Thanks to visit codestin.com
Credit goes to github.com

Skip to content

Conversation

snyk-bot
Copy link
Contributor

Snyk has created this PR to upgrade codemirror from 5.49.2 to 5.63.3.

merge advice
ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


  • The recommended version is 31 versions ahead of your current version.
  • The recommended version was released a month ago, on 2021-10-12.

The recommended version fixes:

Severity Issue PriorityScore (*) Exploit Maturity
Regular Expression Denial of Service (ReDoS)
SNYK-JS-CODEMIRROR-1016937
586/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 5.3
Proof of Concept
Regular Expression Denial of Service (ReDoS)
SNYK-JS-CODEMIRROR-569611
586/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 5.3
No Known Exploit

(*) Note that the real score may have changed since the PR was raised.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

🧐 View latest project report

🛠 Adjust upgrade PR settings

🔕 Ignore this dependency or unsubscribe from future upgrade PRs

Snyk has created this PR to upgrade codemirror from 5.49.2 to 5.63.3.

See this package in npm:


See this project in Snyk:
https://app.snyk.io/org/pinterest-org/project/35cc12a9-a735-45e5-bc6f-5ad2885b9470?utm_source=github&utm_medium=referral&page=upgrade-pr
@github-actions github-actions bot added the title needs formatting PR title must have type (ex. fix:) label Nov 23, 2021
@czgu czgu merged commit f9c2a5f into master Nov 23, 2021
@czgu czgu deleted the snyk-upgrade-13e6cdb95baa238e838db761ef95e0b5 branch November 23, 2021 03:58
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
title needs formatting PR title must have type (ex. fix:)
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants