Skip to content
New issue

Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? # to your account

[Snyk] Fix for 1 vulnerabilities #17

Open
wants to merge 1 commit into
base: main
Choose a base branch
from

Conversation

Dixiejane
Copy link
Owner

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • deps/npm/package.json

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
high severity 823/1000
Why? Proof of Concept exploit, Recently disclosed, Has a fix available, CVSS 8.6
Server-side Request Forgery (SSRF)
SNYK-JS-IP-6240864
Yes Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: @npmcli/run-script The new version differs by 15 commits.
  • fcebe38 chore: release 7.0.2
  • 30623cf deps: bump node-gyp from 9.4.1 to 10.0.0
  • 54e5bd0 chore: postinstall for dependabot template-oss PR
  • 7d95e9f chore: bump @ npmcli/template-oss from 4.18.1 to 4.19.0
  • 90bcf54 chore: postinstall for dependabot template-oss PR
  • ba0ab48 chore: bump @ npmcli/template-oss from 4.18.0 to 4.18.1
  • 43ccfc7 chore: release 7.0.1
  • f61fd84 deps: bump @ npmcli/promise-spawn from 6.0.2 to 7.0.0
  • 87b740b chore: release 7.0.0
  • e1b1a3c fix: drop node14 support
  • a8045a9 deps: bump which from 3.0.1 to 4.0.0
  • c4f4fb4 chore: postinstall for dependabot template-oss PR
  • dacd67e chore: bump @ npmcli/template-oss from 4.17.0 to 4.18.0
  • 9d2d807 chore: postinstall for dependabot template-oss PR
  • 8b21725 chore: bump @ npmcli/template-oss from 4.15.1 to 4.17.0

See the full diff

Package name: libnpmaccess The new version differs by 250 commits.

See the full diff

Package name: libnpmhook The new version differs by 250 commits.

See the full diff

Package name: libnpmsearch The new version differs by 250 commits.

See the full diff

Package name: libnpmversion The new version differs by 250 commits.

See the full diff

Package name: make-fetch-happen The new version differs by 14 commits.

See the full diff

Package name: node-gyp The new version differs by 27 commits.

See the full diff

Package name: npm-profile The new version differs by 27 commits.
  • 32cf63c chore: release 8.0.0
  • 96370c2 deps: bump npm-registry-fetch from 14.0.5 to 15.0.0
  • 384988c chore: turn on autopublish
  • cfd2d07 fix: drop node14 support
  • f20ba2b chore: merge old changelog to current format
  • 444ca44 chore: postinstall for dependabot template-oss PR
  • 3369a3d chore: bump @ npmcli/template-oss from 4.17.0 to 4.18.0
  • 3219ad5 chore: postinstall for dependabot template-oss PR
  • ef6d9df chore: bump @ npmcli/template-oss from 4.15.1 to 4.17.0
  • 446b025 chore: postinstall for dependabot template-oss PR
  • 17904ca chore: bump @ npmcli/template-oss from 4.14.1 to 4.15.1
  • 1c17cd1 chore: bump @ npmcli/template-oss from 4.12.1 to 4.14.1 (Proposal: return Promises as well as taking callbacks. nodejs/node#88)
  • d7055e6 chore: bump @ npmcli/template-oss from 4.12.0 to 4.12.1 (Installation via curl nodejs/node#86)
  • e88a3de chore: postinstall for dependabot template-oss PR
  • 2771943 chore: bump @ npmcli/template-oss from 4.11.4 to 4.12.0
  • 78bbb4c chore: postinstall for dependabot template-oss PR
  • 9b39807 chore: bump @ npmcli/template-oss from 4.11.3 to 4.11.4
  • 4bc95d9 chore: postinstall for dependabot template-oss PR
  • 8009557 chore: bump @ npmcli/template-oss from 4.11.0 to 4.11.3
  • f89f346 chore: postinstall for dependabot template-oss PR
  • 6767e40 chore: bump @ npmcli/template-oss from 4.10.0 to 4.11.0
  • b7f6f2b chore: postinstall for dependabot template-oss PR
  • 5c8f187 chore: bump @ npmcli/template-oss from 4.8.0 to 4.10.0
  • 47530f1 chore: postinstall for dependabot template-oss PR

See the full diff

Package name: npm-registry-fetch The new version differs by 10 commits.

See the full diff

Package name: pacote The new version differs by 27 commits.
  • 18e760f chore: release 17.0.4
  • ba8f790 deps: bump @ npmcli/promise-spawn from 6.0.2 to 7.0.0
  • 2c0d3ae deps: bump @ npmcli/run-script from 6.0.2 to 7.0.0
  • 7aa2062 chore: release 17.0.3
  • ace7c28 deps: bump npm-packlist from 7.0.4 to 8.0.0
  • f1efd0c chore: release 17.0.2
  • c3b892d deps: bump sigstore from 1.3.0 to 2.0.0
  • c75d7d5 chore: release 17.0.1
  • 6ddae13 deps: bump npm-registry-fetch from 15.0.0 to 16.0.0
  • 42bf787 deps: bump npm-pick-manifest from 8.0.2 to 9.0.0
  • 9fa2de9 chore: release 17.0.0
  • e9e964b deps: bump read-package-json from 6.0.4 to 7.0.0
  • f69d844 chore: hosted-git-info@7.0.0
  • 5d26500 deps: bump npm-package-arg from 10.1.0 to 11.0.0
  • d13bb9c deps: bump @ npmcli/git from 4.1.0 to 5.0.0
  • 7a25e39 deps: bump cacache from 17.1.4 to 18.0.0
  • 2db2fb5 fix: drop node 16.13.x support
  • 5cdbfd1 chore: release 16.0.0
  • 8dc6a32 deps: bump minipass from 5.0.0 to 7.0.2
  • 7cebf19 deps: bump npm-registry-fetch from 14.0.5 to 15.0.0
  • 73b6297 fix: drop node14 support (build,src: remove sslv2 support nodejs/node#290)
  • 53cf17e chore: postinstall for dependabot template-oss PR
  • 865d5c7 chore: bump @ npmcli/template-oss from 4.17.0 to 4.18.0
  • 040add9 chore: postinstall for dependabot template-oss PR

See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Server-side Request Forgery (SSRF)

The following vulnerabilities are fixed with an upgrade:
- https://snyk.io/vuln/SNYK-JS-IP-6240864
Copy link

vercel bot commented Feb 11, 2024

The latest updates on your projects. Learn more about Vercel for Git ↗︎

Name Status Preview Comments Updated (UTC)
node ❌ Failed (Inspect) Feb 11, 2024 4:59pm
node-dca1 ❌ Failed (Inspect) Feb 11, 2024 4:59pm
node-hrd9 ❌ Failed (Inspect) Feb 11, 2024 4:59pm

# for free to join this conversation on GitHub. Already have an account? # to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants