Skip to content
New issue

Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? # to your account

[Snyk] Fix for 1 vulnerabilities #30

Open
wants to merge 1 commit into
base: main
Choose a base branch
from

Conversation

giuseppealbrizio
Copy link
Owner

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

✨ Snyk has automatically assigned this pull request, set who gets assigned.

As this is a private repository, Snyk-bot does not have access. Therefore, this PR has been created automatically, but appears to have been created by a real user.

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • package.json
    • package-lock.json

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
medium severity 658/1000
Why? Proof of Concept exploit, Recently disclosed, Has a fix available, CVSS 5.3
Regular Expression Denial of Service (ReDoS)
SNYK-JS-AXIOS-6124857
No Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: @googlemaps/google-maps-services-js The new version differs by 34 commits.
  • 92a5b5a chore(release): 3.3.40 [skip ci]
  • a0d416b fix: only use pre-ESM dependencies (#1047)
  • dacfff6 build(deps): bump retry-axios from 2.6.0 to 3.1.0 (#1027)
  • c5c0990 chore: update all dependencies (#1044)
  • 9a5405f chore(release): 3.3.39 [skip ci]
  • fe1b7b8 build(deps-dev): bump @ types/node from 20.7.0 to 20.8.2 (#1043)
  • 218c66c build(deps-dev): bump @ types/node from 20.6.2 to 20.7.0 (#1041)
  • a2d68dd build(deps-dev): bump @ types/node from 20.6.0 to 20.6.2 (#1036)
  • 0b8bb3f chore(release): 3.3.38 [skip ci]
  • 22e6139 docs: highlight API key in Quick Start example (#1014)
  • dfca658 build(deps-dev): bump @ types/node from 20.5.9 to 20.6.0 (#1033)
  • b1a7ef1 build(deps-dev): bump typedoc from 0.25.0 to 0.25.1 (#1031)
  • 798938f build(deps-dev): bump prettier from 3.0.2 to 3.0.3 (#1032)
  • 59b3517 chore(release): 3.3.37 [skip ci]
  • a4a6f59 build(deps-dev): bump @ types/node from 20.5.1 to 20.5.9 (#1030)
  • d2fa136 build(deps-dev): bump typedoc from 0.24.8 to 0.25.0 (#1026)
  • 4216b1e build(deps-dev): bump prettier from 3.0.1 to 3.0.2 (#1024)
  • 476aa7d build(deps-dev): bump @ types/node from 20.5.0 to 20.5.1 (#1023)
  • dc3c68e chore(release): 3.3.36 [skip ci]
  • fdba501 build(deps-dev): bump nock from 13.3.2 to 13.3.3 (#1022)
  • 1a5f4da build(deps-dev): bump prettier from 3.0.0 to 3.0.1 (#1019)
  • 4dcd924 build(deps-dev): bump @ types/node from 20.4.8 to 20.5.0 (#1020)
  • e4be842 build(deps): bump agentkeepalive from 4.3.0 to 4.5.0 (#1018)
  • 77e49b4 build(deps-dev): bump @ types/node from 20.4.5 to 20.4.8 (#1017)

See the full diff

Package name: axios The new version differs by 46 commits.
  • b15b918 chore(release): v1.6.3 (#6151)
  • b76cce0 chore(ci): added branches filter for notify action; (#6084)
  • 5e7ad38 fix: Regular Expression Denial of Service (ReDoS) (#6132)
  • 8befb86 docs: update alloy link (#6145)
  • d18f40d docs: add headline sponsors
  • b3be365 chore(release): v1.6.2 (#6082)
  • 8739acb chore(ci): removed redundant release action; (#6081)
  • bfa9c30 chore(docs): fix outdated grunt to npm scripts (#6073)
  • a2b0fb3 chore(docs): update README.md (#6048)
  • b12a608 chore(ci): removed paths-ignore filter; (#6080)
  • 0c9d886 chore(ci): reworked ignoring files logic; (#6079)
  • 30873ee chore(ci): add paths-ignore config to testing action; (#6078)
  • cff9967 feat(withXSRFToken): added withXSRFToken option as a workaround to achieve the old `withCredentials` behavior; (#6046)
  • 7009715 chore(ci): fixed release notification action; (#6064)
  • 7144f10 chore(ci): fixed release notification action; (#6063)
  • f6d2cf9 chore(ci): fix publish action content permission; (#6061)
  • a22f4b9 chore(release): v1.6.1 (#6060)
  • cb8bb2b chore(ci): Publish to NPM with provenance (#5835)
  • 37cbf92 chore(ci): added labeling and notification for published PRs; (#6059)
  • dd465ab fix(formdata): fixed content-type header normalization for non-standard browser environments; (#6056)
  • 3dc8369 fix(platform): fixed emulated browser detection in node.js environment; (#6055)
  • f7adacd chore(release): v1.6.0 (#6031)
  • 9917e67 chore(ci): fix release-it arg; (#6032)
  • 96ee232 fix(CSRF): fixed CSRF vulnerability CVE-2023-45857 (#6028)

See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report

👩‍💻 Set who automatically gets assigned

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Regular Expression Denial of Service (ReDoS)

@giuseppealbrizio giuseppealbrizio self-assigned this Dec 27, 2023
# for free to join this conversation on GitHub. Already have an account? # to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants