Skip to content

[Snyk] Security upgrade @salesforce/core from 3.36.2 to 4.0.1#43

Open
dcarroll wants to merge 1 commit intomasterfrom
snyk-fix-f6fe281c7d053857df52124e513a56e5
Open

[Snyk] Security upgrade @salesforce/core from 3.36.2 to 4.0.1#43
dcarroll wants to merge 1 commit intomasterfrom
snyk-fix-f6fe281c7d053857df52124e513a56e5

Conversation

@dcarroll
Copy link
Owner

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • package.json

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
medium severity 631/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 6.2
Missing Release of Resource after Effective Lifetime
SNYK-JS-INFLIGHT-6095116
Yes Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: @salesforce/core The new version differs by 20 commits.
  • 0b8ba43 chore(release): 4.0.1 [skip ci]
  • a8b6921 Merge pull request #830 from forcedotcom/sm/node16
  • 800ef5a Merge pull request #828 from forcedotcom/dependabot-npm_and_yarn-types-jsonwebtoken-9.0.2
  • cff9e57 Merge pull request #838 from forcedotcom/dependabot-npm_and_yarn-eslint-8.41.0
  • 6ef4a35 chore(dev-deps): bump eslint from 8.38.0 to 8.41.0
  • 4dc1a2e Merge pull request #843 from forcedotcom/dependabot-npm_and_yarn-typescript-eslint-parser-5.59.7
  • 55490c3 chore(dev-deps): bump @ typescript-eslint/parser from 5.57.1 to 5.59.7
  • a2e7d3c chore(dev-deps): bump @ types/jsonwebtoken from 9.0.1 to 9.0.2
  • 567d2d0 Merge pull request #844 from forcedotcom/dependabot-npm_and_yarn-typescript-eslint-eslint-plugin-5.59.7
  • ff21d46 chore(dev-deps): bump @ typescript-eslint/eslint-plugin
  • a212cc7 Merge remote-tracking branch 'origin/main' into sm/node16
  • ccc1ed1 chore: remove deprecated testSetup
  • a63b48a chore: bump jsforce
  • 61e18c3 Merge remote-tracking branch 'origin/main' into sm/node16
  • 8e8eefc chore: major version bump
  • abdcaf5 docs: expain v4 deprecations
  • 079cdc5 test: handle additional envs (test environment has telemetry disabled via env)
  • a1d4d5c chore: restore schema printer for plugin-data
  • 977b028 feat!: remove most deprecated items
  • dedd5ed chore: node16 deps and engines prop

See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic


Note: This is a default PR template raised by Snyk. Find out more about how you can customise Snyk PRs in our documentation.

Learn how to fix vulnerabilities with free interactive lessons:

🦉 Learn about vulnerability in an interactive lesson of Snyk Learn.

The following vulnerabilities are fixed with an upgrade:
- https://snyk.io/vuln/SNYK-JS-INFLIGHT-6095116
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants