[PR #16] [CLOSED] [Snyk] Upgrade natural from 5.0.4 to 5.1.13 #19

Closed
opened 2026-03-04 00:58:27 +03:00 by kerem · 0 comments
Owner

📋 Pull Request Information

Original PR: https://github.com/spamscanner/spamscanner/pull/16
Author: @snyk-bot
Created: 4/8/2022
Status: Closed

Base: masterHead: snyk-upgrade-7f292546a1f601c5f6daaa872fef321e


📝 Commits (1)

  • 189596e fix: upgrade natural from 5.0.4 to 5.1.13

📊 Changes

2 files changed (+11 additions, -18 deletions)

View changed files

📝 package.json (+1 -1)
📝 yarn.lock (+10 -17)

📄 Description

Snyk has created this PR to upgrade natural from 5.0.4 to 5.1.13.

merge advice
ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


  • The recommended version is 7 versions ahead of your current version.
  • The recommended version was released 3 months ago, on 2022-01-03.

The recommended version fixes:

Severity Issue PriorityScore (*) Exploit Maturity
Regular Expression Denial of Service (ReDoS)
SNYK-JS-NATURAL-1915418
479/1000
Why? Has a fix available, CVSS 5.3
No Known Exploit

(*) Note that the real score may have changed since the PR was raised.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

🧐 View latest project report

🛠 Adjust upgrade PR settings

🔕 Ignore this dependency or unsubscribe from future upgrade PRs


🔄 This issue represents a GitHub Pull Request. It cannot be merged through Gitea due to API limitations.

## 📋 Pull Request Information **Original PR:** https://github.com/spamscanner/spamscanner/pull/16 **Author:** [@snyk-bot](https://github.com/snyk-bot) **Created:** 4/8/2022 **Status:** ❌ Closed **Base:** `master` ← **Head:** `snyk-upgrade-7f292546a1f601c5f6daaa872fef321e` --- ### 📝 Commits (1) - [`189596e`](https://github.com/spamscanner/spamscanner/commit/189596e4f45a81926561baf3b0d1d2ba928b4b92) fix: upgrade natural from 5.0.4 to 5.1.13 ### 📊 Changes **2 files changed** (+11 additions, -18 deletions) <details> <summary>View changed files</summary> 📝 `package.json` (+1 -1) 📝 `yarn.lock` (+10 -17) </details> ### 📄 Description <h3>Snyk has created this PR to upgrade natural from 5.0.4 to 5.1.13.</h3> ![merge advice](https://app.snyk.io/badges/merge-advice/?package_manager=yarn&package_name=natural&from_version=5.0.4&to_version=5.1.13&pr_id=7b90a88a-ba84-459b-9b85-6d0364363606&visibility=true&has_feature_flag=false) :information_source: Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project. <hr/> - The recommended version is **7 versions** ahead of your current version. - The recommended version was released **3 months ago**, on 2022-01-03. The recommended version fixes: Severity | Issue | PriorityScore (*) | Exploit Maturity | :-------------------------:|:-------------------------|-------------------------|:------------------------- <img src="https://res.cloudinary.com/snyk/image/upload/w_20,h_20/v1561977819/icon/m.png" width="20" height="20" title="medium severity"/> | Regular Expression Denial of Service (ReDoS)<br/> [SNYK-JS-NATURAL-1915418](https://snyk.io/vuln/SNYK-JS-NATURAL-1915418) | **479/1000** <br/> **Why?** Has a fix available, CVSS 5.3 | No Known Exploit (*) Note that the real score may have changed since the PR was raised. <hr/> **Note:** *You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.* For more information: <img src="https://api.segment.io/v1/pixel/track?data=eyJ3cml0ZUtleSI6InJyWmxZcEdHY2RyTHZsb0lYd0dUcVg4WkFRTnNCOUEwIiwiYW5vbnltb3VzSWQiOiI3YjkwYTg4YS1iYTg0LTQ1OWItOWI4NS02ZDAzNjQzNjM2MDYiLCJldmVudCI6IlBSIHZpZXdlZCIsInByb3BlcnRpZXMiOnsicHJJZCI6IjdiOTBhODhhLWJhODQtNDU5Yi05Yjg1LTZkMDM2NDM2MzYwNiJ9fQ==" width="0" height="0"/> 🧐 [View latest project report](https://app.snyk.io/org/titanism/project/31f9eeb1-e0ca-41b6-8260-3db1fdd55c29?utm_source&#x3D;github&amp;utm_medium&#x3D;referral&amp;page&#x3D;upgrade-pr) 🛠 [Adjust upgrade PR settings](https://app.snyk.io/org/titanism/project/31f9eeb1-e0ca-41b6-8260-3db1fdd55c29/settings/integration?utm_source&#x3D;github&amp;utm_medium&#x3D;referral&amp;page&#x3D;upgrade-pr) 🔕 [Ignore this dependency or unsubscribe from future upgrade PRs](https://app.snyk.io/org/titanism/project/31f9eeb1-e0ca-41b6-8260-3db1fdd55c29/settings/integration?pkg&#x3D;natural&amp;utm_source&#x3D;github&amp;utm_medium&#x3D;referral&amp;page&#x3D;upgrade-pr#auto-dep-upgrades) <!--- (snyk:metadata:{"prId":"7b90a88a-ba84-459b-9b85-6d0364363606","prPublicId":"7b90a88a-ba84-459b-9b85-6d0364363606","dependencies":[{"name":"natural","from":"5.0.4","to":"5.1.13"}],"packageManager":"yarn","type":"auto","projectUrl":"https://app.snyk.io/org/titanism/project/31f9eeb1-e0ca-41b6-8260-3db1fdd55c29?utm_source=github&utm_medium=referral&page=upgrade-pr","projectPublicId":"31f9eeb1-e0ca-41b6-8260-3db1fdd55c29","env":"prod","prType":"upgrade","vulns":["SNYK-JS-NATURAL-1915418"],"issuesToFix":[{"issueId":"SNYK-JS-NATURAL-1915418","severity":"medium","title":"Regular Expression Denial of Service (ReDoS)","exploitMaturity":"no-known-exploit","priorityScore":479,"priorityScoreFactors":[{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"5.3","score":265}]}],"upgrade":["SNYK-JS-NATURAL-1915418"],"upgradeInfo":{"versionsDiff":7,"publishedDate":"2022-01-03T13:32:42.146Z"},"templateVariants":["merge-advice-badge-shown","priorityScore"],"hasFixes":true,"isMajorUpgrade":false,"isBreakingChange":false,"priorityScoreList":[479]}) ---> --- <sub>🔄 This issue represents a GitHub Pull Request. It cannot be merged through Gitea due to API limitations.</sub>
kerem 2026-03-04 00:58:27 +03:00
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
starred/spamscanner#19
No description provided.