[Snyk] Security upgrade npm from 5.10.0 to 7.0.0#53
[Snyk] Security upgrade npm from 5.10.0 to 7.0.0#53tjenkinson wants to merge 1 commit intomasterfrom
Conversation
The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-JS-QS-14724253
|
Review the following changes in direct dependencies. Learn more about Socket for GitHub.
|
|
Warning Review the following alerts detected in dependencies. According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.
|
There was a problem hiding this comment.
Pull request overview
This PR addresses a high-severity security vulnerability (SNYK-JS-QS-14724253) by upgrading the npm dependency in a test case from version 5.x to 7.x. The vulnerability relates to allocation of resources without limits or throttling, with a severity score of 828/1000.
- Upgrades npm dependency from ^5.7.1 to ^7.0.0 in a test package
- Fixes high-severity security vulnerability in the qs package (transitive dependency)
- Major version upgrade that may include breaking changes
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
Snyk has created this PR to fix 1 vulnerabilities in the npm dependencies of this project.
Snyk changed the following file(s):
tests/cases/user/npm/package.jsonVulnerabilities that will be fixed with an upgrade:
SNYK-JS-QS-14724253
Important
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.
For more information:
🧐 View latest project report
📜 Customise PR templates
🛠 Adjust project settings
📚 Read about Snyk's upgrade logic
Learn how to fix vulnerabilities with free interactive lessons:
🦉 Allocation of Resources Without Limits or Throttling