Skip to content

[Snyk] Security upgrade juicy-chat-bot from 0.6.6 to 0.7.1

Chris Hamill requested to merge snyk-fix-272334acb182e1f7eaf06b6e2a1e32ea into master

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this Merge Request

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • package.json

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
critical severity 816/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 9.9
Sandbox Escape
SNYK-JS-VM2-5415299
No Proof of Concept
critical severity 883/1000
Why? Proof of Concept exploit, Recently disclosed, Has a fix available, CVSS 9.8
Sandbox Escape
SNYK-JS-VM2-5422057
No Proof of Concept
critical severity 776/1000
Why? Recently disclosed, Has a fix available, CVSS 9.8
Improper Handling of Exceptional Conditions
SNYK-JS-VM2-5426093
No No Known Exploit

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: juicy-chat-bot The new version differs by 8 commits.
  • 11bbd8b Bump CI/CD to Node.js 18
  • 3b677b5 Bump to v0.7.1
  • 4a90dc5 Merge remote-tracking branch 'origin/develop' into develop
  • 7b32e43 Pin version of VM2 to 3.9.17 without vulnerability (#14)
  • 8e63414 Pin version of VM2 to 3.9.17 without vulnerability (#14)
  • 61a1f1a Bump version
  • 5ef0011 Add typescript definition for juicy-chat-bot
  • d816d29 Bump copyright notes to include 2023

See the full diff

Check the changes in this Merge Request to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information: 🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Learn about vulnerability in an interactive lesson of Snyk Learn.

Merge request reports