Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Snyk] Upgrade tape from 4.13.0 to 5.6.6 #24

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

Woodpile37
Copy link
Owner

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to upgrade tape from 4.13.0 to 5.6.6.

ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


Warning: This is a major version upgrade, and may be a breaking change.

  • The recommended version is 38 versions ahead of your current version.
  • The recommended version was released 3 months ago, on 2023-07-18.

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

🧐 View latest project report

🛠 Adjust upgrade PR settings

🔕 Ignore this dependency or unsubscribe from future upgrade PRs

Snyk has created this PR to upgrade tape from 4.13.0 to 5.6.6.

See this package in npm:


See this project in Snyk:
https://app.snyk.io/org/woodpile37/project/4b18aafe-03e2-4f80-883a-dfcefbb56ae0?utm_source=github&utm_medium=referral&page=upgrade-pr
@changeset-bot
Copy link

changeset-bot bot commented Oct 8, 2023

⚠️ No Changeset found

Latest commit: 2f68132

Merging this PR will not cause a version bump for any packages. If these changes should not result in a new version, you're good to go. If these changes should result in a version bump, you need to add a changeset.

Click here to learn what changesets are, and how to add one.

Click here if you're a maintainer who wants to add a changeset to this PR

@codeautopilot
Copy link

codeautopilot bot commented Oct 8, 2023

Pull Request Summary

OpenAI's API is not working at the moment 😓. Please try later.


Current plan usage: 27.46%


Have feedback or need help?

Discord
Documentation
[email protected]

@socket-security
Copy link

Updated dependencies detected. Learn more about Socket for GitHub ↗︎

Packages Version New capabilities Transitives Size Publisher
tape 4.13.0...5.7.0 eval, network, environment +75/-18 5.24 MB ljharb

Copy link

@bridgecrew bridgecrew bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Bridgecrew has found errors in this PR ⬇️

@@ -45,7 +45,7 @@
"eslint": "^6.8.0",
"faucet": "^0.0.1",
"tap-browser-color": "^0.1.2",
"tape": "^4.13.0",
"tape": "^5.6.6",
Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

word-wrap 1.2.3 / package.json

Total vulnerabilities: 1

Critical: 0 High: 0 Medium: 1 Low: 0
Vulnerability IDSeverityCVSSFixed inStatus
CVE-2023-26115 MEDIUM MEDIUM 5.3 1.2.4 Open

@@ -45,7 +45,7 @@
"eslint": "^6.8.0",
"faucet": "^0.0.1",
"tap-browser-color": "^0.1.2",
"tape": "^4.13.0",
"tape": "^5.6.6",
Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

semver 5.7.1 / package.json

Total vulnerabilities: 1

Critical: 0 High: 1 Medium: 0 Low: 0
Vulnerability IDSeverityCVSSFixed inStatus
CVE-2022-25883 HIGH HIGH 7.5 7.5.2 Open

@@ -45,7 +45,7 @@
"eslint": "^6.8.0",
"faucet": "^0.0.1",
"tap-browser-color": "^0.1.2",
"tape": "^4.13.0",
"tape": "^5.6.6",
Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

minimist 0.0.5 / package.json

Total vulnerabilities: 2

Critical: 1 High: 0 Medium: 1 Low: 0
Vulnerability IDSeverityCVSSFixed inStatus
CVE-2021-44906 CRITICAL CRITICAL 9.8 1.2.6 Open
CVE-2020-7598 MEDIUM MEDIUM 5.6 1.2.2 Open

@@ -45,7 +45,7 @@
"eslint": "^6.8.0",
"faucet": "^0.0.1",
"tap-browser-color": "^0.1.2",
"tape": "^4.13.0",
"tape": "^5.6.6",
Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

semver 6.3.0 / package.json

Total vulnerabilities: 1

Critical: 0 High: 1 Medium: 0 Low: 0
Vulnerability IDSeverityCVSSFixed inStatus
CVE-2022-25883 HIGH HIGH 7.5 7.5.2 Open

@@ -45,7 +45,7 @@
"eslint": "^6.8.0",
"faucet": "^0.0.1",
"tap-browser-color": "^0.1.2",
"tape": "^4.13.0",
"tape": "^5.6.6",
Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

minimist 0.0.8 / package.json

Total vulnerabilities: 2

Critical: 1 High: 0 Medium: 1 Low: 0
Vulnerability IDSeverityCVSSFixed inStatus
CVE-2021-44906 CRITICAL CRITICAL 9.8 1.2.6 Open
CVE-2020-7598 MEDIUM MEDIUM 5.6 1.2.2 Open

@@ -45,7 +45,7 @@
"eslint": "^6.8.0",
"faucet": "^0.0.1",
"tap-browser-color": "^0.1.2",
"tape": "^4.13.0",
"tape": "^5.6.6",
Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

ajv 6.10.2 / package.json

Total vulnerabilities: 1

Critical: 0 High: 0 Medium: 1 Low: 0
Vulnerability IDSeverityCVSSFixed inStatus
CVE-2020-15366 MEDIUM MEDIUM 5.6 6.12.3 Open

@@ -45,7 +45,7 @@
"eslint": "^6.8.0",
"faucet": "^0.0.1",
"tap-browser-color": "^0.1.2",
"tape": "^4.13.0",
"tape": "^5.6.6",
Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

cached-path-relative 1.0.2 / package.json

Total vulnerabilities: 1

Critical: 1 High: 0 Medium: 0 Low: 0
Vulnerability IDSeverityCVSSFixed inStatus
CVE-2021-23518 CRITICAL CRITICAL 9.8 1.1.0 Open

@@ -45,7 +45,7 @@
"eslint": "^6.8.0",
"faucet": "^0.0.1",
"tap-browser-color": "^0.1.2",
"tape": "^4.13.0",
"tape": "^5.6.6",
Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

acorn 7.1.0 / package.json

Total vulnerabilities: 1

Critical: 0 High: 1 Medium: 0 Low: 0
Vulnerability IDSeverityCVSSFixed inStatus
GHSA-6chw-6frg-f759 HIGH HIGH 7.5 7.1.1 Open

@@ -45,7 +45,7 @@
"eslint": "^6.8.0",
"faucet": "^0.0.1",
"tap-browser-color": "^0.1.2",
"tape": "^4.13.0",
"tape": "^5.6.6",
Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

type-fest 0.8.1 / package.json

MEDIUM  Noncompliant License (CC0-1.0)

This package contains a license that is not OSI-approved.

@@ -45,7 +45,7 @@
"eslint": "^6.8.0",
"faucet": "^0.0.1",
"tap-browser-color": "^0.1.2",
"tape": "^4.13.0",
"tape": "^5.6.6",
Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

jsonify 0.0.0 / package.json

LOW  Unknown License (PUBLIC DOMAIN)

This package use a non-SPDX, unrecognized, or private open-source license. Ensure this package is compliant.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants