Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This PR was automatically created by Snyk using the credentials of a real user.
Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.
Changes included in this PR
Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
Adding or updating a Snyk policy (.snyk) file; this file is required in order to apply Snyk vulnerability patches.
Find out more.
Vulnerabilities that will be fixed
With an upgrade:
Why? Has a fix available, CVSS 8.8
SNYK-JS-ELECTRON-1312313
Why? Mature exploit, Has a fix available, CVSS 8.8
SNYK-JS-ELECTRON-1312314
Why? Has a fix available, CVSS 8.8
SNYK-JS-ELECTRON-1312315
Why? Mature exploit, Has a fix available, CVSS 8.8
SNYK-JS-ELECTRON-1313765
Why? Has a fix available, CVSS 6.3
SNYK-JS-ELECTRON-1313767
Why? Has a fix available, CVSS 8.8
SNYK-JS-ELECTRON-1314896
Why? Has a fix available, CVSS 8.8
SNYK-JS-ELECTRON-1315151
Why? Has a fix available, CVSS 9.8
SNYK-JS-ELECTRON-1315668
Why? Has a fix available, CVSS 8.8
SNYK-JS-ELECTRON-1533614
Why? Has a fix available, CVSS 8.8
SNYK-JS-ELECTRON-1534881
Why? Has a fix available, CVSS 8.8
SNYK-JS-ELECTRON-1534882
Why? Mature exploit, Has a fix available, CVSS 8.8
SNYK-JS-ELECTRON-1534883
Why? Has a fix available, CVSS 6.5
SNYK-JS-ELECTRON-1534884
Why? Has a fix available, CVSS 6.3
SNYK-JS-ELECTRON-1536579
Why? Proof of Concept exploit, Has a fix available, CVSS 8.8
SNYK-JS-ELECTRON-1536581
Why? Has a fix available, CVSS 8.8
SNYK-JS-ELECTRON-1536587
Why? Mature exploit, Has a fix available, CVSS 5.3
SNYK-JS-ELECTRON-1585619
Why? Has a fix available, CVSS 8.8
SNYK-JS-ELECTRON-1586050
Why? Has a fix available, CVSS 7.3
SNYK-JS-ELECTRON-1656742
Why? Mature exploit, Has a fix available, CVSS 8.8
SNYK-JS-ELECTRON-1656743
Why? Has a fix available, CVSS 6.5
SNYK-JS-ELECTRON-2932172
Why? Has a fix available, CVSS 5.9
SNYK-JS-ELECTRON-2934721
Why? Mature exploit, Has a fix available, CVSS 8.6
SNYK-JS-ELECTRON-2946881
Why? Has a fix available, CVSS 8.8
SNYK-JS-ELECTRON-2946891
Why? Has a fix available, CVSS 7.5
SNYK-JS-ELECTRON-2961655
Why? Has a fix available, CVSS 5.3
SNYK-JS-ELECTRON-2977510
Why? Has a fix available, CVSS 5.3
SNYK-JS-ELECTRON-2977512
Why? Has a fix available, CVSS 5.6
SNYK-JS-ELECTRON-2978483
Why? Has a fix available, CVSS 5.9
SNYK-JS-ELECTRON-2978519
Why? Has a fix available, CVSS 8.8
SNYK-JS-ELECTRON-2992453
Why? Has a fix available, CVSS 8.8
SNYK-JS-ELECTRON-2992478
Why? Has a fix available, CVSS 4.3
SNYK-JS-ELECTRON-2992482
Why? Has a fix available, CVSS 8.8
SNYK-JS-ELECTRON-2994414
Why? Has a fix available, CVSS 7.5
SNYK-JS-ELECTRON-3014402
Why? Has a fix available, CVSS 8.8
SNYK-JS-ELECTRON-3014405
Why? Has a fix available, CVSS 8.8
SNYK-JS-ELECTRON-3014407
Why? Has a fix available, CVSS 8.8
SNYK-JS-ELECTRON-3014409
Why? Has a fix available, CVSS 8.8
SNYK-JS-ELECTRON-3014411
Why? Has a fix available, CVSS 8.8
SNYK-JS-ELECTRON-3028028
Why? Mature exploit, Has a fix available, CVSS 8.8
SNYK-JS-ELECTRON-3091122
Why? Has a fix available, CVSS 6.3
SNYK-JS-ELECTRON-3097694
Why? Has a fix available, CVSS 8.8
SNYK-JS-ELECTRON-3097832
Why? Has a fix available, CVSS 5.8
SNYK-JS-ELECTRON-3107036
Why? Has a fix available, CVSS 7.6
SNYK-JS-ELECTRON-3111876
Why? Has a fix available, CVSS 7.3
SNYK-JS-ELECTRON-3111878
Why? Has a fix available, CVSS 7.5
SNYK-JS-ELECTRON-3111879
Why? Has a fix available, CVSS 8.8
SNYK-JS-ELECTRON-3111880
Why? Has a fix available, CVSS 8.8
SNYK-JS-ELECTRON-3111881
Why? Has a fix available, CVSS 8.8
SNYK-JS-ELECTRON-3160317
Why? Has a fix available, CVSS 7.3
SNYK-JS-ELECTRON-3237489
Why? Proof of Concept exploit, Has a fix available, CVSS 5.3
SNYK-JS-FOLLOWREDIRECTS-2332181
Why? Has a fix available, CVSS 2.6
SNYK-JS-FOLLOWREDIRECTS-2396346
Why? Proof of Concept exploit, Has a fix available, CVSS 5.3
SNYK-JS-GLOBPARENT-1016905
Why? Has a fix available, CVSS 5.4
SNYK-JS-GOT-2932019
Why? Has a fix available, CVSS 5
SNYK-JS-HEXO-1932976
Why? Has a fix available, CVSS 5.3
SNYK-JS-HIGHLIGHTJS-1048676
Why? Has a fix available, CVSS 7.3
SNYK-JS-JSTOXML-1017039
Why? Has a fix available, CVSS 4
SNYK-JS-MACADDRESS-567156
Why? Has a fix available, CVSS 7.5
SNYK-JS-MOMENT-2440688
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
SNYK-JS-MOMENT-2944238
Why? Proof of Concept exploit, Has a fix available, CVSS 8.1
SNYK-JS-SIMPLEGIT-2421199
Why? Proof of Concept exploit, Has a fix available, CVSS 8.1
SNYK-JS-SIMPLEGIT-2434306
Why? Proof of Concept exploit, Has a fix available, CVSS 8.1
SNYK-JS-SIMPLEGIT-3112221
Why? Proof of Concept exploit, Has a fix available, CVSS 8.1
SNYK-JS-SIMPLEGIT-3177391
Why? Has a fix available, CVSS 3.7
SNYK-JS-STRIPTAGS-1312310
Why? Proof of Concept exploit, Has a fix available, CVSS 6.8
SNYK-JS-VDITOR-2359056
Why? Proof of Concept exploit, Has a fix available, CVSS 6.6
SNYK-JS-VDITOR-2422324
Why? Has a fix available, CVSS 6.1
SNYK-JS-VDITOR-2438403
Why? Proof of Concept exploit, Has a fix available, CVSS 6.1
SNYK-JS-VDITOR-3329409
Why? Proof of Concept exploit, Has a fix available, CVSS 3.7
npm:braces:20180219
(*) Note that the real score may have changed since the PR was raised.
Commit messages
Package name: ali-oss
The new version differs by 242 commits.See the full diff
Package name: axios
The new version differs by 58 commits.See the full diff
Package name: electron-google-analytics
The new version differs by 7 commits.See the full diff
Package name: hexo
The new version differs by 250 commits.See the full diff
Package name: macaddress
The new version differs by 26 commits.See the full diff
Package name: simple-git
The new version differs by 250 commits.See the full diff
Package name: vditor
The new version differs by 250 commits.See the full diff
With a Snyk patch:
Why? Proof of Concept exploit, Has a fix available, CVSS 8.2
SNYK-JS-LODASH-567746
(*) Note that the real score may have changed since the PR was raised.
Check the changes in this PR to ensure they won't cause issues with your project.
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.
For more information:![](https://camo.githubusercontent.com/bc1b58370f1df3d308218d473a5674d1f4efe634810818b2e6fa25975252c501/68747470733a2f2f6170692e7365676d656e742e696f2f76312f706978656c2f747261636b3f646174613d65794a33636d6c305a55746c65534936496e4a79576d785a634564485932527954485a7362306c596430645563566734576b4652546e4e434f5545774969776959573576626e6c746233567a535751694f6949304f544d324f54517a4f53316a4e3245304c54517a596a517459545a6d5a5330334d574934597a517a4f5464684d5451694c434a6c646d567564434936496c425349485a705a58646c5a434973496e42796233426c636e52705a584d694f6e736963484a4a5a434936496a51354d7a59354e444d354c574d33595451744e444e694e4331684e6d5a6c4c546378596a686a4e444d354e3245784e434a3966513d3d)
🧐 View latest project report
🛠 Adjust project settings
📚 Read more about Snyk's upgrade and patch logic
Learn how to fix vulnerabilities with free interactive lessons:
🦉 Denial of Service (DoS)
🦉 Access Control Bypass
🦉 Open Redirect
🦉 More lessons are available in Snyk Learn