From dee59212d83839229a971950f4eba72d9286129b Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Tue, 12 May 2020 23:11:37 +0100 Subject: [PATCH 1/2] fix: goof/package.json & goof/package-lock.json to reduce vulnerabilities The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-JS-KERBEROS-568900 --- goof/package.json | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/goof/package.json b/goof/package.json index 2300e7e8a..0983da8fc 100644 --- a/goof/package.json +++ b/goof/package.json @@ -32,7 +32,7 @@ "marked": "0.3.5", "method-override": "latest", "moment": "2.15.1", - "mongoose": "4.2.4", + "mongoose": "4.2.5", "morgan": "latest", "ms": "^0.7.1", "npmconf": "0.0.24", From d6839a98eaaebf454e4b0310219a8a89d37f2003 Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Tue, 12 May 2020 23:11:38 +0100 Subject: [PATCH 2/2] fix: goof/package.json & goof/package-lock.json to reduce vulnerabilities The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-JS-KERBEROS-568900 --- goof/package-lock.json | 83 +++++++++++++++++++----------------------- 1 file changed, 38 insertions(+), 45 deletions(-) diff --git a/goof/package-lock.json b/goof/package-lock.json index 70f1692ad..83724a16a 100644 --- a/goof/package-lock.json +++ b/goof/package-lock.json @@ -185,11 +185,18 @@ "dev": true }, "basic-auth": { - "version": "2.0.0", - "resolved": "https://registry.npmjs.org/basic-auth/-/basic-auth-2.0.0.tgz", - "integrity": "sha1-AV2z81PgLlY3d1X5YnQuiYHnu7o=", + "version": "2.0.1", + "resolved": "https://registry.npmjs.org/basic-auth/-/basic-auth-2.0.1.tgz", + "integrity": "sha512-NF+epuEdnUYVlGuhaxbbq+dvJttwLnGY+YixlXlME5KpQ5W3CnXA5cVTneY3SPbPDRkcjMbifrwmFYcClgOZeg==", "requires": { - "safe-buffer": "5.1.1" + "safe-buffer": "5.1.2" + }, + "dependencies": { + "safe-buffer": { + "version": "5.1.2", + "resolved": "https://registry.npmjs.org/safe-buffer/-/safe-buffer-5.1.2.tgz", + "integrity": "sha512-Gd2UZBJDkXlY7GbJxfsE8/nvKkUEU1G38c1siN6QP6a9PT9MmHB8GnpscSmMJSoF8LOIrt8ud/wPtojys4G6+g==" + } } }, "bcrypt-pbkdf": { @@ -252,6 +259,7 @@ "version": "0.4.2", "resolved": "https://registry.npmjs.org/boom/-/boom-0.4.2.tgz", "integrity": "sha1-emNune1O/O+xnO9JR6PGffrukRs=", + "optional": true, "requires": { "hoek": "0.9.x" } @@ -1692,7 +1700,8 @@ "hoek": { "version": "0.9.1", "resolved": "https://registry.npmjs.org/hoek/-/hoek-0.9.1.tgz", - "integrity": "sha1-PTIkYrrfB3Fup+uFuviAec3c5QU=" + "integrity": "sha1-PTIkYrrfB3Fup+uFuviAec3c5QU=", + "optional": true }, "hooks-fixed": { "version": "1.1.0", @@ -1983,15 +1992,6 @@ "resolved": "https://registry.npmjs.org/kareem/-/kareem-1.0.1.tgz", "integrity": "sha1-eAXSFbtTIU7Dr5aaHQsfF+PnuVw=" }, - "kerberos": { - "version": "0.0.24", - "resolved": "https://registry.npmjs.org/kerberos/-/kerberos-0.0.24.tgz", - "integrity": "sha512-QO6bFq9eETHB5zcA0OJiQtw137TH45OuUcGtI+QGg2ZJQIPCvwXL2kjCqZZMColcIdbPhj4X40EY5f3oOiBfiw==", - "optional": true, - "requires": { - "nan": "~2.10.0" - } - }, "labeled-stream-splicer": { "version": "2.0.1", "resolved": "https://registry.npmjs.org/labeled-stream-splicer/-/labeled-stream-splicer-2.0.1.tgz", @@ -2218,12 +2218,12 @@ "integrity": "sha1-6XnCop4iiI5g85byIgphGPhc2Uw=" }, "mongodb": { - "version": "2.0.46", - "resolved": "https://registry.npmjs.org/mongodb/-/mongodb-2.0.46.tgz", - "integrity": "sha1-sbhXRl5F4lmx4OAzaYNBpky5NVk=", + "version": "2.0.48", + "resolved": "https://registry.npmjs.org/mongodb/-/mongodb-2.0.48.tgz", + "integrity": "sha1-8O7kRejyJBxLlmWLhpfhfdq7naM=", "requires": { "es6-promise": "2.1.1", - "mongodb-core": "1.2.19", + "mongodb-core": "1.2.21", "readable-stream": "1.0.31" }, "dependencies": { @@ -2241,24 +2241,23 @@ } }, "mongodb-core": { - "version": "1.2.19", - "resolved": "https://registry.npmjs.org/mongodb-core/-/mongodb-core-1.2.19.tgz", - "integrity": "sha1-/LNfa2q8XD3h8aSl21JrnjBvPrc=", + "version": "1.2.21", + "resolved": "https://registry.npmjs.org/mongodb-core/-/mongodb-core-1.2.21.tgz", + "integrity": "sha1-O8vM0xFHuM8BNMDaUmdfEhseo/s=", "requires": { - "bson": "~0.4.19", - "kerberos": "~0.0" + "bson": "~0.4.19" } }, "mongoose": { - "version": "4.2.4", - "resolved": "https://registry.npmjs.org/mongoose/-/mongoose-4.2.4.tgz", - "integrity": "sha1-4vjAB92Dj2YztPbJZbqSojKskxc=", + "version": "4.2.5", + "resolved": "https://registry.npmjs.org/mongoose/-/mongoose-4.2.5.tgz", + "integrity": "sha1-Vjo9W46Q+xB+sV+VRxxwYwY4+34=", "requires": { "async": "0.9.0", "bson": "~0.4.18", "hooks-fixed": "1.1.0", "kareem": "1.0.1", - "mongodb": "2.0.46", + "mongodb": "2.0.48", "mpath": "0.1.1", "mpromise": "0.5.4", "mquery": "1.6.3", @@ -2276,15 +2275,15 @@ } }, "morgan": { - "version": "1.9.0", - "resolved": "https://registry.npmjs.org/morgan/-/morgan-1.9.0.tgz", - "integrity": "sha1-0B+mxlhZt2/PMbPLU6OCGjEdgFE=", + "version": "1.10.0", + "resolved": "https://registry.npmjs.org/morgan/-/morgan-1.10.0.tgz", + "integrity": "sha512-AbegBVI4sh6El+1gNwvD5YIck7nSA36weD7xvIxG4in80j/UoK8AEGaWnnz8v1GxonMCltmlNs5ZKbGvl9b1XQ==", "requires": { - "basic-auth": "~2.0.0", + "basic-auth": "~2.0.1", "debug": "2.6.9", - "depd": "~1.1.1", + "depd": "~2.0.0", "on-finished": "~2.3.0", - "on-headers": "~1.0.1" + "on-headers": "~1.0.2" }, "dependencies": { "debug": { @@ -2296,9 +2295,9 @@ } }, "depd": { - "version": "1.1.2", - "resolved": "https://registry.npmjs.org/depd/-/depd-1.1.2.tgz", - "integrity": "sha1-m81S4UwJd2PnSbJ0xDRu0uVgtak=" + "version": "2.0.0", + "resolved": "https://registry.npmjs.org/depd/-/depd-2.0.0.tgz", + "integrity": "sha512-g7nH6P6dyDioJogAAGprGpCtVImJhpPk/roCzdb3fIh61/s/nPsfR6onyMwkCAR/OlC3yBC0lESvUoQEAssIrw==" }, "ee-first": { "version": "1.1.1", @@ -2358,12 +2357,6 @@ "resolved": "https://registry.npmjs.org/muri/-/muri-1.0.0.tgz", "integrity": "sha1-3jv2vXHWfq5x12aJuVDS3hGGlcY=" }, - "nan": { - "version": "2.10.0", - "resolved": "https://registry.npmjs.org/nan/-/nan-2.10.0.tgz", - "integrity": "sha512-bAdJv7fBLhWC+/Bls0Oza+mvTaNQtP+1RyhhhvD95pgUJz6XM5IzgmxOkItJ9tkoCiplvAnXI1tNmmUD/eScyA==", - "optional": true - }, "negotiator": { "version": "0.4.9", "resolved": "https://registry.npmjs.org/negotiator/-/negotiator-0.4.9.tgz", @@ -4211,9 +4204,9 @@ } }, "on-headers": { - "version": "1.0.1", - "resolved": "https://registry.npmjs.org/on-headers/-/on-headers-1.0.1.tgz", - "integrity": "sha1-ko9dD0cNSTQmUepnlLCFfBAGk/c=" + "version": "1.0.2", + "resolved": "https://registry.npmjs.org/on-headers/-/on-headers-1.0.2.tgz", + "integrity": "sha512-pZAE+FJLoyITytdqK0U5s+FIpjN0JP3OzFi/u8Rx+EV5/W+JTWGXG8xFzevE7AjBfDqHv/8vL8qQsIhHnqRkrA==" }, "once": { "version": "1.4.0",