Skip to content

[Snyk] Upgrade @vscode/extension-telemetry from 0.8.1 to 0.9.8#5

Open
q1blue wants to merge 1 commit intodevelopfrom
snyk-upgrade-952ee767ff72b5afd9431f3638738e85
Open

[Snyk] Upgrade @vscode/extension-telemetry from 0.8.1 to 0.9.8#5
q1blue wants to merge 1 commit intodevelopfrom
snyk-upgrade-952ee767ff72b5afd9431f3638738e85

Conversation

@q1blue
Copy link

@q1blue q1blue commented Feb 18, 2025

snyk-top-banner

Snyk has created this PR to upgrade @vscode/extension-telemetry from 0.8.1 to 0.9.8.

ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


  • The recommended version is 13 versions ahead of your current version.

  • The recommended version was released 3 months ago.

Issues fixed by the recommended upgrade:

Issue Score Exploit Maturity
high severity Arbitrary Code Execution
SNYK-JS-IMPORTINTHEMIDDLE-5826054
619 No Known Exploit
Release notes
Package name: @vscode/extension-telemetry
  • 0.9.8 - 2024-11-20

    Changes:

    • #218: Bump version for release
    • #216: Accept instrumentation and connection string
    • #215: Propagate session ID metadata

    This list of changes was auto generated.

  • 0.9.7 - 2024-08-02

    Changes:

    • #213: Bump version + packages
    • #211: Update readme + support connection string
    • #210: Send user id in extension paylod
    • #207: Bump braces from 3.0.2 to 3.0.3
    • #206: Update packages
    • #204: Rollback packages

    This list of changes was auto generated.

  • 0.9.6 - 2024-03-22

    Update packages (#206)

  • 0.9.5 - 2024-03-20

    Rollback packages (#204)

  • 0.9.4 - 2024-03-20
    • Allows measurements to also be undefined for easy omitting, similar to how properties work
  • 0.9.3 - 2024-02-29
    • Improves on the user agent metric shown when navigator.userAgentData is unavailable. Thanks to @ sezna
    • Fixes a bug with telemetry fetching using app insights on older version of node. Thanks to @ devm33
  • 0.9.2 - 2023-12-19

    This release contains a small fix to the 1DS package used by Microsoft extensions in the web to ensure compliance with the California's Global Privacy Control. If you're not a Microsoft extension, then it is safe to disregard this release as it contains no new features or improvements for the third party flow.

  • 0.9.1 - 2023-12-12

    Thanks to a community contribution by @ ilia-db the unhandlederror event handler has been properly fixed to include common properties.

  • 0.9.0 - 2023-11-01

    Application insights web basics comes with the ability to pass in a fetch pollyfill that allows it to be used for both Node and Web. This is similar to what we already do for first party extensions using the 1DS package.

    While there is no breaking changes here, the replacement of a key dependency with what should be an equivalent alternative may have unknown edge cases that were not accounted for, therefore the version has been bumped to reflect this.

    Bundlephobia reports a 67Kb decline in bundle size with this change.

  • 0.8.5 - 2023-09-20
    • Improves shutdown performance by lessening the amount of time which is allocated to disposing the telemetry reporters. Additionally, removes a few redundant flushes. Fixes microsoft/vscode#192742
  • 0.8.4 - 2023-08-24
  • 0.8.3 - 2023-08-14
  • 0.8.2 - 2023-07-21
  • 0.8.1 - 2023-07-05
from @vscode/extension-telemetry GitHub release notes

Important

  • Check the changes in this PR to ensure they won't cause issues with your project.
  • This PR was automatically created by Snyk using the credentials of a real user.
  • Max score is 1000. Note that the real score may have changed since the PR was raised.

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

Snyk has created this PR to upgrade @vscode/extension-telemetry from 0.8.1 to 0.9.8.

See this package in npm:
@vscode/extension-telemetry

See this project in Snyk:
https://app.snyk.io/org/quantum-blockchain-ai-9pr/project/ba278951-2c58-42d9-870c-929fe7d94118?utm_source=github&utm_medium=referral&page=upgrade-pr
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants