-
Notifications
You must be signed in to change notification settings - Fork 18
Commit 9bf32c4
[Snyk] Upgrade ansi-regex from 6.0.1 to 6.1.0 (#2482)

<h3>Snyk has created this PR to upgrade ansi-regex from 6.0.1 to
6.1.0.</h3>
:information_source: Keep your dependencies up-to-date. This makes it
easier to fix existing vulnerabilities and to more quickly identify and
fix newly disclosed vulnerabilities when they affect your project.
<hr/>
- The recommended version is **1 version** ahead of your current
version.
- The recommended version was released **6 months ago**.
<details>
<summary><b>Release notes</b></summary>
<br/>
<details>
<summary>Package name: <b>ansi-regex</b></summary>
<ul>
<li>
<b>6.1.0</b> - <a
href="https://redirect.github.com/chalk/ansi-regex/releases/tag/v6.1.0">2024-09-09</a></br><ul>
<li>Match cursorSave and cursorRestore escape codes (<a
class="issue-link js-issue-link" data-error-text="Failed to load title"
data-id="1037673499" data-permission-text="Title is private"
data-url="chalk/ansi-regex#45"
data-hovercard-type="pull_request"
data-hovercard-url="/chalk/ansi-regex/pull/45/hovercard"
href="https://redirect.github.com/chalk/ansi-regex/pull/45">#45</a>) <a
class="commit-link" data-hovercard-type="commit"
data-hovercard-url="https://github.com/chalk/ansi-regex/commit/02fa893d619d3da85411acc8fd4e2eea0e95a9d9/hovercard"
href="https://redirect.github.com/chalk/ansi-regex/commit/02fa893d619d3da85411acc8fd4e2eea0e95a9d9"><tt>02fa893</tt></a></li>
<li>Fix: Handle all valid ST characters (<a class="issue-link
js-issue-link" data-error-text="Failed to load title"
data-id="2505760732" data-permission-text="Title is private"
data-url="chalk/ansi-regex#58"
data-hovercard-type="pull_request"
data-hovercard-url="/chalk/ansi-regex/pull/58/hovercard"
href="https://redirect.github.com/chalk/ansi-regex/pull/58">#58</a>) <a
class="commit-link" data-hovercard-type="commit"
data-hovercard-url="https://github.com/chalk/ansi-regex/commit/9cba40dc3df00ee7316c01db4955d31ef7527012/hovercard"
href="https://redirect.github.com/chalk/ansi-regex/commit/9cba40dc3df00ee7316c01db4955d31ef7527012"><tt>9cba40d</tt></a></li>
</ul>
<p><a class="commit-link"
href="https://redirect.github.com/chalk/ansi-regex/compare/v6.0.1...v6.1.0"><tt>v6.0.1...v6.1.0</tt></a></p>
</li>
<li>
<b>6.0.1</b> - <a
href="https://redirect.github.com/chalk/ansi-regex/releases/tag/v6.0.1">2021-09-10</a></br><h3>Fixes</h3>
<ul>
<li>Fix <a href="https://en.wikipedia.org/wiki/ReDoS"
rel="nofollow">ReDoS</a> in certain cases (<a class="issue-link
js-issue-link" data-error-text="Failed to load title"
data-id="992144440" data-permission-text="Title is private"
data-url="chalk/ansi-regex#37"
data-hovercard-type="pull_request"
data-hovercard-url="/chalk/ansi-regex/pull/37/hovercard"
href="https://redirect.github.com/chalk/ansi-regex/pull/37">#37</a>)<br>
You are only really affected if you run the regex on untrusted user
input in a server context, which it's very unlikely anyone is doing,
since this regex is mainly used in command-line tools.</li>
</ul>
<p><a
href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3807"
rel="nofollow">CVE-2021-3807</a></p>
<p><a class="commit-link"
href="https://redirect.github.com/chalk/ansi-regex/compare/v6.0.0...v6.0.1"><tt>v6.0.0...v6.0.1</tt></a></p>
<p>Thank you <a class="user-mention notranslate"
data-hovercard-type="user"
data-hovercard-url="/users/yetingli/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/yetingli">@ yetingli</a> for the patch
and reproduction case!</p>
</li>
</ul>
from <a
href="https://redirect.github.com/chalk/ansi-regex/releases">ansi-regex
GitHub release notes</a>
</details>
</details>
---
> [!IMPORTANT]
>
> - Check the changes in this PR to ensure they won't cause issues with
your project.
> - This PR was automatically created by Snyk using the credentials of a
real user.
---
**Note:** _You are seeing this because you or someone else with access
to this repository has authorized Snyk to open upgrade PRs._
**For more information:** <img
src="https://api.segment.io/v1/pixel/track?data=eyJ3cml0ZUtleSI6InJyWmxZcEdHY2RyTHZsb0lYd0dUcVg4WkFRTnNCOUEwIiwiYW5vbnltb3VzSWQiOiI2Yzg2ZmFlNi1kN2I5LTQyNmMtYWU3Yi03MzRhZmRmODZmYjAiLCJldmVudCI6IlBSIHZpZXdlZCIsInByb3BlcnRpZXMiOnsicHJJZCI6IjZjODZmYWU2LWQ3YjktNDI2Yy1hZTdiLTczNGFmZGY4NmZiMCJ9fQ=="
width="0" height="0"/>
> - 🧐 [View latest project
report](https://app.snyk.io/org/oeda/project/1a7ace33-7e4c-495f-8b89-dccaf4d6617a?utm_source=github&utm_medium=referral&page=upgrade-pr)
> - 📜 [Customise PR
templates](https://docs.snyk.io/scan-using-snyk/pull-requests/snyk-fix-pull-or-merge-requests/customize-pr-templates?utm_source=&utm_content=fix-pr-template)
> - 🛠 [Adjust upgrade PR
settings](https://app.snyk.io/org/oeda/project/1a7ace33-7e4c-495f-8b89-dccaf4d6617a/settings/integration?utm_source=github&utm_medium=referral&page=upgrade-pr)
> - 🔕 [Ignore this dependency or unsubscribe from future upgrade
PRs](https://app.snyk.io/org/oeda/project/1a7ace33-7e4c-495f-8b89-dccaf4d6617a/settings/integration?pkg=ansi-regex&utm_source=github&utm_medium=referral&page=upgrade-pr#auto-dep-upgrades)
[//]: #
'snyk:metadata:{"customTemplate":{"variablesUsed":[],"fieldsUsed":[]},"dependencies":[{"name":"ansi-regex","from":"6.0.1","to":"6.1.0"}],"env":"prod","hasFixes":false,"isBreakingChange":false,"isMajorUpgrade":false,"issuesToFix":[],"prId":"6c86fae6-d7b9-426c-ae7b-734afdf86fb0","prPublicId":"6c86fae6-d7b9-426c-ae7b-734afdf86fb0","packageManager":"npm","priorityScoreList":[],"projectPublicId":"1a7ace33-7e4c-495f-8b89-dccaf4d6617a","projectUrl":"https://app.snyk.io/org/oeda/project/1a7ace33-7e4c-495f-8b89-dccaf4d6617a?utm_source=github&utm_medium=referral&page=upgrade-pr","prType":"upgrade","templateFieldSources":{"branchName":"default","commitMessage":"default","description":"default","title":"default"},"templateVariants":[],"type":"auto","upgrade":[],"upgradeInfo":{"versionsDiff":1,"publishedDate":"2024-09-09T13:57:56.873Z"},"vulns":[]}'
Co-authored-by: snyk-bot <snyk-bot@snyk.io>1 parent ca99656 commit 9bf32c4Copy full SHA for 9bf32c4
File tree
Expand file treeCollapse file tree
2 files changed
+9
-8
lines changedOpen diff view settings
Filter options
Expand file treeCollapse file tree
2 files changed
+9
-8
lines changedOpen diff view settings
Collapse file
+8-7Lines changed: 8 additions & 7 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.
Collapse file
+1-1Lines changed: 1 addition & 1 deletion
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
9 | 9 | | |
10 | 10 | | |
11 | 11 | | |
12 | | - | |
| 12 | + | |
13 | 13 | | |
14 | 14 | | |
15 | 15 | | |
| |||
0 commit comments