Skip to content
This repository has been archived by the owner on Dec 1, 2023. It is now read-only.

[Snyk] Security upgrade peerflix from 0.32.4 to 0.36.0 #13

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

snyk-bot
Copy link

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

merge advice

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • package.json

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
high severity 758/1000
Why? Proof of Concept exploit, Recently disclosed, Has a fix available, CVSS 7.3
Prototype Pollution
SNYK-JS-INI-1048974
No Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: peerflix The new version differs by 22 commits.
  • f65c089 0.36.0
  • 869653b make executeable
  • 8a47d56 Update packages (#291)
  • f23ab8a Added travis ci support for modern node 4 versions (#289)
  • fbda734 Downloaded percentage (#286)
  • 4b293b4 Merge pull request #285 from amilajack/patch-1
  • 2cb5756 Added travis ci support for modern node versions
  • 912a371 0.35.1
  • 595e778 Merge pull request #284 from asaf400/master
  • 22b477e Fix: VLC Playback Blank Entry
  • a276acf 0.35.0
  • 80b88f8 Merge pull request #277 from watson/airplayer
  • 43bf1f9 Use airplayer
  • f930503 0.34.0
  • cac9db9 Merge pull request #273 from hkraji/master
  • 3e99d1b Removed extra space
  • 84348e7 Merge remote-tracking branch 'upstream/master'
  • 942a5a7 Add support for windows, ubuntu, unix
  • 5e99898 0.33.0
  • cfeb0bd Merge pull request #267 from zaiddabaeen/master
  • 9d62369 Fix for Windows where subtitles path should not be encoded for VLC
  • 152d910 Update app.js

See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic

The following vulnerabilities are fixed with an upgrade:
- https://snyk.io/vuln/SNYK-JS-INI-1048974
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant