Skip to content
New issue

Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? # to your account

[Snyk] Upgrade: , bootstrap, bootstrap-vue, nuxt #29

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

takawiramundure
Copy link
Owner

snyk-top-banner

Snyk has created this PR to upgrade multiple dependencies.

👯‍♂ The following dependencies are linked and will therefore be updated together.

ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.

Name Versions Released on

@nuxtjs/axios
from 5.9.3 to 5.13.6 | 22 versions ahead of your current version | 3 years ago
on 2021-06-02
bootstrap
from 4.4.1 to 4.6.2 | 7 versions ahead of your current version | 2 years ago
on 2022-07-19
bootstrap-vue
from 2.2.0 to 2.23.1 | 36 versions ahead of your current version | 2 years ago
on 2022-10-26
nuxt
from 2.11.0 to 2.18.1 | 40 versions ahead of your current version | 3 months ago
on 2024-06-28

Issues fixed by the recommended upgrade:

Issue Score Exploit Maturity
high severity Path Traversal
SNYK-JS-WEBPACKDEVMIDDLEWARE-6476555
691 Proof of Concept
high severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-ACORN-559469
691 No Known Exploit
high severity Prototype Pollution
SNYK-JS-AJV-584908
691 No Known Exploit
high severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-ANSIHTML-1296849
691 Proof of Concept
high severity Code Injection
SNYK-JS-LODASH-1040724
691 Proof of Concept
high severity Prototype Pollution
SNYK-JS-LODASH-567746
691 Proof of Concept
high severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-UAPARSERJS-1023599
691 Proof of Concept
high severity Asymmetric Resource Consumption (Amplification)
SNYK-JS-BODYPARSER-7926860
691 No Known Exploit
high severity Improper Verification of Cryptographic Signature
SNYK-JS-BROWSERIFYSIGN-6037026
691 No Known Exploit
high severity Improper Input Validation
SNYK-JS-FOLLOWREDIRECTS-6141137
691 Proof of Concept
high severity Improper Input Validation
SNYK-JS-FOLLOWREDIRECTS-6141137
691 Proof of Concept
high severity Denial of Service (DoS)
SNYK-JS-DECODEURICOMPONENT-3149970
691 Proof of Concept
high severity Remote Code Execution (RCE)
SNYK-JS-EJS-2803307
691 Proof of Concept
high severity Cryptographic Issues
SNYK-JS-ELLIPTIC-571484
691 Proof of Concept
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-WS-1296835
691 Proof of Concept
medium severity Open Redirect
SNYK-JS-EXPRESS-6474509
691 No Known Exploit
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-HTMLMINIFIER-3091181
691 Proof of Concept
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-HTMLMINIFIER-3091181
691 Proof of Concept
medium severity Denial of Service (DoS)
SNYK-JS-HTTPPROXY-569139
691 Proof of Concept
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-POSTCSS-1255640
691 Proof of Concept
medium severity Prototype Pollution
SNYK-JS-MINIMIST-559764
691 Proof of Concept
medium severity Prototype Pollution
SNYK-JS-MINIMIST-559764
691 Proof of Concept
medium severity Information Exposure
SNYK-JS-NODEFETCH-2342118
691 No Known Exploit
medium severity Denial of Service
SNYK-JS-NODEFETCH-674311
691 No Known Exploit
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-LOADERUTILS-3105943
691 No Known Exploit
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-LODASH-1018905
691 Proof of Concept
medium severity Uncontrolled Resource Consumption ('Resource Exhaustion')
SNYK-JS-TAR-6476909
691 Proof of Concept
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-TERSER-2806366
691 No Known Exploit
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-UAPARSERJS-1072471
691 Proof of Concept
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-COLORSTRING-1082939
691 Proof of Concept
medium severity Cross-site Scripting
SNYK-JS-EXPRESS-7926867
691 No Known Exploit
medium severity Information Exposure
SNYK-JS-FOLLOWREDIRECTS-2332181
691 Proof of Concept
medium severity Information Exposure
SNYK-JS-FOLLOWREDIRECTS-6444610
691 Proof of Concept
medium severity Information Exposure
SNYK-JS-FOLLOWREDIRECTS-2332181
691 Proof of Concept
low severity Prototype Pollution
SNYK-JS-MINIMIST-2429795
691 Proof of Concept
critical severity Incomplete List of Disallowed Inputs
SNYK-JS-BABELTRAVERSE-5962462
691 Proof of Concept
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-BROWSERSLIST-1090194
691 Proof of Concept
medium severity Information Exposure
SNYK-JS-FOLLOWREDIRECTS-6444610
691 Proof of Concept
medium severity Prototype Pollution
SNYK-JS-DOTPROP-543489
691 Proof of Concept
medium severity Arbitrary Code Injection
SNYK-JS-EJS-1049328
691 Proof of Concept
medium severity Improper Control of Dynamically-Managed Code Resources
SNYK-JS-EJS-6689533
691 No Known Exploit
medium severity Cryptographic Issues
SNYK-JS-ELLIPTIC-1064899
691 No Known Exploit
low severity Information Exposure
SNYK-JS-FOLLOWREDIRECTS-2396346
691 No Known Exploit
low severity Information Exposure
SNYK-JS-FOLLOWREDIRECTS-2396346
691 No Known Exploit
critical severity Improper Verification of Cryptographic Signature
SNYK-JS-ELLIPTIC-7577916
691 Proof of Concept
critical severity Improper Verification of Cryptographic Signature
SNYK-JS-ELLIPTIC-7577917
691 Proof of Concept
critical severity Improper Verification of Cryptographic Signature
SNYK-JS-ELLIPTIC-7577918
691 Proof of Concept
high severity Prototype Pollution
SNYK-JS-INI-1048974
691 Proof of Concept
high severity Server-side Request Forgery (SSRF)
SNYK-JS-IP-6240864
691 Proof of Concept
high severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-AXIOS-1579269
691 Proof of Concept
high severity Remote Code Execution (RCE)
SNYK-JS-SHELLQUOTE-1766506
691 No Known Exploit
high severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-SSRI-1246392
691 Proof of Concept
high severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-SSRI-1246392
691 Proof of Concept
high severity Arbitrary File Overwrite
SNYK-JS-TAR-1536528
691 No Known Exploit
high severity Arbitrary File Overwrite
SNYK-JS-TAR-1536531
691 No Known Exploit
high severity Arbitrary File Write
SNYK-JS-TAR-1579147
691 No Known Exploit
high severity Arbitrary File Write
SNYK-JS-TAR-1579152
691 No Known Exploit
high severity Arbitrary File Write
SNYK-JS-TAR-1579155
691 No Known Exploit
high severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-NTHCHECK-1586032
691 Proof of Concept
high severity Prototype Pollution
SNYK-JS-LOADERUTILS-3043105
691 No Known Exploit
high severity Prototype Pollution
SNYK-JS-LOADERUTILS-3043105
691 No Known Exploit
high severity Prototype Poisoning
SNYK-JS-QS-3153490
691 Proof of Concept
high severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-SEMVER-3247795
691 Proof of Concept
high severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-SEMVER-3247795
691 Proof of Concept
high severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-SEMVER-3247795
691 Proof of Concept
high severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-SEMVER-3247795
691 Proof of Concept
high severity Arbitrary Code Injection
SNYK-JS-SERIALIZEJAVASCRIPT-570062
691 Proof of Concept
high severity Denial of Service (DoS)
SNYK-JS-WS-7266574
691 Proof of Concept
high severity Prototype Pollution
SNYK-JS-Y18N-1021887
691 Proof of Concept
high severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-UAPARSERJS-610226
691 Proof of Concept
high severity Prototype Pollution
SNYK-JS-LODASH-608086
691 Proof of Concept
high severity Prototype Pollution
SNYK-JS-LODASH-6139239
691 Proof of Concept
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-ISSVG-1085627
691 Proof of Concept
medium severity Server-Side Request Forgery (SSRF)
SNYK-JS-AXIOS-1038255
691 Proof of Concept
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-PATHPARSE-1077067
691 Proof of Concept
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-PATHTOREGEXP-7925106
691 Proof of Concept
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-POSTCSS-1090595
691 Proof of Concept
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-ISSVG-1243891
691 Proof of Concept
medium severity Prototype Pollution
SNYK-JS-JSON5-3182856
691 Proof of Concept
medium severity Prototype Pollution
SNYK-JS-JSON5-3182856
691 Proof of Concept
medium severity Prototype Pollution
SNYK-JS-JSON5-3182856
691 Proof of Concept
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-LOADERUTILS-3042992
691 No Known Exploit
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-LOADERUTILS-3105943
691 No Known Exploit
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-LOADERUTILS-3042992
691 No Known Exploit
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-UGLIFYJS-1727251
691 No Known Exploit
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-UGLIFYJS-1727251
691 No Known Exploit
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-MINIMATCH-3050818
691 No Known Exploit
low severity Cross-site Scripting
SNYK-JS-SERVESTATIC-7926865
691 No Known Exploit
low severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-TAR-1536758
691 No Known Exploit
low severity Validation Bypass
SNYK-JS-KINDOF-537849
691 Proof of Concept
low severity Cross-site Scripting
SNYK-JS-SEND-7926862
691 No Known Exploit
low severity Regular Expression Denial of Service (ReDoS)
npm:debug:20170905
691 Proof of Concept
low severity Regular Expression Denial of Service (ReDoS)
npm:debug:20170905
691 Proof of Concept
low severity Prototype Pollution
SNYK-JS-MINIMIST-2429795
691 Proof of Concept
Release notes
Package name: @nuxtjs/axios
  • 5.13.6 - 2021-06-02

    Bug Fixes

    • setHeader function returns after the first scope element (#507) (cb5e29d)
  • 5.13.5 - 2021-05-26

    Bug Fixes

    • only transpile defu for client bundle (resolves #501) (ec2eb0a)
  • 5.13.4 - 2021-05-18

    Bug Fixes

    • build.transpile guard for nuxt@1.x (fixes #498) (66d56ab)
  • 5.13.3 - 2021-05-17

    Bug Fixes

  • 5.13.2 - 2021-05-17

    Dependencies:

    • Update defu to 5.x
  • 5.13.1 - 2021-02-08

    Bug Fixes

  • 5.13.0 - 2021-02-01

    Features

    • Support baseUrl and browserBaseUrl to handle casing typos (8904847)

    Bug Fixes

    • Add x-forwarded-port and x-forwarded-proto to proxyHeaderIgnore defaults (#465) (a1a1894)
  • 5.12.5 - 2021-01-04

    Bug Fixes

    • add x-forwarded-host to proxyHeaderIgnore defaults (#462) (433548b), closes #456

    Dependencies

  • 5.12.4 - 2020-12-14

    Bug Fixes

    Dependencies

    • Update @ nuxtjs/proxy to 2.1.0 (less warnings and typescript rewrite)

    Thanks

  • 5.12.3 - 2020-11-30

    Bug Fixes

  • 5.12.2 - 2020-08-25
  • 5.12.1 - 2020-08-05
  • 5.12.0 - 2020-07-10
  • 5.11.0 - 2020-06-05
  • 5.10.3 - 2020-04-30
  • 5.10.2 - 2020-04-27
  • 5.10.1 - 2020-04-22
  • 5.10.0 - 2020-04-21
  • 5.9.7 - 2020-03-30
  • 5.9.6 - 2020-03-27
  • 5.9.5 - 2020-02-02
  • 5.9.4 - 2020-01-30
  • 5.9.3 - 2020-01-11
from @nuxtjs/axios GitHub release notes
Package name: bootstrap

Snyk has created this PR to upgrade:
  - @nuxtjs/axios from 5.9.3 to 5.13.6.
    See this package in npm: https://www.npmjs.com/package/@nuxtjs/axios
  - bootstrap from 4.4.1 to 4.6.2.
    See this package in npm: https://www.npmjs.com/package/bootstrap
  - bootstrap-vue from 2.2.0 to 2.23.1.
    See this package in npm: https://www.npmjs.com/package/bootstrap-vue
  - nuxt from 2.11.0 to 2.18.1.
    See this package in npm: https://www.npmjs.com/package/nuxt

See this project in Snyk:
https://app.snyk.io/org/takawiramundure/project/106377ad-f313-40be-9456-91d640bb1d91?utm_source=github&utm_medium=referral&page=upgrade-pr
# for free to join this conversation on GitHub. Already have an account? # to comment
Labels
None yet
Projects
None yet
2 participants