[Snyk] Fix for 9 vulnerabilities#91
Conversation
The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-JS-HANDLEBARS-15803084 - https://snyk.io/vuln/SNYK-JS-HANDLEBARS-15803082 - https://snyk.io/vuln/SNYK-JS-LODASH-15869625 - https://snyk.io/vuln/SNYK-JS-HANDLEBARS-15803086 - https://snyk.io/vuln/SNYK-JS-HANDLEBARS-15807042 - https://snyk.io/vuln/SNYK-JS-HANDLEBARS-15807040 - https://snyk.io/vuln/SNYK-JS-LODASH-15869619 - https://snyk.io/vuln/SNYK-JS-HANDLEBARS-15789775 - https://snyk.io/vuln/SNYK-JS-HANDLEBARS-15813000
|
This upgrade includes a major version jump for the tap@11.1.5 → tap@18.0.0Risk: HIGH This is a very large upgrade spanning seven major versions and includes a complete rewrite of the library in TypeScript. Significant effort will be required to migrate. Key Breaking Changes:
Recommendation: This upgrade cannot be merged without a dedicated migration effort. Developers must review the extensive changelogs for versions 12 through 18 to identify all necessary code and configuration changes. Source: Tap Changelog hbs@4.0.4 → hbs@4.2.1Risk: LOW This is a minor version upgrade. No official breaking changes were documented for this specific version range. The underlying Source: Package documentation
|
⛔ Snyk checks have failed. 8 issues have been found so far.
💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse. |
Snyk has created this PR to fix 9 vulnerabilities in the npm dependencies of this project.
Snyk changed the following file(s):
package.jsonpackage-lock.jsonVulnerabilities that will be fixed with an upgrade:
SNYK-JS-HANDLEBARS-15803084
SNYK-JS-HANDLEBARS-15803082
SNYK-JS-LODASH-15869625
SNYK-JS-HANDLEBARS-15803086
SNYK-JS-HANDLEBARS-15807042
SNYK-JS-HANDLEBARS-15807040
SNYK-JS-LODASH-15869619
SNYK-JS-HANDLEBARS-15789775
SNYK-JS-HANDLEBARS-15813000
Breaking Change Risk
Important
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.
For more information:
🧐 View latest project report
📜 Customise PR templates
🛠 Adjust project settings
📚 Read about Snyk's upgrade logic
Learn how to fix vulnerabilities with free interactive lessons:
🦉 Prototype Pollution
🦉 Access of Resource Using Incompatible Type ('Type Confusion')
🦉 Improper Encoding or Escaping of Output
🦉 More lessons are available in Snyk Learn