Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Snyk] Upgrade vm2 from 3.9.9 to 3.9.17 #25

Open
wants to merge 1 commit into
base: main
Choose a base branch
from

Conversation

samul-1
Copy link
Owner

@samul-1 samul-1 commented May 9, 2023

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to upgrade vm2 from 3.9.9 to 3.9.17.

ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


  • The recommended version is 8 versions ahead of your current version.
  • The recommended version was released 22 days ago, on 2023-04-17.

The recommended version fixes:

Severity Issue PriorityScore (*) Exploit Maturity
Arbitrary Code Execution
SNYK-JS-VM2-2990237
811/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 9.8
Proof of Concept
Sandbox Bypass
SNYK-JS-VM2-3018201
811/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 9.8
Proof of Concept
Sandbox Escape
SNYK-JS-VM2-5415299
811/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 9.8
Proof of Concept
Sandbox Escape
SNYK-JS-VM2-5422057
811/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 9.8
Proof of Concept
Improper Handling of Exceptional Conditions
SNYK-JS-VM2-5426093
811/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 9.8
No Known Exploit

(*) Note that the real score may have changed since the PR was raised.

Release notes
Package name: vm2 from vm2 GitHub release notes
Commit messages
Package name: vm2
  • 4f63dc2 Release 3.9.17
  • f3db4de Handle host errors captured in Promises
  • 4b22e87 Ensure every catch block is protected
  • 24c724d Release 3.9.16
  • 115d164 Release 3.9.15
  • d534e57 Wrap host objects passes through prepareStackTrace
  • e541782 Merge pull request #506 from XmiliaH/release-3.9.14
  • 066afd1 Release 3.9.14
  • fe3ab68 Merge pull request #505 from NapkinHQ/fix-conditional-export-resolve
  • eefe3f1 update .eslintignore;update index.d.ts resolve return type
  • c70d945 add 'type':'module' in es module package.json
  • 4659ce0 add additional return type for resolve signature
  • 1da4415 add missing semicolon
  • 5a86675 Support conditional export resolution with custom resolver
  • e7828cf Merge pull request #502 from karanssj4/patch-2
  • 6032907 Update CHANGELOG.md
  • d4bcc21 Merge pull request #495 from XmiliaH/release-3.9.13
  • 0c46bdb Finish release 3.9.13
  • 90e4230 Merge pull request #494 from XmiliaH/fix-493
  • 1c365f7 Fix errors in index.d.ts
  • 4aa3605 Merge pull request #492 from XmiliaH/release-3.9.12
  • 99b6a9d Finish release 3.9.12
  • 81f625d Merge pull request #489 from XmiliaH/add-filesystem-api
  • ffa9398 Merge pull request #488 from XmiliaH/update-readme

Compare


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

🧐 View latest project report

🛠 Adjust upgrade PR settings

🔕 Ignore this dependency or unsubscribe from future upgrade PRs

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants