Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Snyk] Security upgrade @jupyterlab/application from 2.3.1 to 3.0.0 #6

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

snyk-bot
Copy link

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • js/package.json

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
medium severity 713/1000
Why? Proof of Concept exploit, Recently disclosed, Has a fix available, CVSS 6.4
Authorization Bypass
SNYK-JS-URLPARSE-2407759
Yes Proof of Concept
medium severity 718/1000
Why? Proof of Concept exploit, Recently disclosed, Has a fix available, CVSS 6.5
Authorization Bypass
SNYK-JS-URLPARSE-2407770
Yes Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: @jupyterlab/application The new version differs by 250 commits.
  • bdee06a bump version
  • 8c97d20 New version
  • 12e22df Update milestone git commit range
  • 36e0512 Merge pull request #9505 from jasongrout/linkcheck
  • 14cf824 Fix another broken link
  • 2fc3c9c Add back in the changelog link checks
  • 146ffe2 Fix broken link
  • 136d2ec Merge pull request #9252 from jasongrout/extdevdocs
  • e76cf90 Prime link cache by ignoring changelog
  • e2a7951 Cache requests when doing the linkcheck ci test.
  • 6b245e5 Merge pull request #9503 from jasongrout/jlabserver
  • 86d336c Fix typo
  • 3fdb311 Update jupyterlab_server dependency to 2.0 final release.
  • 85f84ee Mention property inspector moved to right sidebar.
  • 1d07008 Delete duplicate docs.
  • 0378597 Fix JLab docs to point to new generated typedoc docs.
  • 4d0d373 Add typedoc module names in ensure-package script.
  • 64fbeaa Add blank line after copyright
  • 717266d Fix typo
  • a45b789 Edit user-level documentation to consistently use source and prebuilt terms.
  • 642a906 Change user-facing terminology from federated to prebuilt.
  • 04c32ef More editing about prebuilt workflow
  • c0316e3 Delete outdated information on packaging extensions
  • ecda1b7 Continuing editing about css files and prebuilt extensions.

See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant