[Snyk] Fix for 5 vulnerabilities#811
Conversation
…kage-lock.json to reduce vulnerabilities The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-JS-JSYAML-17900054 - https://snyk.io/vuln/SNYK-JS-TAR-17909068 - https://snyk.io/vuln/SNYK-JS-TAR-17909104 - https://snyk.io/vuln/SNYK-JS-TAR-17909152 - https://snyk.io/vuln/SNYK-JS-TAR-17909225
|
This upgrade includes major versions for gulp@4.0.2 → gulp@5.0.0 (High Risk)This major upgrade introduces several breaking changes to the build system. Key Changes:
mocha@6.2.2 → mocha@10.6.0 (High Risk)This is a significant jump across multiple major versions (v7, v8, v9, v10) with substantial breaking changes. Key Changes:
gulp-mocha@7.0.2 → gulp-mocha@9.0.0 (High Risk)This upgrade is necessary to support the newer versions of Gulp and Mocha. Key Changes:
Recommendation: These upgrades will almost certainly break your existing build and test setup. A careful migration is required. Developers should:
|
…kage-lock.json to reduce vulnerabilities The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-JS-JSYAML-17900054 - https://snyk.io/vuln/SNYK-JS-TAR-17909068 - https://snyk.io/vuln/SNYK-JS-TAR-17909104 - https://snyk.io/vuln/SNYK-JS-TAR-17909152 - https://snyk.io/vuln/SNYK-JS-TAR-17909225
There was a problem hiding this comment.
Sorry @adamlaska, you have reached your weekly rate limit of 500000 diff characters.
Please try again later or upgrade to continue using Sourcery
…kage-lock.json to reduce vulnerabilities The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-JS-JSYAML-17900054 - https://snyk.io/vuln/SNYK-JS-TAR-17909068 - https://snyk.io/vuln/SNYK-JS-TAR-17909104 - https://snyk.io/vuln/SNYK-JS-TAR-17909152 - https://snyk.io/vuln/SNYK-JS-TAR-17909225
|
Thanks for your pull request! It looks like this may be your first contribution to a Google open source project. Before we can look at your pull request, you'll need to sign a Contributor License Agreement (CLA). View this failed invocation of the CLA check for more information. For the most up to date status, view the checks section at the bottom of the pull request. |
Snyk has created this PR to fix 5 vulnerabilities in the npm dependencies of this project.
Snyk changed the following file(s):
packages/bitcore-build/package.jsonpackages/bitcore-build/package-lock.jsonVulnerabilities that will be fixed with an upgrade:
SNYK-JS-JSYAML-17900054
SNYK-JS-TAR-17909068
SNYK-JS-TAR-17909104
SNYK-JS-TAR-17909152
SNYK-JS-TAR-17909225
Breaking Change Risk
Important
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.
For more information:
🧐 View latest project report
📜 Customise PR templates
🛠 Adjust project settings
📚 Read about Snyk's upgrade logic
Learn how to fix vulnerabilities with free interactive lessons:
🦉 Allocation of Resources Without Limits or Throttling
🦉 Uncaught Exception