Skip to content

Comments

[Snyk] Upgrade node-gyp from 9.3.1 to 9.4.0#4

Open
revagomes wants to merge 1 commit intomasterfrom
snyk-upgrade-48c3bc7daa319bb9f0f9760129b33280
Open

[Snyk] Upgrade node-gyp from 9.3.1 to 9.4.0#4
revagomes wants to merge 1 commit intomasterfrom
snyk-upgrade-48c3bc7daa319bb9f0f9760129b33280

Conversation

@revagomes
Copy link
Owner

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to upgrade node-gyp from 9.3.1 to 9.4.0.

ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


  • The recommended version is 1 version ahead of your current version.
  • The recommended version was released 22 days ago, on 2023-06-13.

The recommended version fixes:

Severity Issue PriorityScore (*) Exploit Maturity
Regular Expression Denial of Service (ReDoS)
SNYK-JS-SEMVER-3247795
444/1000
Why? Proof of Concept exploit, Recently disclosed, CVSS 5.3
Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Release notes
Package name: node-gyp from node-gyp GitHub release notes
Commit messages
Package name: node-gyp
  • 33391db chore: release 9.4.0
  • a0b3d1c test: remove deprecated Node.js and Python (#2868)
  • 7a3fe1c win,install: only download target_arch node.lib (#2857)
  • 55048f8 fix: log statement is for devDir not nodedir (#2840)
  • 5df2b72 Migration from tap to mocha (#2851)
  • aaa117c fix: extract tarball to temp directory on Windows (#2846)
  • bb76021 feat: add support for native windows arm64 build tools
  • 6f3c2d3 docs: docs/README.md add advise about deprecated node-sass (#2828)
  • 02480f6 update make-fetch-happen to 11.0.3 (#2796)
  • c7927e2 doc: Update README.md (#2822)
  • 337e8e6 chore: get update-gyp.py to work with Python >= v3.5 (#2826)
  • 41882a9 Improved advise on repacing node-sass with sass (#2758)
  • fc0ddc6 feat: Upgrade Python linting from flake8 to ruff (#2815)

Compare


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

🧐 View latest project report

🛠 Adjust upgrade PR settings

🔕 Ignore this dependency or unsubscribe from future upgrade PRs

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants