Skip to content

[Snyk] Fix for 1 vulnerabilities - #158

Closed
karencapiiro wants to merge 1 commit into
masterfrom
snyk-fix-e048a782e7060a65d3fc78922026ee93
Closed

karencapiiro wants to merge 1 commit into
masterfrom
snyk-fix-e048a782e7060a65d3fc78922026ee93

Conversation

@karencapiiro

Copy link
Copy Markdown
Owner

snyk-top-banner

Snyk has created this PR to fix 1 vulnerabilities in the npm dependencies of this project.

Snyk changed the following file(s):

  • deps/npm/package.json

Vulnerabilities that will be fixed with an upgrade:

Issue Score
high severity Infinite loop
SNYK-JS-BRACEEXPANSION-15789759
  99  

Breaking Change Risk

Merge Risk: High

Notice: This assessment is enhanced by AI.


Important

  • Check the changes in this PR to ensure they won't cause issues with your project.
  • Max score is 1000. Note that the real score may have changed since the PR was raised.
  • This PR was automatically created by Snyk using the credentials of a real user.

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report
📜 Customise PR templates
🛠 Adjust project settings
📚 Read about Snyk's upgrade logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Learn about vulnerability in an interactive lesson of Snyk Learn.

@karencapiiro

Copy link
Copy Markdown
Owner Author

Merge Risk: High

This upgrade includes many major version bumps for critical dependencies, introducing significant breaking changes. The most impactful changes are in glob, rimraf, and the coordinated updates across @npmcli packages which drop support for older, end-of-life (EOL) Node.js versions.

Top Breaking Changes:

  • glob 7.2.3 → 12.0.0:

    • API Redesign: The core API is now Promise-based instead of using callbacks. Exported function names have changed.
    • Node.js Support: Version 8.x dropped support for Node.js <12, and v10.x dropped support for Node.js <16.
    • Behavioral Changes: The \ character is now exclusively an escape character and not a path separator. Several options like silent, strict, nonull, nounique, and nosort have been removed.
    • Recommendation: Code using glob must be updated to use the new Promise-based API and function names. Verify that path separators are correctly handled, especially on Windows.
  • rimraf 3.0.2 → 6.1.1:

    • API Redesign: The main function is now Promise-based, and callbacks are no longer supported. There is no longer a default export; functions must be imported by name (e.g., import { rimraf } from 'rimraf').
    • Node.js Support: Version 6.x requires Node.js 20 or higher.
    • Recommendation: Update imports to use named exports and refactor any callback-based usage to Promises.
  • @npmcli/* Packages & npm v9/v10:

    • Node.js Support: The numerous @npmcli packages, pacote, make-fetch-happen, and node-gyp have all dropped support for older Node.js versions in alignment with npm CLI v9 and v10. npm v9 requires Node.js ^14.17.0 || ^16.13.0 || &gt;=18.0.0, and npm v10 requires ^18.17.0 || &gt;=20.5.0.
    • Other Changes: npm v9 and v10 introduced other breaking changes, such as stricter handling of auth configuration and removal of implicit if-present logic for workspace scripts.

Other Major Upgrades:

  • pacote 13.6.2 → 21.0.1: Drops support for Node.js 14 and now requires Node.js ^20.17.0 || &gt;=22.9.0.
  • make-fetch-happen 10.2.1 → 15.0.0: Now requires Node.js ^20.17.0 || &gt;=22.9.0.
  • node-gyp 9.4.1 → 12.0.0: Aligns with npm 11's Node.js engine requirements.
  • The remaining libnpm* and other @npmcli packages have been updated in lockstep, primarily to drop support for EOL Node.js versions and introduce internal API changes.

Notice 🤖: This content was augmented using artificial intelligence. AI-generated content may contain errors and should be reviewed for accuracy before use.

@orca-security-eu orca-security-eu Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Orca Security Scan Summary

Status Check Issues by priority
Passed Passed Infrastructure as Code high 0   medium 0   low 0   info 0 View in Orca
Passed Passed Secrets high 0   medium 0   low 0   info 0 View in Orca
Passed Passed Vulnerabilities high 0   medium 0   low 0   info 0 View in Orca

@karencapiiro

Copy link
Copy Markdown
Owner Author

✅ This PR has been automatically closed

The security issues addressed by this pull request are no longer present in the latest project scan. All vulnerabilities this PR was created to fix have been resolved through other means (e.g., dependency updates, direct fixes, or changes in vulnerability data).

Resolved Issues

  • SNYK-JS-BRACEEXPANSION-15789759

What should I do?

No action is required. If you believe this PR was closed in error, you can reopen it and contact Snyk support.


This action was performed automatically by Snyk.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants