[Snyk] Fix for 1 vulnerable dependencies #51

Merged
argoyle merged 2 commits from snyk-fix-0c002eacde43dabe83a66b8663c0a828 into master 2019-07-04 11:07:07 +00:00
argoyle commented 2019-07-04 10:52:52 +00:00 (Migrated from gitlab.com)

Description

This Merge Request fixes one or more vulnerable packages in the yarn dependencies of this project.
See the Snyk test report for more details.

Snyk Project: unboundsoftware/dancefinder/dancefinder-app:package.json

Snyk Organization: argoyle

Lockfile

If you are using package-lock.json or yarn.lock, please re-lock your dependencies and push an updated lockfile before merging this Merge Request.

Changes included in this Merge Request

  • A Snyk policy (.snyk) file, with updated settings.

Vulnerabilities that will be fixed

With a Snyk patch:

You can read more about Snyk's upgrade and patch logic in Snyk's documentation.

Check the changes in this Merge Request to ensure they won't cause issues with your project.

Stay secure,
The Snyk team

Note: You are seeing this because you or someone else with access to this repository has authorised Snyk to open Fix Merge Requests. To review the settings for this Snyk project please go to the project settings page.

#### Description This Merge Request fixes one or more vulnerable packages in the `yarn` dependencies of this project. See the [Snyk test report](https://app.snyk.io/org/argoyle/test/gitlab/fdbefbeb-8f1c-483c-917e-152c9523c009/master..snyk-fix-0c002eacde43dabe83a66b8663c0a828) for more details. #### Snyk Project: [unboundsoftware/dancefinder/dancefinder-app:package.json](https://app.snyk.io/org/argoyle/project/fdbefbeb-8f1c-483c-917e-152c9523c009) #### Snyk Organization: [argoyle](https://app.snyk.io/org/argoyle) #### Lockfile If you are using `package-lock.json` or `yarn.lock`, please re-lock your dependencies and push an updated lockfile before merging this Merge Request. #### Changes included in this Merge Request - A Snyk policy (`.snyk`) file, with updated settings. #### Vulnerabilities that will be fixed ##### With a [Snyk patch](https://snyk.io/docs/fixing-vulnerabilities/#patches): - [SNYK-JS-LODASH-450202](https://snyk.io/vuln/SNYK-JS-LODASH-450202) You can read more about Snyk's upgrade and patch logic in [Snyk's documentation](https://snyk.io/docs/using-snyk/). Check the changes in this Merge Request to ensure they won't cause issues with your project. Stay secure, The Snyk team _**Note**: You are seeing this because you or someone else with access to this repository has authorised Snyk to open Fix Merge Requests. To review the settings for this Snyk project please go to the [project settings page](https://app.snyk.io/org/argoyle/project/fdbefbeb-8f1c-483c-917e-152c9523c009/settings)._ [//]: # (snyk:metadata:{"type":"auto","packageManager":"yarn","vulns":["SNYK-JS-LODASH-450202"],"patch":["SNYK-JS-LODASH-450202"],"upgrade":[],"isBreakingChange":false,"env":"prod","dependencies":[],"prType":"fix"})
argoyle commented 2019-07-04 10:57:21 +00:00 (Migrated from gitlab.com)

added 1 commit

Compare with previous version

added 1 commit <ul><li>467c60c1 - Update yarn.lock</li></ul> [Compare with previous version](/unboundsoftware/dancefinder/dancefinder-app/merge_requests/2/diffs?diff_id=47283299&start_sha=0a298df15ec93789e2d2fe062b6c36e83869526b)
argoyle (Migrated from gitlab.com) scheduled this pull request to auto merge when all checks succeed 2019-07-04 11:05:50 +00:00
argoyle commented 2019-07-04 11:07:07 +00:00 (Migrated from gitlab.com)

merged

merged
argoyle commented 2019-07-04 11:07:07 +00:00 (Migrated from gitlab.com)

mentioned in commit 05d1252456

mentioned in commit 05d1252456c5a7c0dfb07cfdf439ebbda4f16a40
Sign in to join this conversation.