Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Snyk] Upgrade puppeteer from 2.0.0 to 2.1.1 #6

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

snyk-bot
Copy link

Snyk has created this PR to upgrade puppeteer from 2.0.0 to 2.1.1.

merge advice
ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


  • The recommended version is 2 versions ahead of your current version.
  • The recommended version was released a year ago, on 2020-02-05.

The recommended version fixes:

Severity Issue PriorityScore (*) Exploit Maturity
Prototype Pollution
SNYK-JS-MINIMIST-559764
387/1000
Why? Proof of Concept exploit, CVSS 5.6
Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Release notes
Package name: puppeteer
  • 2.1.1 - 2020-02-05

    eec4325 - chore: mark version v2.1.1
    9923e56 - fix(filechooser): quick fix for the headful file chooser (#5369)
    1a1ef83 - Add FAQ entry on cross-browser support (#5360)
    0d243b7 - feat: make it possible to run install.js script with puppeteer-core (#5325)
    c283fea - docs(api): add example to page.$$eval (#5200)
    b45f8e4 - chore: bump version to v2.1.0-post (#5349)

  • 2.1.0 - 2020-01-27

    Big changes

    • Chromium 80.0.3987.0 (r722234)
    • The launcher now has an option to run Puppeteer with different browsers, starting with Firefox (#5137). Puppeteer can now talk to a real, unpatched Firefox binary (as opposed to the old Juggler-based approach). This is a first step towards eventually deprecating the separate puppeteer-firefox package in favor of supporting Firefox directly in puppeteer itself.

    Raw notes

    7e7b05a - chore: mark version v2.1.0 + roll to r722234 (#5347)
    013a86c - feat(chromium): roll Chromium to r722276 (#5289)
    14b2369 - chore: mark puppeteer-firefox version v0.5.1 (#5294)
    3a49cfc - chore: move to GitHub hosting for Juggler binaries (#5293)
    c7af7de - docs(readme): update link for ndb (#5272)
    5e63254 - chore: fix typo in test name (#5217)
    80b5c44 - chore: upgrade https-proxy-agent (#5243)
    6091a34 - fix: prepare jsHandle.uploadFile for CDP Page.handleFileChooser removal (#5196)
    8b49dc6 - fix: don’t disable BlinkGenPropertyTrees anymore (#5159)
    f0bf645 - test: reduce flakiness for accessibility tests with autofocus (#5116)
    6cc98a7 - docs(troubleshooting): recommend using args for heroku (#5197)
    35d5ba5 - feat(launcher): Set default Firefox prefs (#5149) (#5195)
    eddb23b - chore: update URLs (#5185)
    c5a72e9 - feat(launcher): add option to run Puppeteer with different browsers (#5137)
    d17708b - fix(types): publish protocol types to npm (#5174)
    fd43f9c - docs(api): fix defaultArgs link (#5126)
    5fa28b5 - docs(api): fix typo (#5120)
    561c99d - docs(api): prefer async/await over Promise#then (#5089)
    aaa904d - docs(contributing): clarify release process
    304f4a7 - chore: update .npmignore
    7032472 - chore: bump version to v2.0.0-post

  • 2.0.0 - 2019-10-24
    Read more
from puppeteer GitHub release notes
Commit messages
Package name: puppeteer
  • 46386eb chore: mark version v2.1.1 (#5388)
  • 9923e56 fix(filechooser): quick fix for the headful file chooser (#5369)
  • 1a1ef83 Add FAQ entry on cross-browser support (#5360)
  • 0d243b7 feat: make it possible to run `install.js` script with `puppeteer-core` (#5325)
  • c283fea docs(api): add example to page.$$eval (#5200)
  • b45f8e4 chore: bump version to v2.1.0-post (#5349)
  • a30cf05 chore: mark version v2.1.0 (#5347)
  • 013a86c feat(chromium): roll Chromium to r722269 (#5289)
  • 14b2369 chore: mark puppeteer-firefox version v0.5.1 (#5294)
  • 3a49cfc chore: move to GitHub hosting for Juggler binaries (#5293)
  • c7af7de docs(readme): update link for ndb (#5272)
  • 5e63254 chore: fix typo in test name (#5217)
  • 80b5c44 chore: upgrade https-proxy-agent (#5243)
  • 6091a34 fix: prepare jsHandle.uploadFile for CDP Page.handleFileChooser removal (#5196)
  • 8b49dc6 fix: don’t disable BlinkGenPropertyTrees anymore (#5159)
  • f0bf645 test: reduce flakiness for accessibility tests with autofocus (#5116)
  • 6cc98a7 docs(troubleshooting): recommend using args for heroku (#5197)
  • 35d5ba5 feat(launcher): Set default Firefox prefs (#5149) (#5195)
  • eddb23b chore: update URLs (#5185)
  • c5a72e9 feat(launcher): add option to run Puppeteer with different browsers (#5137)
  • d17708b fix(types): publish protocol types to npm (#5174)
  • fd43f9c docs(api.md): fix defaultArgs link (#5126)
  • 5fa28b5 docs(api.md): fix typo (#5120)
  • 561c99d docs(api.md): prefer async/await over Promise#then (#5089)

Compare


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

🧐 View latest project report

🛠 Adjust upgrade PR settings

🔕 Ignore this dependency or unsubscribe from future upgrade PRs

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
1 participant