Skip to content

[Snyk] Upgrade jsdom from 15.2.0 to 15.2.1#10

Open
snyk-bot wants to merge 1 commit into
masterfrom
snyk-upgrade-e3f66280caa0af61a409cc6a7979e6a3
Open

[Snyk] Upgrade jsdom from 15.2.0 to 15.2.1#10
snyk-bot wants to merge 1 commit into
masterfrom
snyk-upgrade-e3f66280caa0af61a409cc6a7979e6a3

Conversation

@snyk-bot

Copy link
Copy Markdown

Snyk has created this PR to upgrade jsdom from 15.2.0 to 15.2.1.

ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


  • The recommended version is 1 version ahead of your current version.
  • The recommended version was released 3 years ago, on 2019-11-04.

The recommended version fixes:

Severity Issue PriorityScore (*) Exploit Maturity
Prototype Pollution
SNYK-JS-QS-3153490
554/1000
Why? Proof of Concept exploit, Recently disclosed, CVSS 7.5
Proof of Concept
Prototype Pollution
SNYK-JS-JSONSCHEMA-1920922
554/1000
Why? Proof of Concept exploit, Recently disclosed, CVSS 7.5
No Known Exploit
Prototype Pollution
SNYK-JS-AJV-584908
554/1000
Why? Proof of Concept exploit, Recently disclosed, CVSS 7.5
No Known Exploit
Regular Expression Denial of Service (ReDoS)
SNYK-JS-WS-1296835
554/1000
Why? Proof of Concept exploit, Recently disclosed, CVSS 7.5
Proof of Concept
Denial of Service (DoS)
SNYK-JS-NWSAPI-2841516
554/1000
Why? Proof of Concept exploit, Recently disclosed, CVSS 7.5
No Known Exploit

(*) Note that the real score may have changed since the PR was raised.

Release notes
Package name: jsdom
  • 15.2.1 - 2019-11-04
  • 15.2.0 - 2019-10-14
from jsdom GitHub release notes
Commit messages
Package name: jsdom
  • c3f0f27 Version 15.2.1
  • dcbbb5e Update ESLint dependency
  • 4ed6b9f Fix JSDOM.fromURL() hash handling
  • ca2ca05 Bump nwsapi minimum version and add namespace selector test
  • d8bede1 Fix focusing a focused element to be a no-op
  • 960cb52 Fix typo in not-implemented message for addTextTrack()

Compare


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

🧐 View latest project report

🛠 Adjust upgrade PR settings

🔕 Ignore this dependency or unsubscribe from future upgrade PRs

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant