Skip to content

Conversation

officialmofabs
Copy link

@officialmofabs officialmofabs commented Mar 8, 2025

snyk-top-banner

Snyk has created this PR to fix 4 vulnerabilities in the npm dependencies of this project.

Snyk changed the following file(s):

  • ui/package.json
  • ui/package-lock.json

Vulnerabilities that will be fixed with an upgrade:

Issue Score
medium severity Server-side Request Forgery (SSRF)
SNYK-JS-AXIOS-9292519
  703  
low severity Arbitrary Code Injection
SNYK-JS-PRISMJS-9055448
  508  
medium severity Cross-site Scripting (XSS)
SNYK-JS-AXIOS-6671926
  479  
low severity Cross-site Scripting (XSS)
SNYK-JS-DOMPURIFY-8722251
  421  

Important

  • Check the changes in this PR to ensure they won't cause issues with your project.
  • Max score is 1000. Note that the real score may have changed since the PR was raised.
  • This PR was automatically created by Snyk using the credentials of a real user.

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report
📜 Customise PR templates
🛠 Adjust project settings
📚 Read about Snyk's upgrade logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Server-side Request Forgery (SSRF)
🦉 Cross-site Scripting (XSS)
🦉 Arbitrary Code Injection

Summary by Sourcery

Upgrade several npm dependencies to address multiple vulnerabilities, including Server-Side Request Forgery (SSRF), Arbitrary Code Injection, and Cross-site Scripting (XSS).

Bug Fixes:

  • Fixes Server-side Request Forgery (SSRF) vulnerability SNYK-JS-AXIOS-9292519.
  • Fixes Arbitrary Code Injection vulnerability SNYK-JS-PRISMJS-9055448.
  • Fixes Cross-site Scripting (XSS) vulnerability SNYK-JS-AXIOS-6671926.
  • Fixes Cross-site Scripting (XSS) vulnerability SNYK-JS-DOMPURIFY-8722251.

Copy link

sourcery-ai bot commented Mar 8, 2025

Reviewer's Guide by Sourcery

This pull request updates the versions of @prefecthq/prefect-design, @prefecthq/prefect-ui-library, and axios in ui/package.json and ui/package-lock.json to address multiple security vulnerabilities.

No diagrams generated as the changes look simple and do not need a visual representation.

File-Level Changes

Change Details Files
Updated multiple dependencies to address security vulnerabilities.
  • Updated @prefecthq/prefect-design from 2.7.16 to 2.14.18.
  • Updated @prefecthq/prefect-ui-library from 2.9.13 to 3.11.45.
  • Updated axios from 1.6.7 to 1.8.2.
ui/package.json
ui/package-lock.json

Tips and commands

Interacting with Sourcery

  • Trigger a new review: Comment @sourcery-ai review on the pull request.
  • Continue discussions: Reply directly to Sourcery's review comments.
  • Generate a GitHub issue from a review comment: Ask Sourcery to create an
    issue from a review comment by replying to it. You can also reply to a
    review comment with @sourcery-ai issue to create an issue from it.
  • Generate a pull request title: Write @sourcery-ai anywhere in the pull
    request title to generate a title at any time. You can also comment
    @sourcery-ai title on the pull request to (re-)generate the title at any time.
  • Generate a pull request summary: Write @sourcery-ai summary anywhere in
    the pull request body to generate a PR summary at any time exactly where you
    want it. You can also comment @sourcery-ai summary on the pull request to
    (re-)generate the summary at any time.
  • Generate reviewer's guide: Comment @sourcery-ai guide on the pull
    request to (re-)generate the reviewer's guide at any time.
  • Resolve all Sourcery comments: Comment @sourcery-ai resolve on the
    pull request to resolve all Sourcery comments. Useful if you've already
    addressed all the comments and don't want to see them anymore.
  • Dismiss all Sourcery reviews: Comment @sourcery-ai dismiss on the pull
    request to dismiss all existing Sourcery reviews. Especially useful if you
    want to start fresh with a new review - don't forget to comment
    @sourcery-ai review to trigger a new review!
  • Generate a plan of action for an issue: Comment @sourcery-ai plan on
    an issue to generate a plan of action for it.

Customizing Your Experience

Access your dashboard to:

  • Enable or disable review features such as the Sourcery-generated pull request
    summary, the reviewer's guide, and others.
  • Change the review language.
  • Add, remove or edit custom review instructions.
  • Adjust other review settings.

Getting Help

Copy link

@sourcery-ai sourcery-ai bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We have skipped reviewing this pull request. It seems to have been created by a bot ('[Snyk]' found in title). We assume it knows what it's doing!

Copy link

New, updated, and removed dependencies detected. Learn more about Socket for GitHub ↗︎

Package New capabilities Transitives Size Publisher
npm/@prefecthq/[email protected]2.14.18 Transitive: environment, filesystem, network +41 47 MB znicholasbrown
npm/@prefecthq/[email protected]3.11.45 Transitive: environment, eval, filesystem, network, shell +138 89.7 MB znicholasbrown
npm/[email protected]1.8.2 Transitive: environment, filesystem +8 2.51 MB emilyemorehouse, jasonsaayman, mzabriskie, ...1 more
pypi/[email protected] None 0 0 B
pypi/[email protected] None 0 217 kB fishtown-analytics
pypi/[email protected] None 0 3.53 MB fishtown-analytics
pypi/[email protected] None 0 0 B
pypi/[email protected] None 0 160 kB fishtown-analytics
pypi/[email protected] None 0 3.21 MB fjetter, jacob.tomlinson, jakirkham, ...5 more
pypi/[email protected] None 0 3.96 MB fjetter, jacob.tomlinson, jakirkham, ...5 more
pypi/[email protected] environment, filesystem, network, shell 0 511 kB aiordache, ccrone, dev-tooling-team, ...4 more
pypi/[email protected] None 0 175 kB asottile, graffatcolmingov
pypi/[email protected] None 0 0 B
pypi/[email protected] None 0 0 B
pypi/[email protected] None 0 0 B
pypi/[email protected] None 0 0 B
pypi/[email protected] None 0 3.2 MB gcloudpypi, google_opensource
pypi/[email protected] None 0 0 B
pypi/[email protected] None 0 1.03 MB roguelynn
pypi/[email protected] None 0 0 B
pypi/[email protected] eval, filesystem 0 21.9 kB oprypin
pypi/[email protected] None 0 0 B
pypi/[email protected] environment, eval, filesystem, network, shell 0 6.88 MB d0ugal, mkdocsdeploy, oprypin, ...2 more
pypi/[email protected] environment, eval, filesystem, shell 0 189 kB pawamoy
pypi/[email protected] None 0 116 MB oprypin, pawamoy
pypi/[email protected] None 0 446 kB Fuzzyman, berkerpeksag, carthorse-mock, ...3 more
pypi/[email protected] None 0 0 B
pypi/[email protected] None 0 0 B
pypi/[email protected] None 0 138 kB vemel
pypi/[email protected] None 0 55.8 MB ambv, guido, hauntsaninja, ...8 more
pypi/[email protected] environment, eval, filesystem, network, shell, unsafe 0 205 MB MarcoGorelli, datapythonista, jbrockmendel, ...8 more
pypi/[email protected] environment, eval, filesystem, shell 0 73.4 MB aclark, hugovk, radarhere, ...1 more
pypi/[email protected] None 0 0 B
pypi/[email protected] None 0 365 kB desertaxle, prefect
pypi/[email protected] environment, filesystem, network, shell 0 54.5 kB desertaxle, prefect
pypi/[email protected] environment, filesystem, network 0 120 kB desertaxle, prefect
pypi/[email protected] environment, network 0 79.4 kB desertaxle, prefect
pypi/[email protected] None 0 0 B
pypi/[email protected] None 0 4.1 MB ptmcg
pypi/[email protected] None 0 0 B
pypi/[email protected] None 0 247 kB ionel
pypi/[email protected] environment, eval, filesystem, network 0 333 kB The_Compiler, anatoly, flub, ...4 more
pypi/[email protected] None 0 363 kB The_Compiler, anatoly, flub, ...4 more
pypi/[email protected] None 0 0 B
pypi/[email protected] None 0 44.5 kB un33k
pypi/[email protected] environment, eval 0 110 kB 5monkeys
pypi/[email protected] None 0 77.6 kB jaraco, jezdez, ronny
pypi/[email protected] None 0 5.19 MB abravalheri, dstufft, jaraco
pypi/[email protected] eval, filesystem, network 0 316 kB barbieri
pypi/[email protected] None 0 220 kB jd, sileht
pypi/[email protected] None 0 1 MB vemel
pypi/[email protected] None 0 488 kB agronholm, joeforker, natefoo

🚮 Removed packages: pypi/[email protected], pypi/[email protected], pypi/[email protected], pypi/[email protected], pypi/[email protected]

View full report↗︎

Copy link

This pull request is stale because it has been open 14 days with no activity. To keep this pull request open remove stale label or comment.

Copy link

This pull request was closed because it has been stale for 14 days with no activity. If this pull request is important or you have more to add feel free to re-open it.

@github-actions github-actions bot closed this Jun 29, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants