+
Skip to content

Conversation

ddzzj
Copy link
Owner

@ddzzj ddzzj commented Oct 18, 2023

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to upgrade tslib from 2.3.1 to 2.6.2.

ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


  • The recommended version is 9 versions ahead of your current version.
  • The recommended version was released 2 months ago, on 2023-08-18.

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

🧐 View latest project report

🛠 Adjust upgrade PR settings

🔕 Ignore this dependency or unsubscribe from future upgrade PRs

Snyk has created this PR to upgrade tslib from 2.3.1 to 2.6.2.

See this package in npm:


See this project in Snyk:
https://app.snyk.io/org/ddzzj/project/29f4c90a-f0a6-44fc-a53e-4272ff5c2962?utm_source=github&utm_medium=referral&page=upgrade-pr
Copy link

@bridgecrew bridgecrew bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Bridgecrew has found errors in this PR ⬇️

},
"dependencies": {
"tslib": "^2.0.1"
"tslib": "^2.6.2"
Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

ua-parser-js 0.7.30 / package.json

Total vulnerabilities: 1

Critical: 0 High: 1 Medium: 0 Low: 0
Vulnerability IDSeverityCVSSFixed inStatus
CVE-2022-25927 HIGH HIGH 7.5 0.7.33 Open

},
"dependencies": {
"tslib": "^2.0.1"
"tslib": "^2.6.2"
Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

qs 6.7.0 / package.json

Total vulnerabilities: 1

Critical: 0 High: 1 Medium: 0 Low: 0
Vulnerability IDSeverityCVSSFixed inStatus
CVE-2022-24999 HIGH HIGH 7.5 6.10.3 Open

},
"dependencies": {
"tslib": "^2.0.1"
"tslib": "^2.6.2"
Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

semver 7.3.5 / package.json

Total vulnerabilities: 1

Critical: 0 High: 1 Medium: 0 Low: 0
Vulnerability IDSeverityCVSSFixed inStatus
CVE-2022-25883 HIGH HIGH 7.5 7.5.2 Open

},
"dependencies": {
"tslib": "^2.0.1"
"tslib": "^2.6.2"
Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

minimatch 3.0.4 / package.json

Total vulnerabilities: 1

Critical: 0 High: 1 Medium: 0 Low: 0
Vulnerability IDSeverityCVSSFixed inStatus
CVE-2022-3517 HIGH HIGH 7.5 3.0.5 Open

},
"dependencies": {
"tslib": "^2.0.1"
"tslib": "^2.6.2"
Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

shelljs 0.8.4 / package.json

Total vulnerabilities: 2

Critical: 0 High: 1 Medium: 1 Low: 0
Vulnerability IDSeverityCVSSFixed inStatus
CVE-2022-0144 HIGH HIGH 7.1 0.8.5 Open
GHSA-64g7-mvw6-v9qj MEDIUM MEDIUM 4 0.8.5 Open

},
"dependencies": {
"tslib": "^2.0.1"
"tslib": "^2.6.2"
Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

follow-redirects 1.14.4 / package.json

Total vulnerabilities: 2

Critical: 0 High: 0 Medium: 2 Low: 0
Vulnerability IDSeverityCVSSFixed inStatus
CVE-2022-0536 MEDIUM MEDIUM 5.9 1.14.8 Open
CVE-2022-0155 MEDIUM MEDIUM 6.5 1.14.7 Open

},
"dependencies": {
"tslib": "^2.0.1"
"tslib": "^2.6.2"
Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

decode-uri-component 0.2.0 / package.json

Total vulnerabilities: 2

Critical: 0 High: 1 Medium: 1 Low: 0
Vulnerability IDSeverityCVSSFixed inStatus
CVE-2022-38900 HIGH HIGH 7.5 0.2.1 Open
CVE-2022-38778 MEDIUM MEDIUM 6.5 0.2.1 Open

},
"dependencies": {
"tslib": "^2.0.1"
"tslib": "^2.6.2"
Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

tslib 1.14.1 / package.json

MEDIUM  Noncompliant License (0BSD)

This package contains a license that is not OSI-approved.

},
"dependencies": {
"tslib": "^2.0.1"
"tslib": "^2.6.2"
Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

tslib 2.3.1 / package.json

MEDIUM  Noncompliant License (0BSD)

This package contains a license that is not OSI-approved.

},
"dependencies": {
"tslib": "^2.0.1"
"tslib": "^2.6.2"
Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

tslib 2.6.2 / package.json

MEDIUM  Noncompliant License (0BSD)

This package contains a license that is not OSI-approved.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

点击 这是indexloc提供的php浏览器服务,不要输入任何密码和下载