-
Notifications
You must be signed in to change notification settings - Fork 0
[Snyk] Security upgrade node-gyp from 10.0.1 to 10.2.0 #22
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: main
Are you sure you want to change the base?
Conversation
[skip ci]
Snyk has created this PR to upgrade tree-sitter-cli from 0.20.8 to 0.22.6. See this package in npm: tree-sitter-cli See this project in Snyk: https://app.snyk.io/org/abdulrahman305/project/b84198ce-387f-40a2-9108-81dc921da607?utm_source=github&utm_medium=referral&page=upgrade-pr
Snyk has created this PR to upgrade tree-sitter-cli from 0.20.8 to 0.22.6. See this package in npm: tree-sitter-cli See this project in Snyk: https://app.snyk.io/org/abdulrahman305/project/d0d88628-ed6d-4d56-9934-a879dc24a83e?utm_source=github&utm_medium=referral&page=upgrade-pr
Snyk has created this PR to upgrade com.github.javaparser:javaparser-core from 3.5.9 to 3.26.0. See this package in maven: com.github.javaparser:javaparser-core See this project in Snyk: https://app.snyk.io/org/abdulrahman305/project/47526198-b676-4801-836f-ec896130d73a?utm_source=github&utm_medium=referral&page=upgrade-pr
Snyk has created this PR to upgrade tree-sitter-cli from 0.20.8 to 0.22.6. See this package in npm: tree-sitter-cli See this project in Snyk: https://app.snyk.io/org/abdulrahman305/project/895a58f8-8171-4c0f-bb16-aab6ad6b61ae?utm_source=github&utm_medium=referral&page=upgrade-pr
Snyk has created this PR to upgrade tree-sitter-cli from 0.20.8 to 0.22.6. See this package in npm: tree-sitter-cli See this project in Snyk: https://app.snyk.io/org/abdulrahman305/project/3c076cc9-3c6f-4d40-bdb5-c379022d47e1?utm_source=github&utm_medium=referral&page=upgrade-pr
…resources/language-metavariables/tree-sitter-sql/docs/Gemfile.lock to reduce vulnerabilities The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-RUBY-REXML-7577227 - https://snyk.io/vuln/SNYK-RUBY-REXML-7577228
…ecea48ac9d59fe [Snyk] Security upgrade jekyll from 4.3.2 to 4.3.3
…01a3abb2b5f908a609 [Snyk] Upgrade tree-sitter-cli from 0.20.8 to 0.22.6
…eb87f9d8f79eb514a6 [Snyk] Upgrade com.github.javaparser:javaparser-core from 3.5.9 to 3.26.0
…dd46bf44323c08875c [Snyk] Upgrade tree-sitter-cli from 0.20.8 to 0.22.6
…3e03ff4099f0941f0e [Snyk] Upgrade tree-sitter-cli from 0.20.8 to 0.22.6
…2d83df2ddf4111877c [Snyk] Upgrade tree-sitter-cli from 0.20.8 to 0.22.6
Snyk has created this PR to upgrade tree-sitter-cli from 0.20.8 to 0.22.6. See this package in npm: tree-sitter-cli See this project in Snyk: https://app.snyk.io/org/abdulrahman305/project/ce505a2d-919f-4785-b479-681dd77f596b?utm_source=github&utm_medium=referral&page=upgrade-pr
Snyk has created this PR to upgrade tree-sitter-cli from 0.20.8 to 0.22.6. See this package in npm: tree-sitter-cli See this project in Snyk: https://app.snyk.io/org/abdulrahman305/project/3cc1ceb4-cc01-4dbf-82c1-5606d7ec4907?utm_source=github&utm_medium=referral&page=upgrade-pr
Snyk has created this PR to upgrade tree-sitter-cli from 0.20.8 to 0.22.6. See this package in npm: tree-sitter-cli See this project in Snyk: https://app.snyk.io/org/abdulrahman305/project/de2a14d4-1968-488a-b7fa-2587f42c7fed?utm_source=github&utm_medium=referral&page=upgrade-pr
Snyk has created this PR to upgrade nan from 2.17.0 to 2.20.0. See this package in npm: nan See this project in Snyk: https://app.snyk.io/org/abdulrahman305/project/de2a14d4-1968-488a-b7fa-2587f42c7fed?utm_source=github&utm_medium=referral&page=upgrade-pr
…b98dc676ee3436d1bf3 [Snyk] Upgrade nan from 2.17.0 to 2.20.0
…fef6fcd6e517520858 [Snyk] Upgrade tree-sitter-cli from 0.20.8 to 0.22.6
…890d792cd0f9e308ce [Snyk] Upgrade tree-sitter-cli from 0.20.8 to 0.22.6
…714f3403eab54a6a50 [Snyk] Upgrade tree-sitter-cli from 0.20.8 to 0.22.6
… reduce vulnerabilities The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-JS-TAR-6476909
👋 I'm here to help you review your pull request. When you're ready for me to perform a review, you can comment anywhere on this pull request with this command: As a reminder, here are some helpful tips on how we can collaborate together:
|
Your organization has reached the subscribed usage limit. You can upgrade your account by purchasing a subscription at Stripe payment link Disclaimer: This comment was entirely generated using AI. Be aware that the information provided may be incorrect. Current plan usage: 100.67% Have feedback or need help? |
New and removed dependencies detected. Learn more about Socket for GitHub ↗︎
|
Snyk has created this PR to fix 1 vulnerabilities in the npm dependencies of this project.
Snyk changed the following file(s):
resources/language-metavariables/tree-sitter-sql/package.json
Vulnerabilities that will be fixed with an upgrade:
SNYK-JS-TAR-6476909
Important
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.
For more information:
🧐 View latest project report
📜 Customise PR templates
🛠 Adjust project settings
📚 Read about Snyk's upgrade logic
Learn how to fix vulnerabilities with free interactive lessons:
🦉 Uncontrolled Resource Consumption ('Resource Exhaustion')
[//]: # 'snyk:metadata:{"customTemplate":{"variablesUsed":[],"fieldsUsed":[]},"dependencies":[{"name":"node-gyp","from":"10.0.1","to":"10.2.0"}],"env":"prod","issuesToFix":[{"exploit_maturity":"Proof of Concept","id":"SNYK-JS-TAR-6476909","priority_score":142,"priority_score_factors":[{"name":"confidentiality","value":"none"},{"name":"integrity","value":"none"},{"name":"availability","value":"high"},{"name":"scope","value":"unchanged"},{"name":"exploitCodeMaturity","value":"proofOfConcept"},{"name":"userInteraction","value":"required"},{"name":"privilegesRequired","value":"none"},{"name":"attackComplexity","value":"low"},{"name":"attackVector","value":"network"},{"name":"epss","value":0.00045},{"name":"isTrending","value":false},{"name":"publicationDate","value":"Fri Mar 22 2024 12:56:33 GMT+0000 (Coordinated Universal Time)"},{"name":"isReachable","value":false},{"name":"isTransitive","value":true},{"name":"isMalicious","value":false},{"name":"businessCriticality","value":"high"},{"name":"relativeImportance","value":"medium"},{"name":"relativePopularityRank","value":99},{"name":"impact","value":5.99},{"name":"likelihood","value":2.36},{"name":"scoreVersion","value":"V5"}],"severity":"medium","title":"Uncontrolled Resource Consumption ('Resource Exhaustion')"}],"prId":"f4ca8000-7670-4161-b0cb-cb6e97823a8f","prPublicId":"f4ca8000-7670-4161-b0cb-cb6e97823a8f","packageManager":"npm","priorityScoreList":[142],"projectPublicId":"82748c62-b1f9-430c-92c8-6b1e1a9a3f0f","projectUrl":"https://app.snyk.io/org/abdulrahman305/project/82748c62-b1f9-430c-92c8-6b1e1a9a3f0f?utm_source=github&utm_medium=referral&page=fix-pr","prType":"fix","templateFieldSources":{"branchName":"default","commitMessage":"default","description":"default","title":"default"},"templateVariants":["updated-fix-title","priorityScore"],"type":"auto","upgrade":["SNYK-JS-TAR-6476909"],"vulns":["SNYK-JS-TAR-6476909"],"patch":[],"isBreakingChange":false,"remediationStrategy":"vuln"}'