Skip to content

[Snyk] Fix for 18 vulnerabilities - #6

Open
snyk-bot wants to merge 1 commit into
masterfrom
snyk-fix-393d3932ac61dd1ce13c8152a94a87e0
Open

[Snyk] Fix for 18 vulnerabilities#6
snyk-bot wants to merge 1 commit into
masterfrom
snyk-fix-393d3932ac61dd1ce13c8152a94a87e0

Conversation

@snyk-bot

@snyk-bot snyk-bot commented Feb 3, 2020

Copy link
Copy Markdown

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • package.json

Vulnerabilities that will be fixed

With an upgrade:
Severity Issue Breaking Change Exploit Maturity
high severity Prototype Pollution
SNYK-JS-LODASH-450202
No Proof of Concept
high severity Prototype Pollution
SNYK-JS-LODASH-73638
No No Known Exploit
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-LODASH-73639
No No Known Exploit
medium severity Cross-site Scripting (XSS)
npm:connect:20130701
No No Known Exploit
medium severity Non-Constant Time String Comparison
npm:cookie-signature:20160804
No No Known Exploit
medium severity Cross-site Scripting (XSS)
npm:express:20140912
No No Known Exploit
high severity Prototype Pollution
npm:extend:20180424
Yes No Known Exploit
high severity Regular Expression Denial of Service (ReDoS)
npm:fresh:20170908
Yes No Known Exploit
medium severity Prototype Pollution
npm:lodash:20180130
No No Known Exploit
low severity Regular Expression Denial of Service (ReDoS)
npm:mime:20170907
Yes No Known Exploit
high severity Regular Expression Denial of Service (DoS)
npm:minimatch:20160620
Yes No Known Exploit
high severity Denial of Service (Memory Exhaustion)
npm:qs:20140806
No No Known Exploit
medium severity Denial of Service (Event Loop Blocking)
npm:qs:20140806-1
No No Known Exploit
high severity Prototype Override Protection Bypass
npm:qs:20170213
Yes No Known Exploit
medium severity Directory Traversal
npm:send:20140912
Yes No Known Exploit
medium severity Root Path Disclosure
npm:send:20151103
Yes No Known Exploit
low severity Denial of Service (DoS)
npm:superagent:20170807
Yes No Known Exploit
medium severity Information Exposure
npm:superagent:20181108
Yes No Known Exploit
Commit messages
Package name: glob The new version differs by 168 commits.
  • 3a7e71d v5.0.15
  • 841fda0 use latest minimatch
  • 4ba54a8 Skip some tests on Windows, make others pass
  • 3936e1e Build: Add build for node v4
  • c47d451 v5.0.14
  • 821fac8 Handle ENOTSUP for sync glob as well as async
  • 9625618 Test for when readdir raises ENOTSUP
  • 0a2b519 Generate fixtures more effectively, with -O instead of eval
  • f96190b Use js for benchmark cleanup
  • 957fd93 Fix some 'use strict' errors
  • bf3381e Treat ENOTSUP like ENOTDIR in readdir
  • 507733d v5.0.13
  • f5878af Do not emit 'match' events for ignored items
  • 9439afd v5.0.12
  • 6071f3a Revert "Use graceful-fs if available"
  • 38ff16c v5.0.11
  • f09292b Use graceful-fs if available
  • 4f39b60 Remove duplicate option description
  • e3cdccc v5.0.10
  • 480da05 ignore .nyc_output, upgrade tap, use coverage, rm fixtures
  • 155124b add more sync cb thrower tests
  • f7302ca Test base-matching
  • 7530e88 v5.0.9
  • b185987 reduce cases where tests need to be regenerated

See the full diff

Package name: minimatch The new version differs by 10 commits.
  • 81edb7c v3.0.2
  • 6944abf Handle extremely long and terrible patterns more gracefully
  • 8ac560e v3.0.1
  • 4f3a8bc update tap
  • 9cf2d88 Remove mentions of cache from readme
  • 7df236f Use svg instead of png to get better image quality
  • 361f803 Fixes spelling mistake from "instanting" to "instantiating"
  • ea0c690 update travis
  • 270dbea v3.0.0
  • 668a1f4 Don't package browser version

See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:

🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant