Skip to content

Conversation

twilio-product-security

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • package.json
    • package-lock.json

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
medium severity 551/1000
Why? Recently disclosed, Has a fix available, CVSS 5.3
Improper Input Validation
SNYK-JS-POSTCSS-5926692
Yes No Known Exploit

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: @twilio/flex-plugin-scripts The new version differs by 250 commits.
  • ff48f0f v6.2.1
  • 8c3ae73 FLEXY-3002 fixed modular css sass/scss support (#850)
  • 7edf53d Merge pull request #848 from twilio/FLEXY-4848-use-actions
  • 6146007 Merge branch 'main' into FLEXY-4848-use-actions
  • 4451e2b FLEXY-4848: revert testing manual release
  • b25f756 Merge pull request #847 from twilio/FLEXY-4848-use-actions
  • dcf7c8f Merge branch 'main' into FLEXY-4848-use-actions
  • ed701f8 FLEXY-4848: test manual release
  • 22a3834 FLEXY-4848: check manual release
  • 49d7700 Merge pull request #846 from twilio/FLEXY-4848-check-schedule-job
  • 5c29c07 Merge branch 'main' into FLEXY-4848-check-schedule-job
  • 364d1b4 FLEXY-4848: delete schedule job
  • 0d138ed Merge pull request #845 from twilio/FLEXY-4848-check-schedule-job
  • e94ecfe FLEXY-4848: check scheduled runs
  • 2103f9c v6.2.0
  • 01c1028 Merge pull request #839 from twilio/FLEXY-3002
  • 720a595 FLEXY-3002 modified e2e and changelog for v6
  • 6b2f5cd Fixed the login btn selector
  • 2ef07df FLEXY-3002 updated changelog for 6.2.0 release
  • 2a9c5f4 FLEXY-3002 updated changelog for 6.2.0 release
  • 115394d FLEXY-3002 fix tests
  • 36b3f0b FLEXY-3002 fix formatting issue in build script
  • 4be4539 FLEXY-3002 fixed review comments
  • d1ac745 FLEXY-3002 ipv6 compatibility for node 18

See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Improper Input Validation

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants