Skip to content

Conversation

@snyk-bot
Copy link

@snyk-bot snyk-bot commented Jul 8, 2022

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • package.json
    • package-lock.json

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
high severity 768/1000
Why? Proof of Concept exploit, Recently disclosed, Has a fix available, CVSS 7.5
Regular Expression Denial of Service (ReDoS)
SNYK-JS-MOMENT-2944238
Yes Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: handsontable The new version differs by 250 commits.
  • 752c841 Merge branch 'release/12.1.2' into develop
  • 264d5df Docs: Adding 12.1.2 docs (#9642)
  • 200cca2 Revert the change that had blocked the code freeze
  • 4933bb1 12.1.2
  • 4f3866e Fix freeze script
  • 24ae7fb Add ability to create freeze and release in the same day
  • e7e7c41 Security upgrade moment from 2.29.3 to 2.29.4 (#9637)
  • e0fabdb create a link from custom editor/renderer page to hot-column page (#9633) (#9634)
  • a1d3a36 Freeze the Vue dev dependency to ~2.6 (#9629)
  • a5a0d2a Merge branch 'release/12.1.1' into develop
  • 9f840be Docs: Adding 12.1.1 docs (#9632)
  • 5b416d6 Typo fix in mergeCells documentation (#9606)
  • 2acf57f Typo in password cell type documentation fixed (#9612)
  • 3dd0b37 12.1.1
  • 84a460a Fix Angular wrapper peers deps and update examples (#9617)
  • d866351 Merge tag '12.1.0' into develop
  • e572583 Merge branch 'release/12.1.0'
  • 10af1ff 12.1.0
  • f300cc1 Docs: Generate the 12.1 docs (#9609)
  • 127f82c Docs: Add 12.1.0 docs (#9599)
  • dfe871d 12.1.0
  • 403ae2f Revert the changes from #9415 (#9605)
  • 0fbd127 Revert the changes from #9415 (#9605)
  • e42c468 Fix Angular examples by linking @ handsontable/angular package (#9600)

See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Learn about vulnerability in an interactive lesson of Snyk Learn.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants