[Snyk] Security upgrade npm from 5.6.0 to 7.0.0 #79
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This PR was automatically created by Snyk using the credentials of a real user.
Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.
Changes included in this PR
Vulnerabilities that will be fixed
With an upgrade:
Why? Confidentiality impact: High, Integrity impact: Low, Availability impact: Low, Scope: Unchanged, Exploit Maturity: Proof of Concept, User Interaction (UI): None, Privileges Required (PR): None, Attack Complexity: Low, Attack Vector: Network, EPSS: 0.00043, Social Trends: No, Days since published: 0, Reachable: No, Transitive dependency: Yes, Is Malicious: No, Business Criticality: High, Provider Urgency: High, Package Popularity Score: 99, Impact: 7.84, Likelihood: 2.81, Score Version: V5
SNYK-JS-IP-6240864
(*) Note that the real score may have changed since the PR was raised.
Release notes
Package name: npm
-
7.0.0 - 2020-10-13
- npm/rfcs#239 Improve handling of conflicting
-
7.0.0-rc.4 - 2020-10-09
- #1919 exposes
- fixed handling of invalid package.json file
- do not calculate integrity values of http errors
-
7.0.0-rc.3 - 2020-10-06
- Do not remove
-
7.0.0-rc.2 - 2020-10-02
- Fix regression running 'install' scripts when package.json does not contain a scripts object
-
7.0.0-rc.1 - 2020-10-02
- Allow
- Only do implicit node-gyp build for gyp files named
- Only do implicit node-gyp build for gyp files named
-
7.0.0-rc.0 - 2020-10-01
- #1849 Do not drop peer/dev dep while saving if both set
- Do not install or build if there is a global top bin conflict
- Default to building node-gyp dependencies
- Default to building node-gyp dependencies and projects
- remove many unused dependencies (@ ruyadorno)
-
7.0.0-beta.13 - 2020-09-29
- fix: workspaces install entering an infinite loop
- Save provided range if not a subset of savePrefix
- package-lock.json custom indentation
- Check engine and platform when building ideal tree
-
7.0.0-beta.12 - 2020-09-22
- Resolve race condition with conflicting bin links in local installs
- #1812 Log engine mismatches more usefully
- #1814 Do not loop trying to resolve dependencies that fail to load
- npm/rfcs#224 Do not automatically install optional peer dependencies
- Add the
- fix forwarding configs to resolve pkg spec when adding new deps
- This updates node-gyp to v7, allowing us to deduplicate a lot of significant dependencies.
-
7.0.0-beta.11 - 2020-09-16
- add meta vulnerability calculator for faster audits
- changed parsing specs to be relative to cwd
- fix logging script execution
- fix properly following resolved symlinks
- fix package.json dependencies order
- fix unkown envs to be passed through
- fix setting correct globalPrefix on load
- fix git ignored lockfiles
-
7.0.0-beta.10 - 2020-09-08
-
7.0.0-beta.9 - 2020-09-04
-
7.0.0-beta.8 - 2020-09-01
-
7.0.0-beta.7 - 2020-08-25
-
7.0.0-beta.6 - 2020-08-21
-
7.0.0-beta.5 - 2020-08-18
-
7.0.0-beta.4 - 2020-08-11
-
7.0.0-beta.3 - 2020-08-10
-
7.0.0-beta.2 - 2020-08-07
-
7.0.0-beta.1 - 2020-08-05
-
7.0.0-beta.0 - 2020-08-04
-
6.14.18 - 2022-12-21
-
6.14.17 - 2022-04-28
-
6.14.16 - 2022-01-19
-
6.14.15 - 2021-08-24
-
6.14.14 - 2021-07-27
-
6.14.13 - 2021-04-12
-
6.14.12 - 2021-03-25
-
6.14.11 - 2021-01-08
-
6.14.10 - 2020-12-18
-
6.14.9 - 2020-11-20
-
6.14.8 - 2020-08-17
-
6.14.7 - 2020-07-21
-
6.14.6 - 2020-07-07
-
6.14.5 - 2020-05-04
-
6.14.4 - 2020-03-25
-
6.14.3 - 2020-03-19
-
6.14.2 - 2020-03-03
-
6.14.1 - 2020-02-27
-
6.14.0 - 2020-02-25
-
6.13.7 - 2020-01-28
-
6.13.6 - 2020-01-09
-
6.13.5 - 2020-01-09
-
6.13.4 - 2019-12-11
-
6.13.3 - 2019-12-10
-
6.13.2 - 2019-12-03
-
6.13.1 - 2019-11-18
-
6.13.0 - 2019-11-05
-
6.12.1 - 2019-10-29
-
6.12.0 - 2019-10-08
-
6.12.0-next.0 - 2019-09-26
-
6.11.3 - 2019-09-03
-
6.11.2 - 2019-08-22
-
6.11.1 - 2019-08-21
-
6.11.0 - 2019-08-20
-
6.10.3 - 2019-08-06
-
6.10.2 - 2019-07-23
-
6.10.2-next.3 - 2019-07-22
-
6.10.2-next.2 - 2019-07-21
-
6.10.2-next.1 - 2019-07-17
-
6.10.2-next.0 - 2019-07-16
-
6.10.1 - 2019-07-11
-
6.10.1-next.2 - 2019-07-10
-
6.10.1-next.1 - 2019-07-03
-
6.10.1-next.0 - 2019-07-03
-
6.10.0 - 2019-07-03
-
6.10.0-next.0 - 2019-07-01
-
6.9.2 - 2019-06-27
-
6.9.1-next.0 - 2019-03-20
-
6.9.0 - 2019-03-06
-
6.9.0-next.0 - 2019-02-21
-
6.8.0 - 2019-02-13
-
6.8.0-next.2 - 2019-02-07
-
6.8.0-next.1 - 2019-02-06
-
6.8.0-next.0 - 2019-01-31
-
6.7.0 - 2019-01-23
-
6.6.0 - 2019-01-17
-
6.6.0-next.1 - 2019-01-10
-
6.6.0-next.0 - 2018-12-12
-
6.5.0 - 2018-12-10
-
6.5.0-next.0 - 2018-11-28
-
6.4.1 - 2018-08-29
-
6.4.1-next.0 - 2018-08-23
-
6.4.0 - 2018-08-15
-
6.4.0-next.0 - 2018-08-09
-
6.3.0 - 2018-08-02
-
6.3.0-next.0 - 2018-07-25
-
6.2.0 - 2018-07-14
-
6.2.0-next.1 - 2018-07-05
-
6.2.0-next.0 - 2018-06-29
-
6.1.0 - 2018-05-24
-
6.1.0-next.0 - 2018-05-17
-
6.0.1 - 2018-05-10
-
6.0.1-next.0 - 2018-05-04
-
6.0.0 - 2018-04-24
-
6.0.0-next.2 - 2018-04-21
-
6.0.0-next.1 - 2018-04-13
-
6.0.0-next.0 - 2018-03-23
-
5.10.0 - 2018-05-11
-
5.10.0-next.1 - 2018-05-07
-
5.10.0-next.0 - 2018-04-13
-
5.9.0-next.0 - 2018-03-23
-
5.8.0 - 2018-03-23
-
5.8.0-next.0 - 2018-03-13
-
5.7.1 - 2018-02-22
-
5.7.0 - 2018-02-21
-
5.6.0 - 2017-11-28
from npm GitHub release notesv7.0.0 (2020-10-12)
BUG FIXES
7bcdb3636#1949 fix: ensurepublishConfigis passed through (@ nlf)97978462efix: patchconfig.jsto remove duplicate vals (@ darcyclarke)DOCUMENTATION
60769d757#1911 docs: v7 npm-install refresh (@ ruyadorno)08de49042#1938 docs: v7 using npm config updates (@ ruyadorno)DEPENDENCIES
15366a1cf[email protected]f04a74140[email protected]1de21dce0fix: support dot-separated aliases defined in a.npmrcini files forinit-*configs (@ ruyadorno)a67275cd9[email protected]6fb83b78d[email protected]1ca30cc9b[email protected]28a2d2ba4@ npmcli/[email protected]peerDependenciesin transitive dependencies, so that--forcewill always accept a best effort override, and--strict-peer-depswill fail faster on conflicts.9306c6833[email protected]fafb348ef[email protected]365f2e756[email protected]v7.0.0-rc.4 (2020-10-09)
09b456f2d@ npmcli/[email protected]npm_config_user_agentenv variable (@ nlf)e859fba9e#1936 fix npx for non-interactive shells (@ nlf)9320b8e4f#1906 restore old npx behavior of running existing bins first (@ nlf)7bd47ca2c@ npmcli/[email protected]02737453b[email protected]v7.0.0-rc.3 (2020-10-06)
d816c2efac8f0d5457d48086d0df34595f2e#1902 tests for several commands (@ nlf)6d49207db#1903 Revert "Remove unused npx binary" (@ MylesBorins)138dfc202set executable permissions on bins that node installer usesb06d68078@ npmcli/[email protected]node_modulesfolders from Workspaces whenloadActualraces withbuildIdealTree(@ ruyadorno)2509e3a1b[email protected]v7.0.0-rc.2 (2020-10-02)
6de81a013@ npmcli/[email protected]v7.0.0-rc.1 (2020-10-02)
281a7f39a@ npmcli/[email protected]npm updateto update bundled root dependenciesbinding.gyp384f5ec47update minipass-fetch to fix many 'cb() never called' errors7b1e75906@ npmcli/[email protected]binding.gypc20e2f0c7#1892 Support--omitoptions in npm outdatedv7.0.0-rc.0 (2020-10-01)
3b417055c#1859 fixproxyandhttps-proxyconfig support (@ badeggg)dd7d7a284@ npmcli/[email protected]40c17e12c[email protected]47a8ca1d7[email protected]81073f99a[email protected]67793abd4[email protected]a27e8d006[email protected]893fed45e[email protected]bc20e0c8a[email protected]a2b8fd3c1[email protected]ee4c85b87[email protected]4bdad5fdf[email protected]c394937ec@ npmcli/[email protected]558e9781adeep-equal2aa9a1f8arequestd77594e52npm-registry-couchapp8ec84d9f6tacksa07b421f7lincesee41126e165npm-cache-filename130da51b5npm-registry-mockb355af486sprintf-js721c0a873uid-number9c920e5f5umaskaae1c38bbconfig-chain450845eacfind-npm-prefix963d542d3has-unicodecad9cbc70infer-owner3ae02914dlockfile7bc474d7conce5c5e0099aretrycfaddd334sha3a978ffc7slidev7.0.0-beta.13 (2020-09-29)
405e051f7Fix EBADPLATFORM error message (@#1876)e4d911d21@ npmcli/[email protected]90550b2e0#1853 test coverage and refactor for token command (@ nlf)2715220c9#1858 #1813 do not include omitted optional dependencies in install output (@ ruyadorno)e225ddcf8#1862 #1861 respect depth when runningnpm ls <pkg>(@ ruyadorno)2469ae515#1870 #1780 Add 'fetch-timeout' config (@ isaacs)52114b75e#1871 fixnpm lsfor linked dependencies (@ ruyadorno)9981211c0#1857 #1703 fixnpm outdatedparsing invalid specs (@ ruyadorno)v7.0.0-beta.12 (2020-09-22)
24f3a5448#1811 npm ci should never save package.json or lockfile (@ isaacs)5e780a5f0remove unused spec parameter, assign error code (@ nlf)f019a248aRemove unused npx binary (@ isaacs)db157b3ce@ npmcli/[email protected]strictPeerDepsoption, defaulting tofalseb3a50d275#1846@ npmcli/[email protected]a1d375f6b#1819 Add--strict-peer-depsoption (@ isaacs)5837a4843#1699 Use allow/deny list in docs (@ luciomartinez)v7.0.0-beta.11 (2020-09-16)
63005f4a9#1639 npm view should not output extra newline (@ MylesBorins)3743a42c8#1750 add outdated tests (@ claudiahdz)2019abdf1#1786 add lib/link.js tests (@ ruyadorno)2f8d11968@ npmcli/[email protected]49b2bf5a7@ npmcli/[email protected]f9aac351d[email protected]v7.0.0-beta.10 (2020-09-08)
7418970f0Improve output of dependency node explanations5e49bdaa3#1776 Add 'npm explain' commandCommit messages
Package name: npm
The new version differs by 250 commits.See the full diff
Check the changes in this PR to ensure they won't cause issues with your project.
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.
For more information:
🧐 View latest project report
🛠 Adjust project settings
📚 Read more about Snyk's upgrade and patch logic
Learn how to fix vulnerabilities with free interactive lessons:
🦉 Server-side Request Forgery (SSRF)