f90b8 Bump teeny-request from 7.0.0 to 7.0.1
  • 712fae8 Bump eslint from 7.9.0 to 7.10.0
  • 244eba1 Bump eslint-config-prettier from 6.11.0 to 6.12.0
  • bcd0ad7 Remove errant bitly (#220)
  • 0fae0f6 Merge pull request #219 from codecov/dependabot/npm_and_yarn/lint-staged-10.4.0
  • 648d40b Bump lint-staged from 10.3.0 to 10.4.0
  • 90ac3c7 Merge pull request #218 from codecov/dependabot/npm_and_yarn/prettier-2.1.2
  • b595b9c Bump prettier from 2.1.1 to 2.1.2

Compare


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

🧐 View latest project report

🛠 Adjust upgrade PR settings

🔕 Ignore this dependency or unsubscribe from future upgrade PRs

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants