-
Notifications
You must be signed in to change notification settings - Fork 22
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
- Loading branch information
Showing
1 changed file
with
2 additions
and
2 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
|
@@ -5,7 +5,7 @@ | |
{"value":"abab","children":{"ID":"abab (deprecation)","Issue":"Use your platform's native atob() and btoa() methods instead","Severity":"moderate","Vulnerable Versions":"2.0.6","Tree Versions":["2.0.6"],"Dependents":["jsdom@virtual:145e7af5a4eef7edc3b5342155c9759e46fd272a65da8c54e71e3a726711ad979907e1887a3fdcf00ecab676547214a60ab3eeb7f8437d187eab031c26d7a1bb#npm:20.0.3"]}} | ||
{"value":"are-we-there-yet","children":{"ID":"are-we-there-yet (deprecation)","Issue":"This package is no longer supported.","Severity":"moderate","Vulnerable Versions":"3.0.1","Tree Versions":["3.0.1"],"Dependents":["npmlog@npm:6.0.2"]}} | ||
{"value":"boolean","children":{"ID":"boolean (deprecation)","Issue":"Package no longer supported. Contact Support at https://www.npmjs.com/support for more info.","Severity":"moderate","Vulnerable Versions":"3.2.0","Tree Versions":["3.2.0"],"Dependents":["global-agent@npm:2.2.0"]}} | ||
{"value":"chromedriver","children":{"ID":1094902,"Issue":"chromedriver Command Injection vulnerability","URL":"https://github.com/advisories/GHSA-hm92-vgmw-qfmx","Severity":"moderate","Vulnerable Versions":"<119.0.1","Tree Versions":["116.0.0"],"Dependents":["accessibility-checker@npm:3.1.73"]}} | ||
{"value":"chromedriver","children":{"ID":1094902,"Issue":"chromedriver Command Injection vulnerability","URL":"https://github.com/advisories/GHSA-hm92-vgmw-qfmx","Severity":"moderate","Vulnerable Versions":"<119.0.1","Tree Versions":["116.0.0"],"Dependents":["accessibility-checker@npm:3.1.79"]}} | ||
{"value":"cookie","children":{"ID":1099846,"Issue":"cookie accepts cookie name, path, and domain with out of bounds characters","URL":"https://github.com/advisories/GHSA-pxg6-pf52-xh8x","Severity":"low","Vulnerable Versions":"<0.7.0","Tree Versions":["0.4.0"],"Dependents":["csurf@npm:1.11.0"]}} | ||
{"value":"cross-spawn","children":{"ID":1100563,"Issue":"Regular Expression Denial of Service (ReDoS) in cross-spawn","URL":"https://github.com/advisories/GHSA-3xgq-45jj-v275","Severity":"high","Vulnerable Versions":">=7.0.0 <7.0.5","Tree Versions":["7.0.3"],"Dependents":["dotenv-extended@npm:2.9.0"]}} | ||
{"value":"csurf","children":{"ID":"csurf (deprecation)","Issue":"Please use another csrf package","Severity":"moderate","Vulnerable Versions":"1.11.0","Tree Versions":["1.11.0"],"Dependents":["rpx-exui@workspace:."]}} | ||
|
@@ -28,7 +28,7 @@ | |
{"value":"npmlog","children":{"ID":"npmlog (deprecation)","Issue":"This package is no longer supported.","Severity":"moderate","Vulnerable Versions":"6.0.2","Tree Versions":["6.0.2"],"Dependents":["node-gyp@npm:9.4.0"]}} | ||
{"value":"passport","children":{"ID":1093639,"Issue":"Passport vulnerable to session regeneration when a users logs in or out","URL":"https://github.com/advisories/GHSA-v923-w3x8-wh69","Severity":"moderate","Vulnerable Versions":"<0.6.0","Tree Versions":["0.5.3"],"Dependents":["@hmcts/rpx-xui-node-lib@npm:2.30.2"]}} | ||
{"value":"protractor","children":{"ID":"protractor (deprecation)","Issue":"We have news to share - Protractor is deprecated and will reach end-of-life by Summer 2023. To learn more and find out about other options please refer to this post on the Angular blog. Thank you for using and contributing to Protractor. https://goo.gle/state-of-e2e-in-angular","Severity":"moderate","Vulnerable Versions":"7.0.0","Tree Versions":["7.0.0"],"Dependents":["protractor-screenshot-utils@virtual:478250b179e2f7a41962cb81e8de022adafb1a3a18c5c9a01a14fbfc1b28d5290463c48c9e2b547a1f1c34dc9b7b468a7fcd7685a99bff9367385d59331a4cd4#npm:1.0.6"]}} | ||
{"value":"puppeteer","children":{"ID":"puppeteer (deprecation)","Issue":"< 22.8.2 is no longer supported","Severity":"moderate","Vulnerable Versions":"13.7.0","Tree Versions":["13.7.0"],"Dependents":["accessibility-checker@npm:3.1.73"]}} | ||
{"value":"puppeteer","children":{"ID":"puppeteer (deprecation)","Issue":"< 22.8.2 is no longer supported","Severity":"moderate","Vulnerable Versions":"13.7.0","Tree Versions":["13.7.0"],"Dependents":["accessibility-checker@npm:3.1.79"]}} | ||
{"value":"q","children":{"ID":"q (deprecation)","Issue":"You or someone you depend on is using Q, the JavaScript Promise library that gave JavaScript developers strong feelings about promises. They can almost certainly migrate to the native JavaScript promise now. Thank you literally everyone for joining me in this bet against the odds. Be excellent to each other.\n\n(For a CapTP with native promises, see @endo/eventual-send and @endo/captp)","Severity":"moderate","Vulnerable Versions":"1.5.1","Tree Versions":["1.5.1"],"Dependents":["webdriver-manager@npm:12.1.9"]}} | ||
{"value":"reflect-metadata","children":{"ID":"reflect-metadata (deprecation)","Issue":"This version has a critical bug in fallback handling. Please upgrade to [email protected] or newer.","Severity":"moderate","Vulnerable Versions":"0.2.1","Tree Versions":["0.2.1"],"Dependents":["@cucumber/messages@npm:24.1.0"]}} | ||
{"value":"request","children":{"ID":1096727,"Issue":"Server-Side Request Forgery in Request","URL":"https://github.com/advisories/GHSA-p8p7-x288-28g6","Severity":"moderate","Vulnerable Versions":"<=2.88.2","Tree Versions":["2.88.2"],"Dependents":["webdriver-manager@npm:12.1.9"]}} | ||
|