Skip to content

Conversation

@snyk-bot
Copy link

@snyk-bot snyk-bot commented Jan 1, 2021

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

merge advice

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • package.json

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
medium severity 611/1000
Why? Recently disclosed, Has a fix available, CVSS 6.5
Improper Input Validation
SNYK-JS-URIJS-1055003
No No Known Exploit

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: urijs The new version differs by 43 commits.
  • bf04ec5 chore(build): bumping to version 1.19.4
  • b02bf03 fix(parse): treat backslash as forwardslash in authority (#403)
  • d7064ab chore(build): bumping to version 1.19.3
  • 4f45faf fix(parse): treat backslash as forwardslash in authority
  • 594ffc1 chore(build): bumping to version 1.19.2
  • e780eeb chore: inform people of modern APIs
  • 433f0e5 chore(package): support Composer by adding composer.json
  • 4ced30a fix(build): handle relative paths with missing authority
  • 7168049 fix(buildQuery): support params without key
  • fa46615 chore(build): bumping to version 1.19.1
  • ec3d57b fix(core): properly parse query property (#367)
  • fde82ec chore(build): bumping to version 1.19.0
  • 3cc5c22 chore(build): bumping to version 1.19.0
  • d1cedf2 fix(parse): add URI.preventInvalidHostname to make hostname validation optional - #345, 352, #354, #355
  • 29ab103 feature(fragment-query): add setFragment()
  • 61cd727 chore(dist): updating distributables to version 1.18.12
  • 7074a5b chore(build): bumping to version 1.18.12
  • 0d20f98 fix(ensureValidPort): replace Number.isInteger() with local util (#350, #351)
  • fdb47bf fix(parse): allow _ in hostnames (#347 #348)
  • 8043e13 chore(dist): updating distributables to version 1.18.11
  • abe52cf chore(build): bumping to version 1.18.11
  • 772852f fix(parse): throw on invalid input (#345)
  • d6f596c chore(dist): updating distributables to version 1.18.10
  • 8a3e8e6 chore(build): bumping to version 1.18.10

See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic

The following vulnerabilities are fixed with an upgrade:
- https://snyk.io/vuln/SNYK-JS-URIJS-1055003
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants