Skip to content

[Snyk] Fix for 1 vulnerabilities - #61

Open
MrBrain295 wants to merge 1 commit into
mainfrom
snyk-fix-3655d117d9bce4458740e953638bd023
Open

[Snyk] Fix for 1 vulnerabilities#61
MrBrain295 wants to merge 1 commit into
mainfrom
snyk-fix-3655d117d9bce4458740e953638bd023

Conversation

@MrBrain295

Copy link
Copy Markdown
Owner

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • package.json
    • package-lock.json

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
medium severity 601/1000
Why? Recently disclosed, Has a fix available, CVSS 6.3
Cross-site Scripting (XSS)
SNYK-JS-COOKIE-8163060
Yes No Known Exploit

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: @11ty/eleventy The new version differs by 250 commits.

See the full diff

Package name: lighthouse The new version differs by 25 commits.
  • e3fdffc v9.4.0 (#13672)
  • 09cf541 deps(sentry): move from raven to @ sentry/node (content is out-dated and has broken links GoogleChrome/web.dev#9325)
  • 0d9f0b9 core(a11y): change link in category description to web.dev (#13638)
  • 23c24df core(uses-long-cache-ttl): ignore `stale-while-revalidate` (#13612)
  • f684e1f report: add options onPrintOverride and onSaveFileOverride (#13529)
  • fa7b543 report: add options disableFireworks and disableDarkMode (#13649)
  • 9331636 core(inputs): fix typo in artifact (#13671)
  • 4608fb9 core(full-page-screenshot): wait for doubleraf, network quiet (#13663)
  • a7b46de deps(snyk): update snyk snapshot (#13669)
  • d55bea0 core(inputs): refactor form-elements gatherer (#13662)
  • ed57d42 tests: use simpler assertion in report-renderer-axe-test.js (#13658)
  • 25b8095 report: add onViewTrace to renderer options (#13528)
  • 8fa48dd core(fr): user triggered navigations (#13496)
  • 233b997 tests(devtools): sync (#13656)
  • 0e6402e report: remove pausing fireworks on click (#13650)
  • 90757c4 deps(snyk): update snyk snapshot (#13644)
  • fd688c4 report: fix fireworks (#13635)
  • 5374d64 core(page-functions): set style in getOuterHTMLSnippet without violating CSP (#13636)
  • 16248c1 core(hreflang): remove eval, import axe valid-langs.js directly (#13385)
  • a213cc5 tests: fix single node a11y tests (#13626)
  • 5991a34 misc: temporarily remove brendan from triage rotation (#13618)
  • bbe05ad core(runner): independent gather and audit functions (#13569)
  • 83e2d3c tests(smoke): test array `_includes` and `lhr.timing` (#13619)
  • 19d95cc deps(snyk): update snyk snapshot (#13616)

See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Cross-site Scripting (XSS)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

content: charset guide [2020 May 29]

2 participants