[Snyk] Fix for 1 vulnerabilities - #30
Conversation
The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-JS-BRACEEXPANSION-18512280
|
This upgrade contains a major version update for eslint from v8 to v9, which is a high-risk change with significant breaking changes. The update for @vscode/vsce is a major version jump with unclear changes, representing a medium risk. eslint@8.57.1 → eslint@9.0.0 (High Risk)The upgrade to ESLint v9.0.0 introduces substantial breaking changes that require mandatory configuration and environment updates. [1, 3] Key Breaking Changes:
Recommendation: @vscode/vsce@2.32.0 → @vscode/vsce@3.9.2 (Medium Risk)This is a major version upgrade for the Visual Studio Code extension publishing tool. A specific changelog detailing the breaking changes between v2 and v3 was not found. Due to the lack of clear documentation for this major version jump, the risk is assessed as medium. Changes to command-line arguments, configuration, or required Node.js versions are possible and require verification. Recommendation:
|
⛔ Snyk checks have failed. 48 issues have been found so far.
💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse. |
Snyk has created this PR to fix 1 vulnerabilities in the pnpm dependencies of this project.
Snyk changed the following file(s):
package.jsonpnpm-lock.yamlVulnerabilities that will be fixed with an upgrade:
SNYK-JS-BRACEEXPANSION-18512280
Breaking Change Risk
Important
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.
For more information:
🧐 View latest project report
📜 Customise PR templates
🛠 Adjust project settings
📚 Read about Snyk's upgrade logic
Learn how to fix vulnerabilities with free interactive lessons:
🦉 Allocation of Resources Without Limits or Throttling