Skip to content

[Snyk] Fix for 32 vulnerabilities - #1

Open
cdegraftjohnson wants to merge 1 commit into
masterfrom
snyk-fix-d2f082ed4756c9b5ee637eba2e47572f
Open

cdegraftjohnson wants to merge 1 commit into
masterfrom
snyk-fix-d2f082ed4756c9b5ee637eba2e47572f

Conversation

@cdegraftjohnson

Copy link
Copy Markdown
Owner

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • package.json
    • package-lock.json

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
high severity 696/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
Regular Expression Denial of Service (ReDoS)
SNYK-JS-ANSIREGEX-1583908
Yes Proof of Concept
high severity 696/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
Regular Expression Denial of Service (ReDoS)
SNYK-JS-AXIOS-1579269
No Proof of Concept
high severity 748/1000
Why? Proof of Concept exploit, Recently disclosed, Has a fix available, CVSS 7.1
Cross-site Request Forgery (CSRF)
SNYK-JS-AXIOS-6032459
Yes Proof of Concept
medium severity 591/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 5.4
Cross-site Scripting (XSS)
SNYK-JS-BRAINTREESANITIZEURL-2339882
Yes Proof of Concept
medium severity 484/1000
Why? Has a fix available, CVSS 5.4
Cross-site Scripting (XSS)
SNYK-JS-BRAINTREESANITIZEURL-3330766
Yes No Known Exploit
medium severity 586/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 5.3
Regular Expression Denial of Service (ReDoS)
SNYK-JS-BROWSERSLIST-1090194
Yes Proof of Concept
medium severity 479/1000
Why? Has a fix available, CVSS 5.3
Regular Expression Denial of Service (ReDoS)
SNYK-JS-CSSWHAT-1298035
Yes No Known Exploit
medium severity 586/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 5.3
Regular Expression Denial of Service (ReDoS)
SNYK-JS-D3COLOR-1076592
Yes Proof of Concept
medium severity 526/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 4.1
Arbitrary Code Injection
SNYK-JS-EJS-1049328
Yes Proof of Concept
high severity 726/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 8.1
Remote Code Execution (RCE)
SNYK-JS-EJS-2803307
Yes Proof of Concept
medium severity 646/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 6.5
Information Exposure
SNYK-JS-EVENTSOURCE-2823375
No Proof of Concept
medium severity 586/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 5.3
Regular Expression Denial of Service (ReDoS)
SNYK-JS-GLOBPARENT-1016905
Yes Proof of Concept
medium severity 504/1000
Why? Has a fix available, CVSS 5.8
Prototype Pollution
SNYK-JS-HIGHLIGHTJS-1045326
Yes No Known Exploit
medium severity 479/1000
Why? Has a fix available, CVSS 5.3
Regular Expression Denial of Service (ReDoS)
SNYK-JS-HIGHLIGHTJS-1048676
Yes No Known Exploit
medium severity 601/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 5.6
Prototype Pollution
SNYK-JS-IMMER-1540542
Yes Proof of Concept
medium severity 479/1000
Why? Has a fix available, CVSS 5.3
Regular Expression Denial of Service (ReDoS)
SNYK-JS-LOADERUTILS-3042992
Yes No Known Exploit
high severity 589/1000
Why? Has a fix available, CVSS 7.5
Prototype Pollution
SNYK-JS-LOADERUTILS-3043105
Yes No Known Exploit
medium severity 479/1000
Why? Has a fix available, CVSS 5.3
Regular Expression Denial of Service (ReDoS)
SNYK-JS-LOADERUTILS-3105943
Yes No Known Exploit
medium severity 479/1000
Why? Has a fix available, CVSS 5.3
Regular Expression Denial of Service (ReDoS)
SNYK-JS-MINIMATCH-3050818
Yes No Known Exploit
medium severity 424/1000
Why? Has a fix available, CVSS 4.2
Information Exposure
SNYK-JS-MONGODB-5871303
No No Known Exploit
medium severity 521/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 4
Information Exposure
SNYK-JS-NANOID-2332193
No Proof of Concept
high severity 696/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
Regular Expression Denial of Service (ReDoS)
SNYK-JS-NTHCHECK-1586032
Yes Proof of Concept
medium severity 454/1000
Why? Has a fix available, CVSS 4.8
Session Fixation
SNYK-JS-PASSPORT-2840631
No No Known Exploit
medium severity 479/1000
Why? Has a fix available, CVSS 5.3
Improper Input Validation
SNYK-JS-POSTCSS-5926692
Yes No Known Exploit
high severity 696/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
Regular Expression Denial of Service (ReDoS)
SNYK-JS-PRISMJS-1076581
Yes Proof of Concept
high severity 584/1000
Why? Has a fix available, CVSS 7.4
Regular Expression Denial of Service (ReDoS)
SNYK-JS-PRISMJS-1314893
Yes No Known Exploit
high severity 696/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
Regular Expression Denial of Service (ReDoS)
SNYK-JS-PRISMJS-1585202
Yes Proof of Concept
medium severity 484/1000
Why? Has a fix available, CVSS 5.4
Cross-site Scripting (XSS)
SNYK-JS-PRISMJS-2404333
Yes No Known Exploit
high severity 629/1000
Why? Has a fix available, CVSS 8.3
Cross-site Scripting (XSS)
SNYK-JS-PRISMJS-597628
Yes No Known Exploit
medium severity 586/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 5.3
Regular Expression Denial of Service (ReDoS)
SNYK-JS-PROMPTS-1729737
Yes Proof of Concept
high severity 696/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
Regular Expression Denial of Service (ReDoS)
SNYK-JS-SEMVER-3247795
Yes Proof of Concept
high severity 619/1000
Why? Has a fix available, CVSS 8.1
Remote Code Execution (RCE)
SNYK-JS-SHELLQUOTE-1766506
Yes No Known Exploit

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: @reduxjs/toolkit The new version differs by 250 commits.
  • 8910a61 1.6.0
  • b718e01 Merge pull request #1016 from reduxjs/feature/v1.6-integration
  • 034bdec Merge branch 'master' into feature/v1.6-integration
  • 17d4629 Merge pull request #1140 from reduxjs/docs/rtkq-exports
  • dac5b00 Remove legacy RTKQ incubator files
  • 4a1d92f Add API docs for miniSerializeError and copyWithStructuralSharing
  • bdc4e3f Merge pull request #1115 from Shrugsy/docs/dynamic-base-url-example-snippet
  • 0075ca9 Merge pull request #1138 from reduxjs/docs/final-rtkq-cleanup
  • f9f85c7 add TS 4.3 to test matrix, disable `strictOptionalProperties` for TS4.4 (#1137)
  • 9e76b6b Add NgRx interop links
  • 64eeee8 Merge branch 'feature/v1.6-integration' into docs/final-rtkq-cleanup
  • b3eee1c Merge pull request #1136 from reduxjs/example-chores
  • 64ffe4b Lots more docs cleanup!
  • c50cf53 fixup examples
  • b1dc9e1 chores: move examples to current RC
  • 13d57c6 Show sandboxes as run-on-click
  • 0c04f42 Expand Query/Mutation descriptions and clarify TS usage
  • 72f9332 Clean up grammar
  • a31e3c5 Add RTQK navbar / footer links
  • c2c4f51 Add additional RTKQ comparison and intro material
  • 4cfdf8a Merge pull request #1135 from Shrugsy/docs/clarify-query-loading-states
  • f94e9d3 📝 Clarify query loading states
  • 037e772 Merge pull request #1133 from Shrugsy/docs/extend-onQueryStarted-documentation
  • ead8694 * change get/update singular post example

See the full diff

Package name: axios The new version differs by 250 commits.
  • f7adacd chore(release): v1.6.0 (#6031)
  • 9917e67 chore(ci): fix release-it arg; (#6032)
  • 96ee232 fix(CSRF): fixed CSRF vulnerability CVE-2023-45857 (#6028)
  • 7d45ab2 chore(tests): fixed tests to pass in node v19 and v20 with `keep-alive` enabled; (#6021)
  • 5aaff53 fix(dns): fixed lookup function decorator to work properly in node v20; (#6011)
  • a48a63a chore(docs): added AxiosHeaders docs; (#5932)
  • a1c8ad0 fix(types): fix AxiosHeaders types; (#5931)
  • 2ac731d chore(docs): update readme.md (#5889)
  • 88fb52b chore(release): v1.5.1 (#5920)
  • e410779 fix(adapters): improved adapters loading logic to have clear error messages; (#5919)
  • bc9af51 fix(formdata): fixed automatic addition of the `Content-Type` header for FormData in non-browser environments; (#5917)
  • 4c89f25 fix(headers): allow `content-encoding` header to handle case-insensitive values (#5890) (#5892)
  • ae00391 docs(paramsSerializer config within request config): update documentation for paramsSerializer
  • a989ccd Change isNaN to Number.isNaN
  • b5b7760 docs: fix CommonJS usage note
  • 9e62056 fix(types): removed duplicated code
  • 6365751 chore(release): v1.5.0 (#5838)
  • 1601f4a feat(export): export adapters without `unsafe` prefix (#5839)
  • dff74ae docs: linting documentation notes (#5791)
  • ca73eb8 feat: export getAdapter function (#5324)
  • 9a414bb fix(adapter): make adapter loading error more clear by using platform-specific adapters explicitly (#5837)
  • b3e327d fix(dns): fixed `cacheable-lookup` integration; (#5836)
  • 8fda276 fix(headers): fixed common Content-Type header merging; (#5832)
  • d8b4ca0 fix(headers): added support for setting header names that overlap with class methods; (#5831)

See the full diff

Package name: eventsource The new version differs by 17 commits.

See the full diff

Package name: immer The new version differs by 68 commits.
  • fa671e5 fix(security): Follow up on CVE-2020-28477 where `path: [["__proto__"], "x"]` could still pollute the prototype
  • 2e0aa95 Create SECURITY.md
  • 050522d chore: fix CI. maybe.
  • 1195510 docs: Update example-setstate.mdx (#833)
  • 648d39b docs: fixing link to RFC-6902 & fixing typo (#830)
  • bc890f7 docs: Update example-setstate.mdx (#829)
  • 16a3d0f chore(deps): bump prismjs from 1.23.0 to 1.24.0 in /website (#822)
  • 847492c docs: Extended / updated documenation (#824)
  • 7f41483 chore: [workflows] don't release from forks
  • 3f9a94e chore: let's test before publish
  • bfb8dec fix: release missing dist/ folder
  • b314b19 chore: fix cpx usage
  • a607d6c chore: Remove old shizzle
  • 6fd5329 chore: fixes for deploy preview
  • 144f886 chore: fix docs deployment attempt 3
  • 38964fa chore: semantic-release + GH actions
  • 06c6741 chore: fix docs deploy
  • ad23da9 chore: fix test job
  • b6d92f4 chore: publish docs automatically
  • c59576a chore: setup GH action for test
  • dc3f66c fix: #807 new undefined properties should end up in result object
  • 5412c9f fix: #791 return 'nothing' should produce undefined patch
  • 58b74a6 chore(deps): bump ssri from 6.0.1 to 6.0.2 in /website (#818)
  • c9deb48 chore(deps): bump color-string from 1.5.4 to 1.5.5 in /website (#817)

See the full diff

Package name: mongodb The new version differs by 105 commits.
  • 1297cd1 chore(release): 3.6.10
  • e9196ab refactor(NODE-3324): bump max wire version to 13 (#2875)
  • 3ce148d fix(NODE-3397): report more helpful error with unsupported authMechanism in initial handshake (#2876)
  • 558182f test(NODE-3307): unified runner does not assert identical keys (#2867)
  • 621677a fix(NODE-3380): perform retryable write checks against server (#2861)
  • e4a9a57 fix(NODE-3150): added bsonRegExp option for v3.6 (#2843)
  • 750760c fix(NODE-3358): Command monitoring objects hold internal state references (#2858)
  • a917dfa fix(NODE-2035): Exceptions thrown from awaited cursor forEach do not propagate (#2852)
  • b98f206 refactor(NODE-3356): Update command monitoring logging (#2853)
  • 68b4665 test(NODE-2856): ensure defaultTransactionOptions get used from session (#2845)
  • 8c8b4c3 fix(NODE-3356): update redaction logic for command monitoring events (#2847)
  • 2c5d440 test(NODE-3357): extend timeout for atlas connectivity (#2846)
  • fd97808 test(NODE-3288): sync command-monitoring spec tests to 3.6 (#2838)
  • bf8b21b docs: change links to use https (#2836)
  • f42ac4c refactor(NODE-2752): deprecate strict option for Db.collection (#2819)
  • 394832a chore(release): 3.6.9
  • fac9610 fix(NODE-3309): remove redundant iteration of bulk write result (#2815)
  • 58c4e69 fix: fix url parsing for a mongodb+srv url that has commas in the database name (#2789)
  • 6c8cc84 chore(release): 3.6.8
  • 6e3bab3 fix(cmap): undo flipping of `beforeHandshake` flag for timeout errors (#2813)
  • 4fd03e8 chore(release): 3.6.7
  • 6ceace6 fix(NODE-3192): check clusterTime is defined before access (#2806)
  • 1967515 test(NODE-3187): port unified test runner (#2783)
  • 5d8f649 fix(NODE-3252): state transistion from DISCONNECTED (#2807)

See the full diff

Package name: passport The new version differs by 100 commits.

See the full diff

Package name: react-flow-renderer The new version differs by 250 commits.
  • 2496a6e Merge branch 'main' of github.com:wbkd/react-flow into main
  • d480d25 refactor(controls): use button element for buttons instead of divs closes #1228
  • 290ba99 chore(deps): update
  • d8c88ee Merge pull request #1258 from wbkd/dependabot/npm_and_yarn/main/babel/preset-react-7.14.5
  • d24c58e Merge pull request #1259 from wbkd/dependabot/npm_and_yarn/main/d3-selection-3.0.0
  • fea40ae Merge pull request #1260 from wbkd/dependabot/npm_and_yarn/main/babel/runtime-7.14.5
  • 0fc9906 Merge pull request #1261 from wbkd/dependabot/npm_and_yarn/main/postcss-8.3.2
  • 0afbe8c chore(deps-dev): bump postcss from 8.3.0 to 8.3.2
  • ce0fe50 chore(deps): bump @ babel/runtime from 7.14.0 to 7.14.5
  • b1cf3d8 chore(deps): bump d3-selection from 2.0.0 to 3.0.0
  • 23b971d chore(deps-dev): bump @ babel/preset-react from 7.13.13 to 7.14.5
  • c956ac2 chore: release v9.6.0
  • 27e2781 feat(props): add onEdgeUpdateEnd handler closes #1157
  • f244e77 chore: release v9.5.5
  • 3124d46 refactor(edge-updater): pass handle type #1212
  • 6451099 fix(layouting): update node dimensions closes #1181
  • f835f85 chore(deps): update
  • cc0a837 chore(example): remove unused func
  • ba6b0b8 chore(deps): update
  • 0950e52 Merge pull request #1171 from wbkd/dependabot/npm_and_yarn/main/rollup/plugin-commonjs-18.1.0
  • d4e4a1c chore(deps-dev): bump @ rollup/plugin-commonjs from 18.0.0 to 18.1.0
  • 1c5bfd7 Merge pull request #1172 from wbkd/dependabot/npm_and_yarn/main/rollup/plugin-node-resolve-13.0.0
  • b36154a Merge pull request #1173 from wbkd/dependabot/npm_and_yarn/main/rollup-2.47.0
  • 0950422 chore(deps-dev): bump rollup from 2.46.0 to 2.47.0

See the full diff

Package name: react-scripts The new version differs by 113 commits.
  • 221e511 Publish
  • 6a3315b Update CONTRIBUTING.md
  • 5614c87 Add support for Tailwind (#11717)
  • 657739f chore(test): make all tests install with `npm ci` (#11723)
  • 20edab4 fix(webpackDevServer): disable overlay for warnings (#11413)
  • 69321b0 Remove cached lockfile (#11706)
  • 3afbbc0 Update all dependencies (#11624)
  • f5467d5 feat(eslint-config-react-app): support ESLint 8.x (#11375)
  • e8319da [WIP] Fix integration test teardown / cleanup and missing yarn installation (#11686)
  • c7627ce Update webpack and dev server (#11646)
  • f85b064 The default port used by `serve` has changed (#11619)
  • 544befe Update package.json (#11597)
  • 9d0369b Fix ESLint Babel preset resolution (#11547)
  • d7b23c8 test(create-react-app): assert for exit code (#10973)
  • 1465357 Prepare 5.0.0 alpha release
  • 3880ba6 Remove dependency pinning (#11474)
  • 8b9fbee Update CODEOWNERS
  • cacf590 Bump template dependency version (#11415)
  • 5cedfe4 Bump browserslist from 4.14.2 to 4.16.5 (#11476)
  • 50ea5ad allow CORS on webpack-dev-server (#11325)
  • 63bba07 Upgrade jest and related packages from 26.6.0 to 27.1.0 (#11338)
  • 960b21e Bump immer from 8.0.4 to 9.0.6 (#11364)
  • 134cd3c Resolve dependency issues in v5 alpha (#11294)
  • b45ae3c Update CONTRIBUTING.md

See the full diff

Package name: react-syntax-highlighter The new version differs by 112 commits.

See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Regular Expression Denial of Service (ReDoS)
🦉 Cross-site Request Forgery (CSRF)
🦉 Cross-site Scripting (XSS)
🦉 More lessons are available in Snyk Learn

The following vulnerabilities are fixed with an upgrade:
- https://snyk.io/vuln/SNYK-JS-ANSIREGEX-1583908
- https://snyk.io/vuln/SNYK-JS-AXIOS-1579269
- https://snyk.io/vuln/SNYK-JS-AXIOS-6032459
- https://snyk.io/vuln/SNYK-JS-BRAINTREESANITIZEURL-2339882
- https://snyk.io/vuln/SNYK-JS-BRAINTREESANITIZEURL-3330766
- https://snyk.io/vuln/SNYK-JS-BROWSERSLIST-1090194
- https://snyk.io/vuln/SNYK-JS-CSSWHAT-1298035
- https://snyk.io/vuln/SNYK-JS-D3COLOR-1076592
- https://snyk.io/vuln/SNYK-JS-EJS-1049328
- https://snyk.io/vuln/SNYK-JS-EJS-2803307
- https://snyk.io/vuln/SNYK-JS-EVENTSOURCE-2823375
- https://snyk.io/vuln/SNYK-JS-GLOBPARENT-1016905
- https://snyk.io/vuln/SNYK-JS-HIGHLIGHTJS-1045326
- https://snyk.io/vuln/SNYK-JS-HIGHLIGHTJS-1048676
- https://snyk.io/vuln/SNYK-JS-IMMER-1540542
- https://snyk.io/vuln/SNYK-JS-LOADERUTILS-3042992
- https://snyk.io/vuln/SNYK-JS-LOADERUTILS-3043105
- https://snyk.io/vuln/SNYK-JS-LOADERUTILS-3105943
- https://snyk.io/vuln/SNYK-JS-MINIMATCH-3050818
- https://snyk.io/vuln/SNYK-JS-MONGODB-5871303
- https://snyk.io/vuln/SNYK-JS-NANOID-2332193
- https://snyk.io/vuln/SNYK-JS-NTHCHECK-1586032
- https://snyk.io/vuln/SNYK-JS-PASSPORT-2840631
- https://snyk.io/vuln/SNYK-JS-POSTCSS-5926692
- https://snyk.io/vuln/SNYK-JS-PRISMJS-1076581
- https://snyk.io/vuln/SNYK-JS-PRISMJS-1314893
- https://snyk.io/vuln/SNYK-JS-PRISMJS-1585202
- https://snyk.io/vuln/SNYK-JS-PRISMJS-2404333
- https://snyk.io/vuln/SNYK-JS-PRISMJS-597628
- https://snyk.io/vuln/SNYK-JS-PROMPTS-1729737
- https://snyk.io/vuln/SNYK-JS-SEMVER-3247795
- https://snyk.io/vuln/SNYK-JS-SHELLQUOTE-1766506
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants