Skip to content

[Snyk] Fix for 2 vulnerabilities #13

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Open
wants to merge 1 commit into
base: develop
Choose a base branch
from

Conversation

naiba4
Copy link
Owner

@naiba4 naiba4 commented Nov 28, 2023

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • package.json
    • package-lock.json

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
high severity 696/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
Regular Expression Denial of Service (ReDoS)
SNYK-JS-ANSIREGEX-1583908
No Proof of Concept
high severity 676/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 7.1
Cross-site Request Forgery (CSRF)
SNYK-JS-AXIOS-6032459
Yes Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: browser-sync The new version differs by 16 commits.

See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Regular Expression Denial of Service (ReDoS)
🦉 Cross-site Request Forgery (CSRF)

Copy link

guardrails bot commented Nov 28, 2023

⚠️ We detected 2 security issues in this pull request:

Vulnerable Libraries (2)
Severity Details
High pkg:npm/[email protected] upgrade to: > 9.0.0
High pkg:npm/[email protected] upgrade to: > 2.28.0

More info on how to fix Vulnerable Libraries in JavaScript.


👉 Go to the dashboard for detailed results.

📥 Happy? Share your feedback with us.

Copy link

Updated dependencies detected. Learn more about Socket for GitHub ↗︎

Packages Version New capabilities Transitives Size Publisher
semver 7.3.5...7.5.4 None +0/-0 93.4 kB npm-cli-ops
typewriter 7.4.1...9.0.0 None +127/-65 16.2 MB sethsegment
browser-sync 2.27.10...2.28.0 None +12/-20 6.01 MB shakyshane

Copy link

🚨 Potential security issues detected. Learn more about Socket for GitHub ↗︎

To accept the risk, merge this PR and you will not be notified again.

Issue Package Version Note Source
Chronological version anomaly socket.io-parser 4.2.4
Chronological version anomaly minimatch 5.1.6
Chronological version anomaly normalize-url 6.1.0
Chronological version anomaly readable-stream 2.3.8
Environment variable access readable-stream 2.3.8
Chronological version anomaly rxjs 7.8.1
Chronological version anomaly pako 0.2.9
Dynamic require pako 0.2.9
Minified code pako 0.2.9
No v1 pako 0.2.9
Unmaintained pako 0.2.9
  • Last Publish: 11/7/2022, 1:02:09 AM
Chronological version anomaly inquirer 8.2.6
Chronological version anomaly js-base64 2.6.4
Major refactor js-base64 2.6.4
  • Change Percentage: 90.46
  • Current Line Count: 249
  • Previous Line Count: 4374
  • Lines Changed: 4182
Chronological version anomaly acorn 7.4.1
Chronological version anomaly got 11.8.6
Filesystem access got 11.8.6
Network access got 11.8.6
Chronological version anomaly @types/cacheable-request 6.0.3
Unmaintained @types/cacheable-request 6.0.3
  • Last Publish: 11/23/2022, 6:19:37 PM
Chronological version anomaly @oclif/core 1.26.2
Dynamic require @oclif/core 1.26.2
Environment variable access @oclif/core 1.26.2
Filesystem access @oclif/core 1.26.2
Network access @oclif/core 1.26.2
CVE node-fetch 1.7.3
Mild CVE node-fetch 1.7.3
Network access node-fetch 1.7.3
Network access node-fetch 2.7.0
Debug access brfs 1.6.1
Filesystem access brfs 1.6.1
Shell access brfs 1.6.1
Unmaintained brfs 1.6.1
  • Last Publish: 2/19/2019, 3:57:43 PM
Dynamic require cardinal 2.1.1
Filesystem access cardinal 2.1.1
Unmaintained cardinal 2.1.1
  • Last Publish: 5/22/2018, 5:44:37 PM
Dynamic require ejs 3.1.9
Environment variable access ejs 3.1.9
Filesystem access ejs 3.1.9
Major refactor ejs 3.1.9
  • Change Percentage: 101.40
  • Current Line Count: 3009
  • Previous Line Count: 2980
  • Lines Changed: 6073
Uses eval ejs 3.1.9
Dynamic require escodegen 1.14.3
Filesystem access escodegen 1.14.3
Dynamic require escodegen 1.9.1
Filesystem access escodegen 1.9.1
Dynamic require jake 10.8.7
Environment variable access jake 10.8.7
Filesystem access jake 10.8.7
Major refactor jake 10.8.7
  • Change Percentage: 100.79
  • Current Line Count: 5291
  • Previous Line Count: 5293
  • Lines Changed: 10668
Shell access jake 10.8.7
Environment variable access external-editor 3.1.0
Unmaintained external-editor 3.1.0
  • Last Publish: 7/8/2019, 4:07:13 PM
Environment variable access cli-width 3.0.0
Environment variable access password-prompt 1.1.3
Environment variable access ws 8.11.0
Environment variable access yaml 1.10.2
Filesystem access get-package-type 0.1.0
No v1 get-package-type 0.1.0
Unmaintained get-package-type 0.1.0
  • Last Publish: 5/19/2020, 9:28:37 AM
Filesystem access redeyed 2.1.1

Copy link

[Snyk] Fix for 2 vulnerabilities

Generated at commit: dc3f01f019d713b95ecceba773aee09f4b606629

🚨 Report Summary

Severity Level Results
Contracts Critical
High
Medium
Low
Note
Total
0
0
0
0
0
0
Dependencies Critical
High
Medium
Low
Note
Total
0
0
0
0
0
0

For more details view the full report in OpenZeppelin Code Inspector

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants