Skip to content

Conversation

@dstreet
Copy link
Owner

@dstreet dstreet commented Nov 29, 2023

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • package.json
    • package-lock.json

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
medium severity 475/1000
Why? Has a fix available, CVSS 5
Prototype Pollution
SNYK-JS-101-1292345
Yes No Known Exploit

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: rpc-websockets The new version differs by 250 commits.
  • 75989e7 7.4.13
  • 53cdbc4 update dist files to latest lock changes
  • 519d6e2 Merge pull request #117 from macalinao/igm/update-dep
  • 7ec35dc Merge branch 'master' into igm/update-dep
  • 682384d Merge pull request #114 from trasherdk/test-server
  • bd1d97a Run 'npm audit fix'
  • 79cca41 Remove dependency on assert-args
  • d62762b fix 4 moderate severity vulnerabilities
  • 3733f2d Removed trailing comma
  • 1b7e18a server.spec.js - relax eslint a bit.
  • 48b16b5 Merge pull request #109 from elpheria/dependabot/npm_and_yarn/ws-7.4.6
  • ddd2cf3 build(deps): bump ws from 7.4.5 to 7.4.6
  • b3adfa3 7.4.12
  • c446f30 Bump websocket to ws 7.4.5 (#108)
  • 5f5350c Merge pull request #107 from elpheria/dependabot/npm_and_yarn/lodash-4.17.21
  • 73df007 build(deps): bump lodash from 4.17.19 to 4.17.21
  • df3cf1c Merge pull request #106 from elpheria/dependabot/npm_and_yarn/handlebars-4.7.7
  • f279e06 build(deps): bump handlebars from 4.7.6 to 4.7.7
  • cc15c04 7.4.11
  • 1bd97b9 Merge pull request #101 from Smittyvb/patch-1
  • 60347e6 Fix license metadata: MIT -> LGPLv3
  • 82b3d03 7.4.10
  • 5cebf7e Merge pull request #100 from elpheria/dependabot/npm_and_yarn/y18n-4.0.1
  • 0188c34 build(deps): bump y18n from 4.0.0 to 4.0.1

See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Prototype Pollution

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants