Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Snyk has created this PR to fix 1 vulnerabilities in the npm dependencies of this project.
Snyk changed the following file(s):
large-file/package.json
large-file/package-lock.json
Vulnerabilities that will be fixed with an upgrade:
SNYK-JS-CROSSSPAWN-8303230
Release notes
Package name: cross-spawn
chore(release): 7.0.5
chore(release): 7.0.4
chore(release): 7.0.3
chore(release): 7.0.2
chore(release): 7.0.1
chore(release): 7.0.0
chore(release): 6.0.5
chore(release): 6.0.4
chore(release): 6.0.3
chore(release): 6.0.2
Package name: mongodb-js-metrics
Package name: snyk
1.996.0 (2022-09-01)
Bug Fixes
Features
1.995.0 (2022-08-31)
Bug Fixes
1.994.0 (2022-08-31)
Bug Fixes
Features
1.993.0 (2022-08-29)
Features
1.992.0 (2022-08-25)
Bug Fixes
--target-name
bug (3431f79)1.991.0 (2022-08-23)
Features
1.990.0 (2022-08-22)
Bug Fixes
1.989.0 (2022-08-19)
Bug Fixes
Features
1.988.0 (2022-08-17)
Bug Fixes
Features
1.987.0 (2022-08-15)
Bug Fixes
Features
Package name: webpack-cli
Package name: yargs
Bug Fixes
Features
chore(release): 13.2.4
chore(release): 13.2.2
chore(release): 13.2.1
chore(release): 13.2.0
chore(release): 13.1.0
Package name: yeoman-generator
Breaking changes
[email protected]
(unreleased yo@4).addDependencies({dependency: 'version'})
addDevDependencies({dependency: 'version'})
this.packageJson
storage. Eg:this.packageJson.merge({scripts: {test: 'mocha'}})
;package.json
changes.unique: 'namespace'
orunique: 'argument'
.this.(spawnCommand/spawnCommandSync)
switched toexeca
and now defaultscwd
tothis.destinationRoot()
.composeWith()
isn't chainable anymore and delegates the running to the Environment for singleton checks.registerTransformStream
withqueueTransformStream
.New api executes transformations before the commit operation, and is executed for every generator.
v4.13.0...v5.0.0
5.0.0-rc.0
5.0.0-beta.1
v4.12.0...v4.13.0
Cache prompt suggestions only to global yo-rc.
this.prompt(prompts, this.config);
will use the storage to read/write answers.!== undefined
(pass --ask-answered to force the prompt to be shown, stored value is the default value)It doesn’t work due to multiple scheduled runs.
Important
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.
For more information:
🧐 View latest project report
📜 Customise PR templates
🛠 Adjust project settings
📚 Read about Snyk's upgrade logic
Learn how to fix vulnerabilities with free interactive lessons:
🦉 Regular Expression Denial of Service (ReDoS)
[//]: # 'snyk:metadata:{"customTemplate":{"variablesUsed":[],"fieldsUsed":[]},"dependencies":[{"name":"cross-spawn","from":"5.1.0","to":"7.0.5"},{"name":"mongodb-js-metrics","from":"5.0.0","to":"6.0.0"},{"name":"snyk","from":"1.389.0","to":"1.996.0"},{"name":"webpack-cli","from":"3.3.5","to":"4.0.0"},{"name":"yargs","from":"13.1.0","to":"13.3.0"},{"name":"yeoman-generator","from":"2.0.5","to":"5.0.0"}],"env":"prod","issuesToFix":[{"exploit_maturity":"Proof of Concept","id":"SNYK-JS-CROSSSPAWN-8303230","priority_score":170,"priority_score_factors":[{"name":"confidentiality","value":"none"},{"name":"integrity","value":"none"},{"name":"availability","value":"high"},{"name":"scope","value":"unchanged"},{"name":"exploitCodeMaturity","value":"proofOfConcept"},{"name":"userInteraction","value":"none"},{"name":"privilegesRequired","value":"none"},{"name":"attackComplexity","value":"low"},{"name":"attackVector","value":"network"},{"name":"epss","value":0.01055},{"name":"isTrending","value":false},{"name":"publicationDate","value":"Thu Nov 07 2024 14:07:29 GMT+0000 (Coordinated Universal Time)"},{"name":"isReachable","value":false},{"name":"isTransitive","value":true},{"name":"isMalicious","value":false},{"name":"businessCriticality","value":"high"},{"name":"relativeImportance","value":"high"},{"name":"relativePopularityRank","value":99},{"name":"impact","value":5.99},{"name":"likelihood","value":2.83},{"name":"scoreVersion","value":"V5"}],"severity":"high","title":"Regular Expression Denial of Service (ReDoS)"},{"exploit_maturity":"Proof of Concept","id":"SNYK-JS-CROSSSPAWN-8303230","priority_score":170,"priority_score_factors":[{"name":"confidentiality","value":"none"},{"name":"integrity","value":"none"},{"name":"availability","value":"high"},{"name":"scope","value":"unchanged"},{"name":"exploitCodeMaturity","value":"proofOfConcept"},{"name":"userInteraction","value":"none"},{"name":"privilegesRequired","value":"none"},{"name":"attackComplexity","value":"low"},{"name":"attackVector","value":"network"},{"name":"epss","value":0.01055},{"name":"isTrending","value":false},{"name":"publicationDate","value":"Thu Nov 07 2024 14:07:29 GMT+0000 (Coordinated Universal Time)"},{"name":"isReachable","value":false},{"name":"isTransitive","value":true},{"name":"isMalicious","value":false},{"name":"businessCriticality","value":"high"},{"name":"relativeImportance","value":"high"},{"name":"relativePopularityRank","value":99},{"name":"impact","value":5.99},{"name":"likelihood","value":2.83},{"name":"scoreVersion","value":"V5"}],"severity":"high","title":"Regular Expression Denial of Service (ReDoS)"},{"exploit_maturity":"Proof of Concept","id":"SNYK-JS-CROSSSPAWN-8303230","priority_score":170,"priority_score_factors":[{"name":"confidentiality","value":"none"},{"name":"integrity","value":"none"},{"name":"availability","value":"high"},{"name":"scope","value":"unchanged"},{"name":"exploitCodeMaturity","value":"proofOfConcept"},{"name":"userInteraction","value":"none"},{"name":"privilegesRequired","value":"none"},{"name":"a...