[Snyk] Security upgrade azure-pipelines-task-lib from 3.0.6-preview.1 to 5.2.3 - #7
newf-bgreet wants to merge 1 commit into
Conversation
…ependency-check-build-task/package-lock.json to reduce vulnerabilities The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-JS-BRACEEXPANSION-18512280
|
This is a major version upgrade from a preview release to a stable major release, crossing two major versions (v3 → v5). This introduces significant breaking changes, primarily related to the underlying Node.js runtime environment required by the task. Key Breaking Changes:
Recommendation:
|
Snyk has created this PR to fix 1 vulnerabilities in the npm dependencies of this project.
Snyk changed the following file(s):
src/Tasks/dependency-check-build-task/package.jsonsrc/Tasks/dependency-check-build-task/package-lock.jsonVulnerabilities that will be fixed with an upgrade:
SNYK-JS-BRACEEXPANSION-18512280
Breaking Change Risk
Important
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.
For more information:
🧐 View latest project report
📜 Customise PR templates
🛠 Adjust project settings
📚 Read about Snyk's upgrade logic
Learn how to fix vulnerabilities with free interactive lessons:
🦉 Allocation of Resources Without Limits or Throttling