Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Snyk] Upgrade webpack-cli from 3.3.6 to 3.3.12 #2

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

snyk-bot
Copy link

Snyk has created this PR to upgrade webpack-cli from 3.3.6 to 3.3.12.

merge advice
ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


  • The recommended version is 6 versions ahead of your current version.
  • The recommended version was released 2 years ago, on 2020-06-18.

The recommended version fixes:

Severity Issue PriorityScore (*) Exploit Maturity
Prototype Pollution
SNYK-JS-YARGSPARSER-560381
387/1000
Why? Proof of Concept exploit, CVSS 5.6
Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Release notes
Package name: webpack-cli
  • 3.3.12 - 2020-06-18

    chore(release): 3.3.12

  • 3.3.11 - 2020-02-11
  • 3.3.10 - 2019-10-31
  • 3.3.9 - 2019-09-17
  • 3.3.8 - 2019-09-05
  • 3.3.7 - 2019-08-18
  • 3.3.6 - 2019-07-14
from webpack-cli GitHub release notes
Commit messages
Package name: webpack-cli
  • 33574ec chore(release): 3.3.12
  • 4f1a2f3 chore: bump dependencies for v3 (#1595)
  • ab910df docs(templates): Branding guide violation fix (#1226)
  • c9927e3 fix: release stable
  • a037dc8 fix: ci (#1193)
  • f9f0860 chore: v3.3.10
  • 08a7650 chore: remove un-synced tests
  • 1208aa6 feat: add new flag and patch sec dep (#1102)
  • 6ad6099 chore: sec patch
  • 48c03ab chore: v3.3.9
  • a1341bd Merge pull request #1078 from lneveu/fix/process-exit-hang
  • ee001bd fix: use process.exitCode instead of process.exit in compilerCallback
  • 7b1e946 chore: version update
  • 64fd810 Merge pull request #1065 from webpack/fix/patch
  • 70bf934 tests: add schema tests
  • 4275fd5 chore: remove lint err
  • 065e87e chore: abstract validation
  • 55b770c chore: vuln patch
  • d28f9f5 fix: support both webpack versions
  • 9487ee5 chore: v3.3.7
  • b20ecd3 Merge pull request #1024 from webpack/fix/no-config-mode
  • 45b9127 chore: resolve differently
  • 43fc033 chore: update lockfile & pass nil
  • 97d5c75 chore: lock deps

Compare


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

🧐 View latest project report

🛠 Adjust upgrade PR settings

🔕 Ignore this dependency or unsubscribe from future upgrade PRs

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant