Skip to content

Update dependency flow-typed to v3#17

Open
dev-mend-for-github-com[bot] wants to merge 1 commit intoalphafrom
whitesource-remediate/flow-typed-3.x
Open

Update dependency flow-typed to v3#17
dev-mend-for-github-com[bot] wants to merge 1 commit intoalphafrom
whitesource-remediate/flow-typed-3.x

Conversation

@dev-mend-for-github-com
Copy link

@dev-mend-for-github-com dev-mend-for-github-com bot commented Oct 30, 2025

This PR contains the following updates:

Package Type Update Change
flow-typed (source) dependencies major ^2.6.2^3.0.0

By merging this PR, the below vulnerabilities will be automatically resolved:

Severity CVSS Score Vulnerability Reachability
High High 7.5 CVE-2021-3807
High High 7.3 CVE-2020-7774
High High 7.1 CVE-2022-0144
Medium Medium 6.1 CVE-2022-0235
Medium Medium 5.6 CVE-2020-15366
Medium Medium 5.3 CVE-2020-7608
Medium Medium 5.3 CVE-2022-25881
Medium Medium 5.3 CVE-2022-33987

Release Notes

flow-typed/flow-typed (flow-typed)

v3.8.0

Compare Source

Added
Changed
  • Consistent list logging (#​4287)
  • Coerce cli version with semver to allow for prerelease tags (#​4291)
  • Fix if dependency is resolved npm package (#​4298)
  • Bump minimist from 1.2.0 to 1.2.6 in (#​4293)
  • [docs] contract -> contrast (#​4281)
  • [docs] update command doesn't take positional arguments (#​4328)
  • [docs] document create-stub --typescript flag (#​4329)

v3.7.0

Compare Source

Added
Changed
  • CLI tool now ships with flowtypes (#​4233)
  • Install can match with alpha versions now (#​4247)
Fixed
  • Fix create def with scopes (#​4234)
  • Fix buffer deprecation error (#​4270)
  • Temporarily turn off validate-def checks against npm (#​4249)
  • Bump ajv from 6.11.0 to 6.12.6 in /cli (#​4260)
  • Bump node-fetch from 2.6.6 to 2.6.7 in /cli (#​4254)
  • Bump shelljs from 0.8.3 to 0.8.5 in /cli (#​4237)

v3.6.1

Compare Source

Changed
  • Provide better logs related to dir structure when running tests (#​4213)
Fixed
  • Pin colors@​1.4.0 to fix security vuln (#​4229)
  • Fix installing minor libdef version (#​4224)
  • Allow .DS_Store files in definitions nested directories (#​4217)
  • [docs] Fix some link issues in contributing docs (#​4212)
  • [docs] Fix the documented pathing for an ignoring eslint (#​4218)

v3.6.0

Compare Source

Added
Fixed
  • Dramatically improve install time (#​4193)
  • Replace unzipper with node-stream-zip (#​4180)
  • Install will restart flow bin (#​4185)
  • Upgrade octokit/rest version (#​4197)
  • [docs] Move wiki to /docs and serve with docsify (#​4179)
Removed
  • Fix definitions not running in ci env (#​4187)

v3.5.0

Compare Source

Added
Changed
  • Update flow-bin version to latest version (#​4153)
  • install will also install lib defs of dependencies that ship with library (#​4143)
  • Only test against changed versions with only-changed option (#​4168)
  • Bump table from 5.4.6 to 6.7.3 (#​4175)
  • Bump ansi-regex from 5.0.0 to 5.0.1 (#​4177)
  • Update multiple devDependencies (#​4174)
    • Bump @​babel/cli from 7.8.4 to 7.16.0
    • Bump @​babel/core from 7.8.4 to 7.16.0
    • Bump @​babel/preset-env from 7.8.4 to 7.16.4
    • Bump @​babel/preset-flow from 7.8.3 to 7.16.0
    • Bump eslint from 6.8.0 to 8.3.0
    • Bump eslint-config-prettier from 6.10.1 to 8.3.0
    • Bump eslint-plugin-fb-flow from 0.0.1 to 0.0.4
    • Bump eslint-plugin-flowtype from 4.6.0 to 8.0.3
    • Bump eslint-plugin-prettier from 3.1.2 to 4.0.0
    • Bump flow-bin from 0.164.0 to 0.165.1
    • Bump jest from 25.1.027.3.1
Fixed
  • Fix installing lib def package when dependency version uses >= (#​4157)
  • Support for slash-style comments in dependencies (#​4169)
  • Remove babel-eslint@​10.0.3
  • Remove babel-jest@​25.1.0

v3.4.0

Compare Source

Added
  • quick_run_def_tests now supports arguments (#​4064)
  • Add eslint-plugin-fb-flow ESLint plugin (#​4114)
  • New create-def command and script for easier libdef creation (#​4125)
  • Add support for .ignore file (#​4133)
Changed
  • Add package health badge to the README (#​4049)
  • Update CI node versions in Github Actions to 12 & 14 (#​4082)
Fixed
  • Fix flow-typed sometimes writing an empty file (#​4011)
  • Bump y18n from 4.0.0 to 4.0.1 (#​4054)
  • Bump lodash from 4.17.19 to 4.17.21 (#​4077)
  • Bump hosted-git-info from 2.7.1 to 2.8.9 (#​4079)
  • Bump browserslist from 4.8.7 to 4.16.6 (#​4081)
  • Bump ws from 7.2.1 to 7.4.6 (#​4084)
  • Bump normalize-url from 4.5.0 to 4.5.1 (#​4090)
  • Bump glob-parent from 5.0.0 to 5.1.2 (#​4091)
  • Bump path-parse from 1.0.6 to 1.0.7 (#​4118)
  • Bump tmpl from 1.0.4 to 1.0.5 (#​4139)

v3.3.1

Compare Source

Fixed
  • Fix a regression introduced in 3.3.0 (#​4023)

v3.3.0

Compare Source

Added
  • Locate modules with Yarn PnP in PnP projects (#​3963)
Changed
  • Move from TravisCI to Github Actions
  • Clean up fs.readFile usage (#​3966)
  • Update cli flow version to 0.144.0 (#​4014)
  • Lock semver to fix install command (#​4018)
  • Bump node-fetch from 2.6.0 to 2.6.1 in /cli (#​3896)
  • [Docs] Update new libdefs minimum Flow version (#​3954)
Fixed
  • Fix installing patch range lib defs (#​4003)
  • Fix broken flow breaking function (#​4017)
  • Fix tests not running in CI (#​4010)
  • Update git author information for Github Action. (#​3952)

v3.2.1

Compare Source

Changed
  • Better fix for semver throwing errors for versions of v0.x.x (#​3866)

v3.2.0

Compare Source

Changed
  • Support flow versions > 0.125.0 (#​3855)
  • Improved eslint/prettier integration (#​3787)
Fixed
  • Add workaround for semver throwing errors for versions of v0.x.x (#​3842)
  • Avoid uncaught error when network fails (#​3846)
  • Fix <> parsing (#​3786)

v3.1.0

Compare Source

Changed
  • Remove react-dom from built-in flow libdefs (#​3748)
Fixed
  • Fix --overwrite install command option type (#​3754)

v3.0.0

Compare Source

Added
  • Recommend matching commands (#​3700)
Changed
  • [BREAKING-CHANGE] Drop support for node < 10 (#​3743)
  • Travis specs now run on node 10 & 12, as opposed to 8 & 10 (#​3743)
Fixed
  • Updated octokit/rest to deprecation message (#​3602)
  • Fix GH_CLIENT usage in runTests test (#​3638)

  • If you want to rebase/retry this PR, check this box

@dev-mend-for-github-com dev-mend-for-github-com bot added the security fix Security fix generated by Mend label Oct 30, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

security fix Security fix generated by Mend

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants