Skip to content

[Snyk] Upgrade phantomjs-prebuilt from 2.1.7 to 2.1.16#1

Open
snyk-bot wants to merge 1 commit intomasterfrom
snyk-upgrade-e7d306c2c8b3664bfeddfc9f2b9b2d01
Open

[Snyk] Upgrade phantomjs-prebuilt from 2.1.7 to 2.1.16#1
snyk-bot wants to merge 1 commit intomasterfrom
snyk-upgrade-e7d306c2c8b3664bfeddfc9f2b9b2d01

Conversation

@snyk-bot
Copy link
Copy Markdown

Snyk has created this PR to upgrade phantomjs-prebuilt from 2.1.7 to 2.1.16.

merge advice
ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


  • The recommended version is 12 versions ahead of your current version.
  • The recommended version was released 4 years ago, on 2017-11-02.

The recommended version fixes:

Severity Issue PriorityScore (*) Exploit Maturity
Regular Expression Denial of Service (ReDoS)
npm:tough-cookie:20160722
589/1000
Why? Has a fix available, CVSS 7.5
No Known Exploit
Prototype Override Protection Bypass
npm:qs:20170213
589/1000
Why? Has a fix available, CVSS 7.5
No Known Exploit
Remote Memory Exposure
SNYK-JS-BL-608877
589/1000
Why? Has a fix available, CVSS 7.5
Proof of Concept
Uninitialized Memory Exposure
npm:tunnel-agent:20170305
589/1000
Why? Has a fix available, CVSS 7.5
Proof of Concept
Regular Expression Denial of Service (ReDoS)
npm:tough-cookie:20170905
589/1000
Why? Has a fix available, CVSS 7.5
No Known Exploit
Remote Memory Exposure
npm:request:20160119
589/1000
Why? Has a fix available, CVSS 7.5
No Known Exploit
Prototype Pollution
npm:hoek:20180212
589/1000
Why? Has a fix available, CVSS 7.5
Proof of Concept
Uninitialized Memory Exposure
npm:concat-stream:20160901
589/1000
Why? Has a fix available, CVSS 7.5
Mature
Prototype Pollution
SNYK-JS-MINIMIST-559764
589/1000
Why? Has a fix available, CVSS 7.5
Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Release notes
Package name: phantomjs-prebuilt
  • 2.1.16 - 2017-11-02
  • 2.1.15 - 2017-08-14
  • 2.1.14 - 2016-12-09

    Upgrades request and fs-extra deps

  • 2.1.13 - 2016-10-04
    • upgrade promise polyfill
  • 2.1.12 - 2016-08-12
    • Removes bundledDependencies from NPM publishing. This option appears to be non-portable, and breaks various OS/NPM version combinations.
  • 2.1.12-alpha - 2016-08-11
  • 2.1.11 - 2016-08-08
  • 2.1.11-alpha.1 - 2016-08-08
  • 2.1.11-alpha - 2016-08-08
  • 2.1.10 - 2016-08-03
    • published with NPM3, to improve path nesting (#589)
    • preserves paths better on install (#583)
    • Adds run/exec methods (#588)
  • 2.1.9 - 2016-07-29

    bundles the dependencies, for more robust npm installs

  • 2.1.8 - 2016-07-26
    • minor package updates
    • fixes for tmp handling
  • 2.1.7 - 2016-03-25
    • Change the default download location to github releases, per discussion on #509 and ariya/phantomjs#13953
    • If there's a global npm phantomjs-prebuilt install on linux/osx, try to use that for local installs (windows is harder for complicated windows reasons)
from phantomjs-prebuilt GitHub release notes
Commit messages
Package name: phantomjs-prebuilt
  • 0cc1407 Merge pull request #746 from avindra/patch-1
  • 2c46265 Dependencies: change tilde to caret
  • a98231b Merge pull request #733 from avindra/patch-1
  • 19c6d4c Bump package.json version
  • 65b57f7 Merge pull request #732 from Ilshidur/patch-1
  • cc52482 Dependencies update : fix security issues
  • 750d5f3 Merge pull request #653 from Medium/nicks/bump
  • 379d3ae Upgrade some deps
  • df5e2ea Merge pull request #652 from nanaya/master
  • 1d2898e Don't download osx binary on freebsd/openbsd
  • e0d2e61 Merge pull request #627 from Medium/nicks/bump
  • d652351 Update version
  • ac0da0b Merge pull request #625 from marcbachmann/patch-1
  • 1cf3ef3 Upgrade to es6-promise@4.0.3
  • 3d44598 Merge pull request #624 from jdalton/readme
  • d8ebc23 Add readme note for CI caching. [ci skip]
  • ae83e7a tweak readme text
  • b612260 Add a section to the FAQ on unsupported OSes/processors
  • 2dead42 Merge pull request #603 from Medium/nicks/bundling
  • 076b959 remove bundledDependencies.
  • b9555f1 Merge pull request #601 from carsonip/master
  • fca4006 Add bzip2 to troubleshooting
  • fdb40fe bump version
  • df332c6 Merge pull request #593 from Medium/nicks/error

Compare


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

🧐 View latest project report

🛠 Adjust upgrade PR settings

🔕 Ignore this dependency or unsubscribe from future upgrade PRs

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant