Skip to content

Conversation

@nerdy-tech-com-gitub
Copy link
Owner

snyk-top-banner

Snyk has created this PR to upgrade globby from 13.1.2 to 15.0.0.

ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


  • The recommended version is 10 versions ahead of your current version.

  • The recommended version was released 24 days ago.

⚠️ Warning: This PR contains major version upgrade(s), and may be a breaking change.

Issues fixed by the recommended upgrade:

Issue Score Exploit Maturity
high severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-SEMVER-3247795
159 Proof of Concept
critical severity Arbitrary Command Injection
SNYK-JS-SYSTEMINFORMATION-5914637
159 No Known Exploit
high severity Excessive Platform Resource Consumption within a Loop
SNYK-JS-BRACES-6838727
159 Proof of Concept
high severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-CROSSSPAWN-8303230
159 Proof of Concept
high severity Server-side Request Forgery (SSRF)
SNYK-JS-IP-12704893
159 Proof of Concept
high severity Server-side Request Forgery (SSRF)
SNYK-JS-IP-12761655
159 Proof of Concept
high severity Server-side Request Forgery (SSRF)
SNYK-JS-IP-6240864
159 Proof of Concept
high severity Server-side Request Forgery (SSRF)
SNYK-JS-IP-12704893
159 Proof of Concept
high severity Server-side Request Forgery (SSRF)
SNYK-JS-IP-12761655
159 Proof of Concept
high severity Server-side Request Forgery (SSRF)
SNYK-JS-IP-6240864
159 Proof of Concept
high severity Code Injection
SNYK-JS-LODASH-1040724
159 Proof of Concept
high severity Prototype Poisoning
SNYK-JS-QS-3153490
159 Proof of Concept
high severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-SEMVER-3247795
159 Proof of Concept
medium severity Arbitrary Code Injection
SNYK-JS-SYSTEMINFORMATION-8547981
159 Proof of Concept
medium severity Symlink Attack
SNYK-JS-TMP-11501554
159 Proof of Concept
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-UAPARSERJS-3244450
159 Proof of Concept
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-WS-1296835
159 Proof of Concept
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-HTTPCACHESEMANTICS-3248783
159 Proof of Concept
medium severity Improper Authentication
SNYK-JS-JSONWEBTOKEN-3180022
159 No Known Exploit
medium severity Improper Restriction of Security Token Assignment
SNYK-JS-JSONWEBTOKEN-3180024
159 No Known Exploit
medium severity Use of a Broken or Risky Cryptographic Algorithm
SNYK-JS-JSONWEBTOKEN-3180026
159 No Known Exploit
medium severity Arbitrary File Write via Archive Extraction (Zip Slip)
SNYK-JS-JSZIP-3188562
159 No Known Exploit
medium severity Open Redirect
SNYK-JS-KOA-10944994
159 Proof of Concept
medium severity Open Redirect
SNYK-JS-KOA-12143256
159 No Known Exploit
low severity Regular Expression Denial of Service (ReDoS)
npm:debug:20170905
159 Proof of Concept
critical severity Incomplete List of Disallowed Inputs
SNYK-JS-BABELTRAVERSE-5962462
159 Proof of Concept
medium severity Server-Side Request Forgery (SSRF)
SNYK-JS-IP-7148531
159 Proof of Concept
medium severity Server-Side Request Forgery (SSRF)
SNYK-JS-IP-7148531
159 Proof of Concept
medium severity Denial of Service (DoS)
SNYK-JS-JSZIP-1251497
159 Proof of Concept
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-LODASH-1018905
159 Proof of Concept
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-MINIMATCH-3050818
159 No Known Exploit
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-PATHPARSE-1077067
159 Proof of Concept
low severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-BRACEEXPANSION-9789073
159 Proof of Concept
critical severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-KOA-8720152
159 No Known Exploit
medium severity Inefficient Regular Expression Complexity
SNYK-JS-MICROMATCH-6838728
159 No Known Exploit
low severity Cross-site Scripting (XSS)
SNYK-JS-KOA-9679272
159 Proof of Concept
Release notes
Package name: globby from globby GitHub release notes

Important

  • Warning: This PR contains a major version upgrade, and may be a breaking change.
  • Check the changes in this PR to ensure they won't cause issues with your project.
  • This PR was automatically created by Snyk using the credentials of a real user.
  • Max score is 1000. Note that the real score may have changed since the PR was raised.

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

Snyk has created this PR to upgrade globby from 13.1.2 to 15.0.0.

See this package in npm:
globby

See this project in Snyk:
https://app.snyk.io/org/nerds-github/project/b402c2a4-88c2-41a8-ad24-ce2c2c83a779?utm_source=github&utm_medium=referral&page=upgrade-pr
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

3 participants