Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Snyk] Fix for 6 vulnerabilities #25

Open
wants to merge 1 commit into
base: main
Choose a base branch
from

Conversation

danielberman79
Copy link

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • package.json
    • package-lock.json

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
high severity 159/1000
Why? Confidentiality impact: None, Integrity impact: None, Availability impact: High, Scope: Unchanged, Exploit Maturity: Proof of Concept, User Interaction (UI): None, Privileges Required (PR): None, Attack Complexity: Low, Attack Vector: Network, EPSS: 0.00299, Social Trends: No, Days since published: 808, Reachable: No, Transitive dependency: Yes, Is Malicious: No, Business Criticality: High, Provider Urgency: High, Package Popularity Score: 99, Impact: 5.99, Likelihood: 2.65, Score Version: V5
Regular Expression Denial of Service (ReDoS)
SNYK-JS-ANSIREGEX-1583908
Yes Proof of Concept
high severity /1000
Why?
Command Injection
SNYK-JS-NEMOAPPIUM-3183747
No Proof of Concept
medium severity 118/1000
Why? Confidentiality impact: Low, Integrity impact: Low, Availability impact: None, Scope: Unchanged, Exploit Maturity: Proof of Concept, User Interaction (UI): None, Privileges Required (PR): None, Attack Complexity: Low, Attack Vector: Network, EPSS: 0.00063, Social Trends: No, Days since published: 257, Reachable: No, Transitive dependency: Yes, Is Malicious: No, Business Criticality: High, Provider Urgency: Medium, Package Popularity Score: 99, Impact: 4.19, Likelihood: 2.81, Score Version: V5
Server-side Request Forgery (SSRF)
SNYK-JS-REQUEST-3361831
No Proof of Concept
critical severity /1000
Why?
Heap-based Buffer Overflow
SNYK-JS-SHARP-5922108
No Mature
medium severity 118/1000
Why? Confidentiality impact: Low, Integrity impact: Low, Availability impact: None, Scope: Unchanged, Exploit Maturity: Proof of Concept, User Interaction (UI): None, Privileges Required (PR): None, Attack Complexity: Low, Attack Vector: Network, EPSS: 0.00173, Social Trends: No, Days since published: 152, Reachable: No, Transitive dependency: Yes, Is Malicious: No, Business Criticality: High, Provider Urgency: Medium, Package Popularity Score: 99, Impact: 4.19, Likelihood: 2.81, Score Version: V5
Prototype Pollution
SNYK-JS-TOUGHCOOKIE-5672873
No Proof of Concept
high severity 115/1000
Why? Confidentiality impact: None, Integrity impact: None, Availability impact: High, Scope: Unchanged, Exploit Maturity: No data, User Interaction (UI): None, Privileges Required (PR): None, Attack Complexity: Low, Attack Vector: Network, EPSS: 0.01055, Social Trends: No, Days since published: 653, Reachable: No, Transitive dependency: Yes, Is Malicious: No, Business Criticality: High, Provider Urgency: High, Package Popularity Score: 99, Impact: 5.99, Likelihood: 1.92, Score Version: V5
Prototype Pollution
SNYK-JS-UNSETVALUE-2400660
Yes No Known Exploit

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: check-dependencies The new version differs by 61 commits.

See the full diff

Package name: grunt-contrib-compress The new version differs by 5 commits.

See the full diff

Package name: nemo-appium The new version differs by 4 commits.

See the full diff

Package name: sharp The new version differs by 250 commits.
  • eefaa99 Release v0.32.6
  • dbce6fa Upgrade to libvips v8.14.5
  • af0fcb3 Docs: changelog for #3799
  • c6f54e5 Bump devDeps
  • 846563e TypeScript: add definitions for block and unblock (#3799)
  • 9c217ab Ensure withMetadata can add RGB16 profiles #3773
  • e7381e5 Alternative fix for 4340d60, uses existing StaySequential
  • 4340d60 Ensure composite tile images fully decoded #3767
  • 7f64d46 Docs: add missing returns property to raw
  • 67e927b Docs: ensure all functions include method signature #3777
  • 9c7713e Docs: remove mention of EXIF from flip/flop ops
  • 8be6da1 Docs: clarify when rotate op will remove EXIF Orientation
  • 9563568 Ensure withMetadata skips default profile for RGB16 #3773
  • 44a0ee3 Release v0.32.5
  • ccd51c8 Upgrade to libvips v8.14.4
  • bb7469b Ensure withMetadata adds default sRGB profile #3761
  • a2cac61 Simplify 90/270 orient-before-resize logic (#3762)
  • 5c19f6d Ensure resize fit=inside respects 90/270 rotate #3756
  • 3d01775 Docs: changelog entries for #3748 #3755 #3758
  • 87562a5 TypeScript: Ensure WebpOptions minSize is boolean (#3758)
  • 2829e17 Fix build with musl 1.2.4 (#3755)
  • ffefbd2 TypeScript: add missing WebpPresetEnum (#3748)
  • bc8f983 Tests: ensure Jimp benchmark uses bicubic as resizing kernel (#3745)
  • 440936a Tests: update benchmark deps and container (#3744)

See the full diff

Package name: sqlite3 The new version differs by 44 commits.

See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Regular Expression Denial of Service (ReDoS)
🦉 Server-side Request Forgery (SSRF)
🦉 Prototype Pollution

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants