Skip to content

[Snyk] Security upgrade @percy/agent from 0.13.0 to 0.28.7#37

Open
AgnellusX1 wants to merge 1 commit intomasterfrom
snyk-fix-2ed5569cd80fe826b7bc5bd4834243b1
Open

[Snyk] Security upgrade @percy/agent from 0.13.0 to 0.28.7#37
AgnellusX1 wants to merge 1 commit intomasterfrom
snyk-fix-2ed5569cd80fe826b7bc5bd4834243b1

Conversation

@AgnellusX1
Copy link

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • package.json
    • package-lock.json

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
medium severity 718/1000
Why? Proof of Concept exploit, Recently disclosed, Has a fix available, CVSS 6.5
Information Exposure
SNYK-JS-FOLLOWREDIRECTS-6444610
No Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: @percy/agent The new version differs by 250 commits.
  • 3a8cc3a 🔖 v0.28.7
  • a27b610 fix: Lock colors.js to prevent infinite loop (#646)
  • 4889495 Add deprecated isssue template
  • 14c93a8 build(deps): bump ssri from 6.0.1 to 6.0.2 (#623)
  • 4a17184 build(deps): bump hosted-git-info from 2.8.8 to 2.8.9 (#624)
  • 1e905bb build(deps): bump underscore from 1.9.1 to 1.13.1 (#625)
  • 0368029 build(deps): bump ini from 1.3.5 to 1.3.8 (#628)
  • b7c8f8e build(deps-dev): bump testem from 3.2.0 to 3.4.2 (#622)
  • 23e5f57 build(deps-dev): bump tslint from 6.1.0 to 6.1.3 (#619)
  • 05b1032 build(deps): [security] bump y18n from 4.0.0 to 4.0.3 (#617)
  • 1b7edf3 docs: Add notice about `@ percy/cli` to README
  • 80a59f3 build(deps): [security] bump elliptic from 6.5.3 to 6.5.4 (#607)
  • 42af5f5 v0.28.6
  • 39ffeb9 Update lockfile
  • ae237ad fix: [Security] upgrade axios from 0.19.2 to 0.21.1
  • d9dd683 build(deps-dev): bump @ babel/core from 7.10.4 to 7.12.9 (#583)
  • cf6e4d7 build(deps): bump puppeteer from 5.3.1 to 5.5.0 (#588)
  • e808b33 build(deps-dev): bump nock from 11.7.0 to 13.0.5 (#586)
  • c3119e6 build(deps-dev): bump tslib from 2.0.0 to 2.0.3 (#582)
  • 7d7a28b build(deps-dev): bump @ types/puppeteer from 3.0.1 to 5.4.0 (#587)
  • 8d4240d build(deps-dev): bump npm-watch from 0.6.0 to 0.7.0 (#584)
  • 5fb1286 build(deps-dev): bump ts-node from 8.5.4 to 9.0.0 (#585)
  • 3a016ca v0.28.5
  • 609ad5e fix: Don't check if the service is running to stop Percy (#581)

See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Learn about vulnerability in an interactive lesson of Snyk Learn.

@AgnellusX1 AgnellusX1 requested a review from a team as a code owner March 15, 2024 19:39
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants