-
Notifications
You must be signed in to change notification settings - Fork 54
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[Snyk] Fix for 41 vulnerabilities #389
base: master
Are you sure you want to change the base?
Conversation
The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-JS-IP-6240864 - https://snyk.io/vuln/SNYK-JS-LODASH-567746 - https://snyk.io/vuln/SNYK-JS-HANDLEBARS-534478 - https://snyk.io/vuln/SNYK-JS-PACRESOLVER-1564857 - https://snyk.io/vuln/SNYK-JS-NETMASK-1089716 - https://snyk.io/vuln/SNYK-JS-NETMASK-6056519 - https://snyk.io/vuln/SNYK-JS-HANDLEBARS-534988 - https://snyk.io/vuln/SNYK-JS-ANSIREGEX-1583908 - https://snyk.io/vuln/SNYK-JS-LODASH-6139239 - https://snyk.io/vuln/SNYK-JS-QS-3153490 - https://snyk.io/vuln/SNYK-JS-SEMVER-3247795 - https://snyk.io/vuln/SNYK-JS-INI-1048974 - https://snyk.io/vuln/SNYK-JS-LODASH-450202 - https://snyk.io/vuln/SNYK-JS-LODASH-608086 - https://snyk.io/vuln/SNYK-JS-LODASH-73638 - https://snyk.io/vuln/SNYK-JS-Y18N-1021887 - https://snyk.io/vuln/npm:deep-extend:20180409 - https://snyk.io/vuln/SNYK-JS-LODASH-1040724 - https://snyk.io/vuln/SNYK-JS-HANDLEBARS-1056767 - https://snyk.io/vuln/SNYK-JS-HANDLEBARS-567742 - https://snyk.io/vuln/SNYK-JS-IP-7148531 - https://snyk.io/vuln/SNYK-JS-REQUEST-3361831 - https://snyk.io/vuln/SNYK-JS-TOUGHCOOKIE-5672873 - https://snyk.io/vuln/SNYK-JS-JSONSCHEMA-1920922 - https://snyk.io/vuln/SNYK-JS-DOTPROP-543489 - https://snyk.io/vuln/npm:lodash:20180130 - https://snyk.io/vuln/SNYK-JS-HTTPSPROXYAGENT-469131 - https://snyk.io/vuln/SNYK-JS-AJV-584908 - https://snyk.io/vuln/SNYK-JS-HANDLEBARS-1279029 - https://snyk.io/vuln/SNYK-JS-MINIMIST-559764 - https://snyk.io/vuln/SNYK-JS-HANDLEBARS-480388 - https://snyk.io/vuln/SNYK-JS-HOSTEDGITINFO-1088355 - https://snyk.io/vuln/SNYK-JS-LODASH-1018905 - https://snyk.io/vuln/SNYK-JS-HANDLEBARS-173692 - https://snyk.io/vuln/SNYK-JS-HANDLEBARS-174183 - https://snyk.io/vuln/SNYK-JS-HANDLEBARS-469063 - https://snyk.io/vuln/SNYK-JS-LODASH-73639 - https://snyk.io/vuln/npm:brace-expansion:20170302 - https://snyk.io/vuln/SNYK-JS-MINIMIST-2429795 - https://snyk.io/vuln/npm:clean-css:20180306 - https://snyk.io/vuln/SNYK-JS-MINIMATCH-3050818
"once": "^1.3.2" | ||
} | ||
}, | ||
"npm": { |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Risk: npm 8.x before 8.11.0 is vulnerable to exposure of sensitive information to an unauthorized actor. The npm cli incorrectly ignores root-level .gitignore
and .npmignore
files when run in a workspace. Upgrade to npm 8.11.0.
Fix: Upgrade this library to at least version 8.11.0 at auth0-authorization-extension/package-lock.json:13572.
Reference(s): GHSA-hj9c-8jmm-8c52, CVE-2022-29244
Ignore this finding from ssc-d5d8f586-e6e9-42b3-8b5b-ab176a2efd4e."once": "^1.3.2" | ||
} | ||
}, | ||
"npm": { |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Risk: npm 8.x before 8.11.0 is vulnerable to exposure of sensitive information to an unauthorized actor. The npm cli incorrectly ignores root-level .gitignore
and .npmignore
files when run in a workspace. Upgrade to npm 8.11.0.
Fix: Upgrade this library to at least version 8.11.0 at auth0-authorization-extension/package-lock.json:13572.
Reference(s): GHSA-hj9c-8jmm-8c52, CVE-2022-29244
Ignore this finding from ssc-d5d8f586-e6e9-42b3-8b5b-ab176a2efd4e.
Snyk has created this PR to fix 41 vulnerabilities in the npm dependencies of this project.
Snyk changed the following file(s):
package.json
package-lock.json
Vulnerabilities that will be fixed with an upgrade:
SNYK-JS-IP-6240864
SNYK-JS-LODASH-567746
SNYK-JS-HANDLEBARS-534478
SNYK-JS-PACRESOLVER-1564857
SNYK-JS-NETMASK-1089716
SNYK-JS-NETMASK-6056519
SNYK-JS-HANDLEBARS-534988
SNYK-JS-ANSIREGEX-1583908
SNYK-JS-LODASH-6139239
SNYK-JS-QS-3153490
SNYK-JS-SEMVER-3247795
SNYK-JS-INI-1048974
SNYK-JS-LODASH-450202
SNYK-JS-LODASH-608086
SNYK-JS-LODASH-73638
SNYK-JS-Y18N-1021887
npm:deep-extend:20180409
SNYK-JS-LODASH-1040724
SNYK-JS-HANDLEBARS-1056767
SNYK-JS-HANDLEBARS-567742
SNYK-JS-IP-7148531
SNYK-JS-REQUEST-3361831
SNYK-JS-TOUGHCOOKIE-5672873
SNYK-JS-JSONSCHEMA-1920922
SNYK-JS-DOTPROP-543489
npm:lodash:20180130
SNYK-JS-HTTPSPROXYAGENT-469131
SNYK-JS-AJV-584908
SNYK-JS-HANDLEBARS-1279029
SNYK-JS-MINIMIST-559764
SNYK-JS-HANDLEBARS-480388
SNYK-JS-HOSTEDGITINFO-1088355
SNYK-JS-LODASH-1018905
SNYK-JS-HANDLEBARS-173692
SNYK-JS-HANDLEBARS-174183
SNYK-JS-HANDLEBARS-469063
SNYK-JS-LODASH-73639
npm:brace-expansion:20170302
SNYK-JS-MINIMIST-2429795
npm:clean-css:20180306
SNYK-JS-MINIMATCH-3050818
Important
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.
For more information:
🧐 View latest project report
📜 Customise PR templates
🛠 Adjust project settings
📚 Read about Snyk's upgrade logic
Learn how to fix vulnerabilities with free interactive lessons:
🦉 Prototype Pollution
🦉 Regular Expression Denial of Service (ReDoS)
🦉 Remote Code Execution (RCE)
🦉 More lessons are available in Snyk Learn