Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Snyk] Upgrade netlify-cli from 9.16.2 to 17.38.0 #2

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

snyk-io[bot]
Copy link

@snyk-io snyk-io bot commented Dec 31, 2024

snyk-top-banner

Snyk has created this PR to upgrade netlify-cli from 9.16.2 to 17.38.0.

ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


⚠️ Warning: This PR contains major version upgrade(s), and may be a breaking change.

  • The recommended version is 302 versions ahead of your current version.

  • The recommended version was released a month ago.

Issues fixed by the recommended upgrade:

Issue Score Exploit Maturity
high severity Regular Expression Denial of Service (ReDoS)
npm:ansi2html:20151025
118 No Known Exploit
high severity Denial of Service (DoS)
SNYK-JS-HTTPPROXYMIDDLEWARE-8229906
118 Proof of Concept
high severity Server-side Request Forgery (SSRF)
SNYK-JS-IP-6240864
118 Proof of Concept
high severity Server-side Request Forgery (SSRF)
SNYK-JS-IP-6240864
118 Proof of Concept
high severity Prototype Poisoning
SNYK-JS-QS-3153490
118 Proof of Concept
high severity Asymmetric Resource Consumption (Amplification)
SNYK-JS-BODYPARSER-7926860
118 No Known Exploit
high severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-LUXON-3225081
118 Proof of Concept
high severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-NODEFETCH-2964180
118 Proof of Concept
high severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-NODEFETCH-2964180
118 Proof of Concept
high severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-CROSSSPAWN-8303230
118 Proof of Concept
high severity Denial of Service (DoS)
SNYK-JS-DECODEURICOMPONENT-3149970
118 Proof of Concept
high severity Improper Handling of Extra Parameters
SNYK-JS-FOLLOWREDIRECTS-6141137
118 Proof of Concept
high severity Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')
SNYK-JS-GITCLONE-2434308
118 No Known Exploit
high severity Directory Traversal
SNYK-JS-STATICSERVER-5722341
118 Proof of Concept
medium severity Improper Authentication
SNYK-JS-JSONWEBTOKEN-3180022
118 No Known Exploit
medium severity Improper Restriction of Security Token Assignment
SNYK-JS-JSONWEBTOKEN-3180024
118 No Known Exploit
medium severity Use of a Broken or Risky Cryptographic Algorithm
SNYK-JS-JSONWEBTOKEN-3180026
118 No Known Exploit
medium severity Denial of Service (DoS)
SNYK-JS-GRAPHQL-5905181
118 Proof of Concept
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-HTTPCACHESEMANTICS-3248783
118 Proof of Concept
medium severity Prototype Pollution
SNYK-JS-JSON5-3182856
118 Proof of Concept
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-PATHTOREGEXP-8482416
118 Proof of Concept
medium severity Improper Input Validation
SNYK-JS-POSTCSS-5926692
118 No Known Exploit
medium severity Cross-site Scripting (XSS)
SNYK-JS-ROLLUP-8073097
118 Proof of Concept
critical severity Incomplete List of Disallowed Inputs
SNYK-JS-BABELTRAVERSE-5962462
118 Proof of Concept
medium severity Improper Input Validation
SNYK-JS-NANOID-8492085
118 No Known Exploit
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-PATHTOREGEXP-7925106
118 Proof of Concept
medium severity Cross-site Scripting (XSS)
SNYK-JS-COOKIE-8163060
118 No Known Exploit
medium severity Arbitrary File Write via Archive Extraction (Zip Slip)
SNYK-JS-DECOMPRESSTAR-559095
118 Proof of Concept
medium severity Open Redirect
SNYK-JS-EXPRESS-6474509
118 No Known Exploit
medium severity Cross-site Scripting
SNYK-JS-EXPRESS-7926867
118 No Known Exploit
medium severity Information Exposure
SNYK-JS-FOLLOWREDIRECTS-6444610
118 Proof of Concept
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-TERSER-2806366
118 No Known Exploit
low severity Cross-site Scripting
SNYK-JS-SEND-7926862
118 No Known Exploit
low severity Information Exposure
SNYK-JS-FOLLOWREDIRECTS-2396346
118 No Known Exploit
low severity Cross-site Scripting
SNYK-JS-SERVESTATIC-7926865
118 No Known Exploit
low severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-WORDWRAP-3149973
118 Proof of Concept
Release notes
Package name: netlify-cli
  • 17.38.0 - 2024-12-03

    17.38.0 (2024-12-03)

    Features

    Bug Fixes

    • check ip version if settings.useStaticServer (#6936) (be6b07e)
    • deps: update dependency @ netlify/edge-functions to v2.11.1 (#6772) (cd7aeed)
    • deps: update dependency @ sanity/client to v6 (#6650) (fdaabc0)
    • deps: update dependency @ types/node to v20.17.6 (#6918) (9c4eb22)
    • deps: update dependency @ types/node to v20.17.7 (#6933) (fce5cc3)
    • deps: update dependency @ types/node to v22.10.1 (#6942) (2218116)
    • deps: update dependency ci-info to v4.1.0 (#6925) (f4eca65)
    • deps: update dependency ora to v8.1.1 (#6919) (f89b707)
    • deps: update netlify packages (#6922) (96f64ef)
    • deps: update rust crate lambda_runtime to 0.13.0 (#6920) (f48841c)
    • make outputs more user-friendly for sites:create-template (#6915) (d132ddd)
    • prevent redundant repos, add preliminary name checks, and improve error handling in sites:create-template (#6908) (a1000b3)
  • 17.37.2 - 2024-10-29

    17.37.2 (2024-10-29)

    Bug Fixes

    • add zsh autocomplete setup and file permissions instructions to completion:install (#6882) (75c0e7b)
    • deps: update dependency @ netlify/build to v29.55.4 (#6892) (da3563b)
    • deps: update dependency @ netlify/build to v29.56.0 (#6906) (e63a9c2)
    • deps: update dependency @ types/node to v20.17.1 (#6903) (93a728b)
    • deps: update dependency ws to v8.18.0 (#6904) (89e814d)
    • deps: update netlify packages (#6891) (8db8a3a)
    • deps: update netlify packages (#6899) (62d3123)
    • improve console message when unlinking from directory without a netlify.toml (#6897) (622098e)
    • link --name prefers exact match if exists, first match otherwise (#6865) (6a15c79)
    • logs: deploy command instructs user to link to a site if one is … (#6867) (98763f7)
    • updated error message for attempting to deploy a site with a bad… (#6884) (9cb44c5)
  • 17.37.1 - 2024-10-18

    17.37.1 (2024-10-17)

    Bug Fixes

    • deploy: fix edge function logs url scope key (#6881) (f833f2d)
    • deps: update dependency @ netlify/blobs to v8.1.0 (#6870) (b82c536)
    • deps: update dependency @ types/node to v20.16.11 (#6874) (e41ac33)
    • deps: update dependency cookie to v0.7.2 (#6875) (69a7a3b)
    • deps: update dependency express to v4.21.1 (#6858) (9d37ec0)
  • 17.37.0 - 2024-10-11

    17.37.0 (2024-10-11)

    Features

    Bug Fixes

    • deps: update dependency cookie to v0.7.0 [security] (#6856) (01810d5)
    • deps: update dependency envinfo to v7.14.0 (#6860) (7805687)
    • deps: update dependency http-proxy-middleware to v2.0.7 (#6852) (e1e7c72)
    • deps: update dependency listr2 to v8.2.5 (#6853) (b59f28b)
    • deps: update dependency log-update to v6.1.0 (#6861) (33f449f)
    • deps: update dependency ora to v8.1.0 (#6862) (d459d4e)
    • deps: update dependency pump to v3.0.2 (#6859) (f3f6d0a)
    • deps: update dependency update-notifier to v7.3.1 (#6863) (db8c10a)
    • deps: update netlify packages (#6868) (0944c42)
    • deps: update netlify packages (#6869) (48e032f)
  • 17.37.0-rc-redirects.0 - 2024-10-02

    17.37.0-rc-redirects.0

  • 17.37.0-rc-redirect.0 - 2024-10-02

    17.37.0-rc-redirect.0

  • 17.37.0-rc.1 - 2024-09-30

    17.37.0-rc.1

  • 17.37.0-rc.0 - 2024-09-30

    17.37.0-rc.0

  • 17.36.4 - 2024-10-01

    17.36.4 (2024-10-01)

    Bug Fixes

  • 17.36.3 - 2024-09-30

    17.36.3 (2024-09-30)

    Bug Fixes

  • 17.36.2 - 2024-09-20
  • 17.36.1 - 2024-09-19
  • 17.36.0 - 2024-09-10
  • 17.35.0 - 2024-09-06
  • 17.34.4 - 2024-09-06
  • 17.34.3 - 2024-08-26
  • 17.34.2 - 2024-08-19
  • 17.34.1 - 2024-08-13
  • 17.34.0 - 2024-08-08
  • 17.33.6 - 2024-08-06
  • 17.33.5 - 2024-07-30
  • 17.33.4 - 2024-07-15
  • 17.33.3 - 2024-07-12
  • 17.33.2 - 2024-07-11
  • 17.33.1 - 2024-07-11
  • 17.33.0 - 2024-07-05
  • 17.32.1 - 2024-07-04
  • 17.32.0 - 2024-07-02
  • 17.31.0 - 2024-07-01
  • 17.30.0 - 2024-06-26
  • 17.29.0 - 2024-06-20
  • 17.28.0 - 2024-06-17
  • 17.27.0 - 2024-06-13
  • 17.26.3 - 2024-06-12
  • 17.26.2 - 2024-06-10
  • 17.26.1 - 2024-06-07
  • 17.26.0 - 2024-06-05
  • 17.25.0 - 2024-05-29
  • 17.24.0 - 2024-05-29
  • 17.23.8 - 2024-05-24
  • 17.23.7 - 2024-05-24
  • 17.23.6 - 2024-05-23
  • 17.23.5 - 2024-05-14
  • 17.23.4 - 2024-05-14
  • 17.23.3 - 2024-05-13
  • 17.23.2 - 2024-05-07
  • 17.23.1 - 2024-04-26
  • 17.23.0 - 2024-04-25
  • 17.22.1 - 2024-04-10
  • 17.22.0 - 2024-04-08
  • 17.21.2 - 2024-04-05
  • 17.21.1 - 2024-03-26
  • 17.21.0 - 2024-03-26
  • 17.20.1 - 2024-03-22
  • 17.20.0 - 2024-03-21
  • 17.19.6 - 2024-03-20
  • 17.19.5 - 2024-03-18
  • 17.19.4 - 2024-03-15
  • 17.19.3 - 2024-03-13
  • 17.19.2 - 2024-03-11
  • 17.19.1 - 2024-03-11
  • 17.19.0 - 2024-03-08
  • 17.18.1 - 2024-03-06
  • 17.18.0 - 2024-03-05
  • 17.17.2 - 2024-03-04
  • 17.17.1 - 2024-02-26
  • 17.17.0 - 2024-02-22
  • 17.16.4 - 2024-02-20
  • 17.16.3 - 2024-02-19
  • 17.16.2 - 2024-02-13
  • 17.16.1 - 2024-02-08
  • 17.16.0 - 2024-02-05
  • 17.15.7 - 2024-02-01
  • 17.15.6 - 2024-01-31
  • 17.15.5 - 2024-01-30
  • 17.15.4 - 2024-01-29
  • 17.15.3 - 2024-01-24
  • 17.15.2 - 2024-01-22
  • 17.15.1 - 2024-01-19
  • 17.15.0 - 2024-01-18
  • 17.14.1 - 2024-01-18
  • 17.14.0 - 2024-01-15
  • 17.13.2 - 2024-01-12
  • 17.13.1 - 2024-01-11
  • 17.13.0 - 2024-01-09
  • 17.12.0 - 2024-01-09
  • 17.11.1 - 2024-01-05
  • 17.11.0 - 2024-01-02
  • 17.10.2 - 2023-12-29
  • 17.10.1 - 2023-12-08
  • 17.10.0 - 2023-12-06
  • 17.9.0 - 2023-12-04
  • 17.8.1 - 2023-11-28
  • 17.8.0 - 2023-11-28
  • 17.7.0 - 2023-11-23
  • 17.6.0 - 2023-11-21
  • 17.5.3 - 2023-11-20
  • 17.5.2 - 2023-11-20
  • 17.5.1 - 2023-11-17
  • 17.5.0 - 2023-11-17
  • 17.4.0 - 2023-11-16
  • 17.3.2 - 2023-11-15
  • 17.3.1 - 2023-11-14
  • 17.3.0 - 2023-11-14
  • 17.2.2 - 2023-11-10
  • 17.2.1 - 2023-11-09
  • 17.2.0 - 2023-11-08
  • 17.1.0 - 2023-11-07
  • 17.0.1 - 2023-11-02
  • 17.0.0 - 2023-11-01
  • 16.9.3 - 2023-10-27
  • 16.9.2 - 2023-10-24
  • 16.9.1 - 2023-10-20
  • 16.9.0 - 2023-10-19
  • 16.8.1 - 2023-10-19
  • 16.8.0 - 2023-10-17
  • 16.7.0 - 2023-10-12
  • 16.6.2 - 2023-10-12
  • 16.6.1 - 2023-10-10
  • 16.6.0 - 2023-10-10
  • 16.5.1 - 2023-10-03
  • 16.5.0 - 2023-10-02
  • 16.4.2 - 2023-09-21
  • 16.4.1 - 2023-09-20
  • 16.4.0 - 2023-09-19
  • 16.3.6 - 2023-09-18
  • 16.3.5 - 2023-09-18
  • 16.3.4 - 2023-09-18
  • 16.3.3 - 2023-09-15
  • 16.3.2 - 2023-09-13
  • 16.3.1 - 2023-09-06
  • 16.3.0 - 2023-09-06
  • 16.2.0 - 2023-08-29
  • 16.1.0 - 2023-08-17
  • 16.0.3 - 2023-08-14
  • 16.0.2 - 2023-08-11
  • 16.0.1 - 2023-08-10
  • 16.0.0 - 2023-08-10
  • 16.0.0-alpha.0 - 2023-08-10
  • 15.11.0 - 2023-08-07
  • 15.10.0 - 2023-07-31
  • 15.10.0-rc.1 - 2023-08-03
  • 15.10.0-rc.0 - 2023-08-03
  • 15.9.1 - 2023-07-19
  • 15.9.1-rc.0 - 2023-07-20
  • 15.9.0 - 2023-07-12
  • 15.8.1 - 2023-07-06
  • 15.8.1-rc.1 - 2023-07-11
  • 15.8.1-rc.0 - 2023-07-10
  • 15.8.0 - 2023-06-30
  • 15.7.0 - 2023-06-27
  • 15.6.0 - 2023-06-14
  • 15.5.1 - 2023-06-13
  • 15.5.0 - 2023-06-13
  • 15.4.2 - 2023-06-12
  • 15.4.1 - 2023-06-08
  • 15.4.0 - 2023-06-07
  • 15.3.2 - 2023-06-07
  • 15.3.1 - 2023-06-02
  • 15.3.0 - 2023-06-02
  • 15.2.0 - 2023-05-26
  • 15.1.1 - 2023-05-17
  • 15.1.0 - 2023-05-15
  • 15.0.3 - 2023-05-15
  • 15.0.2 - 2023-05-08
  • 15.0.1 - 2023-05-08
  • 15.0.0 - 2023-05-05
  • 15.0.0-rc.0 - 2023-05-02
  • 14.4.0 - 2023-05-03
  • 14.3.1 - 2023-04-26
  • 14.3.0 - 2023-04-25
  • 14.2.1 - 2023-04-20
  • 14.2.0 - 2023-04-20
  • 14.1.0 - 2023-04-19
  • 14.0.0 - 2023-04-17
  • 14.0.0-rc - 2023-04-14
  • 13.2.2 - 2023-03-28
  • 13.2.1 - 2023-03-22
  • 13.2.0 - 2023-03-21
  • 13.1.7 - 2023-03-21
  • 13.1.6 - 2023-03-14
  • 13.1.5 - 2023-03-14
  • 13.1.4 - 2023-03-14
  • 13.1.3 - 2023-03-13
  • 13.1.2 - 2023-03-10
  • 13.1.1 - 2023-03-09
  • 13.1.0 - 2023-03-09
  • 13.0.1 - 2023-03-03
  • 13.0.0 - 2023-02-21
  • 12.14.0 - 2023-02-20
  • 12.13.2 - 2023-02-20
  • 12.13.1 - 2023-02-17
  • 12.13.0 - 2023-02-17
  • 12.12.1 - 2023-02-16
  • 12.12.0 - 2023-02-10
  • 12.11.0 - 2023-02-09
  • 12.10.0 - 2023-01-26
  • 12.9.2 - 2023-01-24
  • 12.9.1 - 2023-01-20
  • 12.9.0 - 2023-01-20
  • 12.8.0 - 2023-01-20
  • 12.7.2 - 2023-01-11
  • 12.7.1 - 2023-01-11
  • 12.7.0 - 2023-01-10
  • 12.6.0 - 2023-01-09
  • 12.5.0 - 2022-12-22
  • 12.4.1 - 2022-12-20
  • 12.4.0 - 2022-12-15
  • 12.3.0 - 2022-12-15
  • 12.2.11 - 2022-12-14
  • 12.2.10 - 2022-12-12
  • 12.2.9 - 2022-12-06
  • 12.2.8 - 2022-12-01
  • 12.2.7 - 2022-11-23
  • 12.2.6 - 2022-11-21
  • 12.2.5 - 2022-11-21
  • 12.2.4 - 2022-11-18
  • 12.2.3 - 2022-11-18
  • 12.2.2 - 2022-11-18
  • 12.2.1 - 2022-11-17
  • 12.2.0 - 2022-11-15
  • 12.1.1 - 2022-11-09
  • 12.1.0 - 2022-11-04
  • 12.0.11 - 2022-10-18
  • 12.0.10 - 2022-10-17
  • 12.0.9 - 2022-10-13
  • 12.0.8 - 2022-10-12
  • 12.0.7 - 2022-10-07
  • 12.0.6 - 2022-10-05
  • 12.0.5 - 2022-10-04
  • 12.0.4 - 2022-10-03
  • 12.0.3 - 2022-10-03
  • 12.0.2 - 2022-09-30
  • 12.0.1 - 2022-09-29
  • 12.0.0 - 2022-09-27
  • 11.8.3 - 2022-09-23
  • 11.8.2 - 2022-09-21
  • 11.8.1 - 2022-09-20
  • 11.8.0 - 2022-09-15
  • 11.7.1 - 2022-09-09
  • 11.7.0 - 2022-09-09
  • 11.6.0 - 2022-09-08
  • 11.5.1 - 2022-08-29
  • 11.5.0 - 2022-08-22
  • 11.4.0 - 2022-08-22
  • 11.3.0 - 2022-08-19
  • 11.2.0 - 2022-08-19
  • 11.1.0 - 2022-08-19
  • 11.1.0-rc.2 - 2022-08-19
  • 11.1.0-rc.1 - 2022-08-18
  • 11.1.0-rc.0 - 2022-08-18
  • 11.0.0 - 2022-08-18
  • 10.18.0 - 2022-08-18
  • 10.18.0-rc2 - 2022-08-17
  • 10.18.0-rc1 - 2022-08-16
  • 10.18.0-rc.4 - 2022-08-18
  • 10.18.0-rc.3 - 2022-08-17
  • 10.17.8 - 2022-08-16
  • 10.17.7 - 2022-08-16
  • 10.17.6 - 2022-08-15
  • 10.17.5 - 2022-08-15
  • 10.17.4 - 2022-08-12
  • 10.17.3 - 2022-08-12
  • 10.17.2 - 2022-08-12
  • 10.17.1 - 2022-08-12
  • 10.17.0 - 2022-08-11
  • 10.16.0 - 2022-08-11
  • 10.15.0 - 2022-08-04
  • 10.14.0 - 2022-08-01
  • 10.13.0 - 2022-07-29
  • 10.12.1 - 2022-07-27
  • 10.12.0 - 2022-07-27
  • 10.11.2 - 2022-07-25
  • 10.11.1 - 2022-07-22
  • 10.11.0 - 2022-07-22
  • 10.10.2 - 2022-07-19
  • 10.10.1 - 2022-07-19
  • 10.10.0 - 2022-07-15
  • 10.9.1 - 2022-07-15
  • 10.9.0 - 2022-07-13
  • 10.8.0 - 2022-07-11
  • 10.7.1 - 2022-07-01
  • 10.7.0 - 2022-06-30
  • 10.6.3 - 2022-06-27
  • 10.6.2 - 2022-06-23
  • 10.6.1 - 2022-06-22
  • 10.6.0 - 2022-06-22
  • 10.5.1 - 2022-06-10
  • 10.5.0 - 2022-06-08
  • 10.4.0 - 2022-05-31
  • 10.3.3 - 2022-05-26
  • 10.3.1 - 2022-05-12
  • 10.3.0 - 2022-05-06
  • 10.2.0 - 2022-05-04
  • 10.1.0 - 2022-04-27
  • 10.0.0 - 2022-04-19
  • 10.0.0-rc.0 - 2022-04-18
  • 9.16.7 - 2022-04-18
  • 9.16.6 - 2022-04-11
  • 9.16.5 - 2022-04-11
  • 9.16.4 - 2022-04-08
  • 9.16.3 - 2022-04-04
  • 9.16.2 - 2022-04-04
from netlify-cli GitHub release notes

Important

  • Warning: This PR contains a major version upgrade, and may be a breaking change.
  • Check the changes in this PR to ensure they won't cause issues with your project.
  • This PR was automatically created by Snyk using the credentials of a real user.
  • Max score is 1000. Note that the real score may have changed since the PR was raised.

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

Snyk has created this PR to upgrade netlify-cli from 9.16.2 to 17.38.0.

See this package in npm:
netlify-cli

See this project in Snyk:
https://app.snyk.io/org/hashim21223445/project/894c8aac-2f32-4da3-a6a5-eb6c2fd5cdb2?utm_source=github-cloud-app&utm_medium=referral&page=upgrade-pr
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

0 participants