Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Snyk] Fix for 2 vulnerabilities #90

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

djantaio
Copy link
Owner

@djantaio djantaio commented Oct 8, 2024

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • package.json
    • package-lock.json

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
medium severity 601/1000
Why? Recently disclosed, Has a fix available, CVSS 6.3
Cross-site Scripting (XSS)
SNYK-JS-COOKIE-8163060
Yes No Known Exploit
high severity 828/1000
Why? Proof of Concept exploit, Recently disclosed, Has a fix available, CVSS 8.7
Prototype Pollution
SNYK-JS-WHETEXTEND-3178372
Yes Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: css-loader The new version differs by 9 commits.
  • 43179a8 chore(release): 1.0.0
  • 3d53968 Merge remote-tracking branch 'origin/master'
  • 240db53 version 1.0 (#742)
  • 1b7acf7 Merge remote-tracking branch 'origin/master'
  • 1703721 docs(README): add more context to `localIdentName` (#711)
  • 1c51265 docs(README): fix malformed emoji (#701)
  • 50f8ec0 Merge remote-tracking branch 'origin/master'
  • 07444ad tests: css custom variables (#709)
  • 3de8aa7 tests: css custom variables (#709)

See the full diff

Package name: webpack-bundle-analyzer The new version differs by 250 commits.
  • fb77b1b v4.3.0
  • d8cfba7 Merge pull request #404 from webpack-contrib/dependabot/npm_and_yarn/ini-1.3.7
  • fbd8a17 Bump ini from 1.3.5 to 1.3.7
  • 2d12514 Merge pull request #402 from webpack-contrib/github-actions
  • d701153 Use Node.js as name
  • fdb5a0e Add custom name for build-and-test
  • 6e6c3e8 Remove Travis CI
  • 1adc58f Only trigger GitHub actions on direct pushes to master
  • 6c46bad Run tests with gabrielbb/xvfb-action
  • bb74281 Setup GitHub actions to run tests and lint
  • 9b84418 Mention #401 in changelog
  • fcc577c Merge pull request #401 from realityking/filesize
  • 8de9dae Move filesize to dev depnendencies
  • d54a8d0 Mention #398 in changelog
  • 9096227 Merge pull request #398 from TrySound/drop-express
  • 0f70814 Drop static-serve, add comment
  • ab9f23d Switch to sirv
  • b30784d Remove viewsRoot
  • 776ecb7 Add missing require
  • 4a674c4 Replace express with builtin node server
  • 313fac1 v4.2.0
  • 302df4f Merge pull request #397 from realityking/templates
  • 084cc02 Add changelog entry
  • 11e4db1 fix syntax error

See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Cross-site Scripting (XSS)
🦉 Prototype Pollution

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants