Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Snyk] Upgrade yeoman-generator from 0.22.6 to 5.7.0 #3

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

snyk-bot
Copy link

Snyk has created this PR to upgrade yeoman-generator from 0.22.6 to 5.7.0.

ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


Warning: This is a major version upgrade, and may be a breaking change.

  • The recommended version is 59 versions ahead of your current version.
  • The recommended version was released 22 days ago, on 2022-07-29.

The recommended version fixes:

Severity Issue PriorityScore (*) Exploit Maturity
Regular Expression Denial of Service (ReDoS)
npm:underscore.string:20170908
589/1000
Why? Has a fix available, CVSS 7.5
No Known Exploit
Prototype Pollution
npm:deep-extend:20180409
589/1000
Why? Has a fix available, CVSS 7.5
Proof of Concept
Arbitrary File Overwrite
SNYK-JS-TAR-174125
589/1000
Why? Has a fix available, CVSS 7.5
Proof of Concept
Arbitrary File Write
SNYK-JS-TAR-1579155
589/1000
Why? Has a fix available, CVSS 7.5
No Known Exploit
Arbitrary File Write
SNYK-JS-TAR-1579152
589/1000
Why? Has a fix available, CVSS 7.5
No Known Exploit
Arbitrary File Write
SNYK-JS-TAR-1579147
589/1000
Why? Has a fix available, CVSS 7.5
No Known Exploit
Arbitrary File Overwrite
SNYK-JS-TAR-1536531
589/1000
Why? Has a fix available, CVSS 7.5
No Known Exploit
Arbitrary File Overwrite
SNYK-JS-TAR-1536528
589/1000
Why? Has a fix available, CVSS 7.5
No Known Exploit
Improper Privilege Management
SNYK-JS-SHELLJS-2332187
589/1000
Why? Has a fix available, CVSS 7.5
Proof of Concept
Improper Privilege Management
SNYK-JS-SHELLJS-2332187
589/1000
Why? Has a fix available, CVSS 7.5
Proof of Concept
Prototype Pollution
SNYK-JS-SETVALUE-450213
589/1000
Why? Has a fix available, CVSS 7.5
Proof of Concept
Prototype Pollution
SNYK-JS-SETVALUE-1540541
589/1000
Why? Has a fix available, CVSS 7.5
Proof of Concept
Prototype Pollution
SNYK-JS-SETVALUE-450213
589/1000
Why? Has a fix available, CVSS 7.5
Proof of Concept
Prototype Pollution
SNYK-JS-SETVALUE-1540541
589/1000
Why? Has a fix available, CVSS 7.5
Proof of Concept
Regular Expression Denial of Service (ReDoS)
SNYK-JS-NTHCHECK-1586032
589/1000
Why? Has a fix available, CVSS 7.5
Proof of Concept
Prototype Pollution
SNYK-JS-MIXINDEEP-450212
589/1000
Why? Has a fix available, CVSS 7.5
Proof of Concept
Command Injection
SNYK-JS-LODASHTEMPLATE-1088054
589/1000
Why? Has a fix available, CVSS 7.5
Proof of Concept
Prototype Pollution
SNYK-JS-LODASH-73638
589/1000
Why? Has a fix available, CVSS 7.5
Proof of Concept
Prototype Pollution
SNYK-JS-LODASH-608086
589/1000
Why? Has a fix available, CVSS 7.5
Proof of Concept
Prototype Pollution
SNYK-JS-LODASH-567746
589/1000
Why? Has a fix available, CVSS 7.5
Proof of Concept
Prototype Pollution
SNYK-JS-LODASH-450202
589/1000
Why? Has a fix available, CVSS 7.5
Proof of Concept
Command Injection
SNYK-JS-LODASH-1040724
589/1000
Why? Has a fix available, CVSS 7.5
Proof of Concept
Prototype Pollution
SNYK-JS-LODASH-608086
589/1000
Why? Has a fix available, CVSS 7.5
Proof of Concept
Prototype Pollution
SNYK-JS-LODASH-567746
589/1000
Why? Has a fix available, CVSS 7.5
Proof of Concept
Command Injection
SNYK-JS-LODASH-1040724
589/1000
Why? Has a fix available, CVSS 7.5
Proof of Concept
Prototype Pollution
SNYK-JS-LODASH-608086
589/1000
Why? Has a fix available, CVSS 7.5
Proof of Concept
Prototype Pollution
SNYK-JS-LODASH-567746
589/1000
Why? Has a fix available, CVSS 7.5
Proof of Concept
Prototype Pollution
SNYK-JS-LODASH-450202
589/1000
Why? Has a fix available, CVSS 7.5
Proof of Concept
Command Injection
SNYK-JS-LODASH-1040724
589/1000
Why? Has a fix available, CVSS 7.5
Proof of Concept
Prototype Pollution
SNYK-JS-INI-1048974
589/1000
Why? Has a fix available, CVSS 7.5
Proof of Concept
Denial of Service (DoS)
SNYK-JS-FILETYPE-2958042
589/1000
Why? Has a fix available, CVSS 7.5
No Known Exploit
Arbitrary Code Execution
SNYK-JS-ESLINTUTILS-460220
589/1000
Why? Has a fix available, CVSS 7.5
No Known Exploit
Remote Memory Exposure
SNYK-JS-BL-608877
589/1000
Why? Has a fix available, CVSS 7.5
Proof of Concept
Prototype Pollution
SNYK-JS-ASYNC-2441827
589/1000
Why? Has a fix available, CVSS 7.5
Proof of Concept
Prototype Pollution
SNYK-JS-AJV-584908
589/1000
Why? Has a fix available, CVSS 7.5
No Known Exploit
Regular Expression Denial of Service (ReDoS)
SNYK-JS-ACORN-559469
589/1000
Why? Has a fix available, CVSS 7.5
No Known Exploit
Regular Expression Denial of Service (ReDoS)
SNYK-JS-ACORN-559469
589/1000
Why? Has a fix available, CVSS 7.5
No Known Exploit
Uninitialized Memory Exposure
npm:tunnel-agent:20170305
589/1000
Why? Has a fix available, CVSS 7.5
Proof of Concept
Time of Check Time of Use (TOCTOU)
npm:chownr:20180731
589/1000
Why? Has a fix available, CVSS 7.5
No Known Exploit
Regular Expression Denial of Service (ReDoS)
SNYK-JS-PATHPARSE-1077067
589/1000
Why? Has a fix available, CVSS 7.5
Proof of Concept
Prototype Pollution
SNYK-JS-MINIMIST-559764
589/1000
Why? Has a fix available, CVSS 7.5
Proof of Concept
Prototype Pollution
SNYK-JS-MINIMIST-559764
589/1000
Why? Has a fix available, CVSS 7.5
Proof of Concept
Prototype Pollution
npm:lodash:20180130
589/1000
Why? Has a fix available, CVSS 7.5
Proof of Concept
Regular Expression Denial of Service (ReDoS)
SNYK-JS-LODASH-73639
589/1000
Why? Has a fix available, CVSS 7.5
Proof of Concept
Regular Expression Denial of Service (ReDoS)
SNYK-JS-LODASH-1018905
589/1000
Why? Has a fix available, CVSS 7.5
Proof of Concept
Regular Expression Denial of Service (ReDoS)
SNYK-JS-LODASH-1018905
589/1000
Why? Has a fix available, CVSS 7.5
Proof of Concept
Regular Expression Denial of Service (ReDoS)
SNYK-JS-LODASH-1018905
589/1000
Why? Has a fix available, CVSS 7.5
Proof of Concept
Regular Expression Denial of Service (ReDoS)
SNYK-JS-HOSTEDGITINFO-1088355
589/1000
Why? Has a fix available, CVSS 7.5
Proof of Concept
Arbitrary File Write via Archive Extraction (Zip Slip)
SNYK-JS-DECOMPRESSTAR-559095
589/1000
Why? Has a fix available, CVSS 7.5
Proof of Concept
Arbitrary File Write via Archive Extraction (Zip Slip)
SNYK-JS-DECOMPRESS-557358
589/1000
Why? Has a fix available, CVSS 7.5
Proof of Concept
Regular Expression Denial of Service (ReDoS)
SNYK-JS-TAR-1536758
589/1000
Why? Has a fix available, CVSS 7.5
No Known Exploit
Prototype Pollution
SNYK-JS-MINIMIST-2429795
589/1000
Why? Has a fix available, CVSS 7.5
Proof of Concept
Prototype Pollution
SNYK-JS-MINIMIST-2429795
589/1000
Why? Has a fix available, CVSS 7.5
Proof of Concept
Validation Bypass
SNYK-JS-KINDOF-537849
589/1000
Why? Has a fix available, CVSS 7.5
Proof of Concept
Denial of Service (DoS)
SNYK-JS-JUSTEXTEND-72674
589/1000
Why? Has a fix available, CVSS 7.5
No Known Exploit

(*) Note that the real score may have changed since the PR was raised.

Release notes
Package name: yeoman-generator
  • 5.7.0 - 2022-07-29
    • make prompt default value dynamic ea460eb
    • show error message when task fails. 92cc534

    v5.6.1...v5.7.0

  • 5.6.1 - 2022-01-19
    • Move custom args inside the runAsync for better error handling ef3f702
    • Allow task to override taskPrefix. d2f4274
    • Fix destinationRoot overridden by current value. f6e1e67
    • Fix resolved when not passed by options. 52ac34c

    v5.6.0...v5.6.1

  • 5.6.0 - 2022-01-18

    v5.5.2...v5.6.0

  • 5.5.2 - 2022-01-04
    • Fix createStorage with options. 185a408

    v5.5.1...v5.5.2

  • 5.5.1 - 2022-01-04
    • Add options parameter to createStorage. 82db7d0

    v5.5.0...v5.5.1

  • 5.5.0 - 2022-01-04
    • Rework private methods. dac452e
    • Add args to queueTask. cf8580f
    • Add optional support to sorted Storage. cf2e53f
    • Documentation improvements.

    v5.4.2...v5.5.0

  • 5.4.2 - 2021-08-21

    v5.4.1...v5.4.2

  • 5.4.1 - 2021-08-12

    v5.4.0...v5.4.1

  • 5.4.0 - 2021-07-05
    • Add immediately parameter to composeWith 8fd5c86
    • Add support to beforeQueue. b8747da

    v5.3.0...v5.4.0

  • 5.3.0 - 2021-05-23

    v5.2.0...v5.3.0

  • 5.2.0 - 2021-03-13
  • 5.1.0 - 2021-03-06
  • 5.0.1 - 2021-02-22
  • 5.0.0 - 2021-02-20
  • 5.0.0-rc.0 - 2021-02-15
  • 5.0.0-beta.1 - 2021-02-13
  • 4.13.0 - 2021-01-30
  • 4.12.0 - 2020-08-31
  • 4.11.0 - 2020-06-26
  • 4.10.1 - 2020-05-11
  • 4.10.0 - 2020-05-03
  • 4.9.0 - 2020-04-24
  • 4.8.3 - 2020-04-22
  • 4.8.2 - 2020-04-13
  • 4.8.1 - 2020-04-12
  • 4.8.0 - 2020-04-08
  • 4.7.2 - 2020-03-14
  • 4.7.1 - 2020-03-11
  • 4.7.0 - 2020-03-09
  • 4.6.0 - 2020-02-26
  • 4.5.0 - 2020-01-27
  • 4.4.0 - 2019-12-24
  • 4.3.0 - 2019-12-15
  • 4.2.0 - 2019-10-27
  • 4.1.0 - 2019-09-26
  • 4.0.2 - 2019-09-01
  • 4.0.1 - 2019-05-28
  • 4.0.0 - 2019-05-08
  • 3.2.0 - 2018-12-22
  • 3.1.1 - 2018-07-28
  • 3.1.0 - 2018-07-24
  • 3.0.0 - 2018-07-01
  • 2.0.5 - 2018-04-30
  • 2.0.4 - 2018-04-13
  • 2.0.3 - 2018-02-19
  • 2.0.2 - 2017-12-26
  • 2.0.1 - 2017-09-30
  • 2.0.0 - 2017-09-12
  • 1.1.1 - 2017-03-05
  • 1.1.0 - 2017-01-27
  • 1.0.1 - 2016-12-20
  • 1.0.0 - 2016-12-17
  • 1.0.0-rc1 - 2016-12-08
  • 0.24.1 - 2016-07-18
  • 0.23.4 - 2016-06-16
  • 0.23.3 - 2016-05-04
  • 0.23.2 - 2016-05-03
  • 0.23.1 - 2016-05-03
  • 0.23.0 - 2016-05-02
  • 0.22.6 - 2016-04-19
from yeoman-generator GitHub release notes
Commit messages
Package name: yeoman-generator
  • 58bd701 5.7.0
  • 2debebf Bump actions/setup-node from 3.3.0 to 3.4.1 (#1359)
  • 5feabbe Bump actions/stale from 5.0.0 to 5.1.0 (#1360)
  • 8c3e594 Bump actions/setup-node from 3.2.0 to 3.3.0 (#1356)
  • ea460eb make prompt default value dynamic
  • 6518394 Bump peter-evans/create-pull-request from 4.0.3 to 4.0.4
  • 3fd1b7c Bump transitional dependencies
  • e30899c Bump actions/setup-node from 2.1.4 to 3.2.0
  • da14af9 Bump peter-evans/create-pull-request from 3.10.1 to 4.0.3
  • 2904481 Bump actions/stale from 3.0.17 to 5.0.0
  • 5c89e21 Bump execa from 4.1.0 to 5.1.1
  • 6b7f56d Bump sinon from 9.2.4 to 13.0.2
  • 305498e chore: ignore github-username@7 dependency
  • 80174aa Bump mocha from 8.4.0 to 9.2.2
  • 97431e8 chore: update ignored dependencies
  • 82ba67d chore: ignore execa@6 dependency
  • 4893edb Bump inquirer from 7.3.3 to 8.2.4
  • 76067d5 Bump ejs from 3.1.6 to 3.1.8
  • 3226d31 Bump actions/checkout from 2 to 3
  • 225e6e6 chore: add ignored dependencies
  • fb46944 chore: enable dependabot for major versions
  • cefb66e Set permissions for GitHub actions
  • 615819f Bump transitional dependencies (#1333)
  • 6907f3a Bump minimist from 1.2.5 to 1.2.6 (#1331)

Compare


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

🧐 View latest project report

🛠 Adjust upgrade PR settings

🔕 Ignore this dependency or unsubscribe from future upgrade PRs

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant