forked from snyk-fixtures/npm-lockfiles
-
Notifications
You must be signed in to change notification settings - Fork 0
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[Snyk] Fix for 92 vulnerabilities #100
Open
Omrisnyk
wants to merge
1
commit into
master
Choose a base branch
from
snyk-fix-206a08dff61b7441ac10b14a3da37011
base: master
Could not load branches
Branch not found: {{ refName }}
Loading
Could not load tags
Nothing to show
Loading
Are you sure you want to change the base?
Some commits from the old base branch may be removed from the timeline,
and old review comments may become outdated.
Open
Conversation
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
…le/.snyk to reduce vulnerabilities The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-JS-AWSSDK-1059424 - https://snyk.io/vuln/SNYK-JS-AXIOS-1038255 - https://snyk.io/vuln/SNYK-JS-AXIOS-1579269 - https://snyk.io/vuln/SNYK-JS-AXIOS-174505 - https://snyk.io/vuln/SNYK-JS-BROWSERSLIST-1090194 - https://snyk.io/vuln/SNYK-JS-CACHEDPATHRELATIVE-2342653 - https://snyk.io/vuln/SNYK-JS-JSON5-3182856 - https://snyk.io/vuln/SNYK-JS-JSONSCHEMA-1920922 - https://snyk.io/vuln/SNYK-JS-JSZIP-1251497 - https://snyk.io/vuln/SNYK-JS-KARMA-2395349 - https://snyk.io/vuln/SNYK-JS-LODASH-608086 - https://snyk.io/vuln/SNYK-JS-LODASH-73638 - https://snyk.io/vuln/SNYK-JS-LODASH-73639 - https://snyk.io/vuln/SNYK-JS-LODASHES-2434283 - https://snyk.io/vuln/SNYK-JS-LODASHES-2434284 - https://snyk.io/vuln/SNYK-JS-LODASHES-2434285 - https://snyk.io/vuln/SNYK-JS-LODASHES-2434286 - https://snyk.io/vuln/SNYK-JS-LODASHES-2434287 - https://snyk.io/vuln/SNYK-JS-LODASHES-2434289 - https://snyk.io/vuln/SNYK-JS-LODASHES-2434290 - https://snyk.io/vuln/SNYK-JS-LOG4JS-2348757 - https://snyk.io/vuln/SNYK-JS-MERGE-1040469 - https://snyk.io/vuln/SNYK-JS-MERGE-1042987 - https://snyk.io/vuln/SNYK-JS-MINIMATCH-3050818 - https://snyk.io/vuln/SNYK-JS-MINIMIST-2429795 - https://snyk.io/vuln/SNYK-JS-MINIMIST-559764 - https://snyk.io/vuln/SNYK-JS-MOCHA-2863123 - https://snyk.io/vuln/SNYK-JS-MOMENT-2440688 - https://snyk.io/vuln/SNYK-JS-MOMENT-2944238 - https://snyk.io/vuln/SNYK-JS-MONGODBJSMETRICS-1243685 - https://snyk.io/vuln/SNYK-JS-MOUT-1014544 - https://snyk.io/vuln/SNYK-JS-MOUT-2342654 - https://snyk.io/vuln/SNYK-JS-NCONF-2395478 - https://snyk.io/vuln/SNYK-JS-NETMASK-1089716 - https://snyk.io/vuln/SNYK-JS-NODEFETCH-2342118 - https://snyk.io/vuln/SNYK-JS-NODEFETCH-674311 - https://snyk.io/vuln/SNYK-JS-NODEMAILER-1038834 - https://snyk.io/vuln/SNYK-JS-NODEMAILER-1296415 - https://snyk.io/vuln/SNYK-JS-NTHCHECK-1586032 - https://snyk.io/vuln/SNYK-JS-OBJECTPATH-1017036 - https://snyk.io/vuln/SNYK-JS-OBJECTPATH-1569453 - https://snyk.io/vuln/SNYK-JS-PACRESOLVER-1564857 - https://snyk.io/vuln/SNYK-JS-PATHPARSE-1077067 - https://snyk.io/vuln/SNYK-JS-PATHVAL-596926 - https://snyk.io/vuln/SNYK-JS-POSTCSS-1255640 - https://snyk.io/vuln/SNYK-JS-PROMPTS-1729737 - https://snyk.io/vuln/SNYK-JS-QS-3153490 - https://snyk.io/vuln/SNYK-JS-RAMDA-1582370 - https://snyk.io/vuln/SNYK-JS-REDIS-1255645 - https://snyk.io/vuln/SNYK-JS-SANITIZEHTML-1070780 - https://snyk.io/vuln/SNYK-JS-SANITIZEHTML-1070786 - https://snyk.io/vuln/SNYK-JS-SANITIZEHTML-2957526 - https://snyk.io/vuln/SNYK-JS-SANITIZEHTML-585892 - https://snyk.io/vuln/SNYK-JS-SHELLQUOTE-1766506 - https://snyk.io/vuln/SNYK-JS-SNYK-3037342 - https://snyk.io/vuln/SNYK-JS-SNYK-3038622 - https://snyk.io/vuln/SNYK-JS-SNYK-3111871 - https://snyk.io/vuln/SNYK-JS-SNYKDOCKERPLUGIN-3039679 - https://snyk.io/vuln/SNYK-JS-SNYKGOPLUGIN-3037316 - https://snyk.io/vuln/SNYK-JS-SNYKGRADLEPLUGIN-3038624 - https://snyk.io/vuln/SNYK-JS-SNYKMVNPLUGIN-3038623 - https://snyk.io/vuln/SNYK-JS-SNYKPYTHONPLUGIN-3039677 - https://snyk.io/vuln/SNYK-JS-SNYKSBTPLUGIN-3038626 - https://snyk.io/vuln/SNYK-JS-SNYKSNYKCOCOAPODSPLUGIN-3038625 - https://snyk.io/vuln/SNYK-JS-SOCKETIO-1024859 - https://snyk.io/vuln/SNYK-JS-SOCKETIOPARSER-1056752 - https://snyk.io/vuln/SNYK-JS-SOCKETIOPARSER-3091012 - https://snyk.io/vuln/SNYK-JS-SSH2-1656673 - https://snyk.io/vuln/SNYK-JS-SSRI-1246392 - https://snyk.io/vuln/SNYK-JS-TRIM-1017038 - https://snyk.io/vuln/SNYK-JS-UAPARSERJS-1023599 - https://snyk.io/vuln/SNYK-JS-UAPARSERJS-1072471 - https://snyk.io/vuln/SNYK-JS-UAPARSERJS-610226 - https://snyk.io/vuln/SNYK-JS-UGLIFYJS-1727251 - https://snyk.io/vuln/SNYK-JS-UNDERSCORE-1080984 - https://snyk.io/vuln/SNYK-JS-URLPARSE-1078283 - https://snyk.io/vuln/SNYK-JS-URLPARSE-1533425 - https://snyk.io/vuln/SNYK-JS-URLPARSE-2401205 - https://snyk.io/vuln/SNYK-JS-URLPARSE-2407759 - https://snyk.io/vuln/SNYK-JS-URLPARSE-2407770 - https://snyk.io/vuln/SNYK-JS-URLPARSE-2412697 - https://snyk.io/vuln/SNYK-JS-WS-1296835 - https://snyk.io/vuln/SNYK-JS-XMLHTTPREQUESTSSL-1082936 - https://snyk.io/vuln/SNYK-JS-XMLHTTPREQUESTSSL-1255647 - https://snyk.io/vuln/SNYK-JS-Y18N-1021887 - https://snyk.io/vuln/npm:braces:20180219 - https://snyk.io/vuln/npm:debug:20170905 - https://snyk.io/vuln/npm:lodash:20180130 - https://snyk.io/vuln/npm:ms:20170412 - https://snyk.io/vuln/npm:ws:20171108 The following vulnerabilities are fixed with a Snyk patch: - https://snyk.io/vuln/npm:hoek:20180212 - https://snyk.io/vuln/npm:tunnel-agent:20170305
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This PR was automatically created by Snyk using the credentials of a real user.
Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.
Changes included in this PR
Vulnerabilities that will be fixed
With an upgrade:
Why? Proof of Concept exploit, Has a fix available, CVSS 7.3
SNYK-JS-AWSSDK-1059424
Why? Proof of Concept exploit, Has a fix available, CVSS 5.9
SNYK-JS-AXIOS-1038255
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
SNYK-JS-AXIOS-1579269
Why? Proof of Concept exploit, Has a fix available, CVSS 5.3
SNYK-JS-AXIOS-174505
Why? Proof of Concept exploit, Has a fix available, CVSS 5.3
SNYK-JS-BROWSERSLIST-1090194
Why? Proof of Concept exploit, Has a fix available, CVSS 7.3
SNYK-JS-CACHEDPATHRELATIVE-2342653
Why? Proof of Concept exploit, Has a fix available, CVSS 6.4
SNYK-JS-JSON5-3182856
Why? Has a fix available, CVSS 8.6
SNYK-JS-JSONSCHEMA-1920922
Why? Proof of Concept exploit, Has a fix available, CVSS 5.3
SNYK-JS-JSZIP-1251497
Why? Proof of Concept exploit, Has a fix available, CVSS 5.4
SNYK-JS-KARMA-2395349
Why? Proof of Concept exploit, CVSS 7.3
SNYK-JS-LODASH-608086
Why? Proof of Concept exploit, CVSS 7.3
SNYK-JS-LODASH-73638
Why? Proof of Concept exploit, CVSS 4.4
SNYK-JS-LODASH-73639
Why? Proof of Concept exploit, Has a fix available, CVSS 8.2
SNYK-JS-LODASHES-2434283
Why? Proof of Concept exploit, Has a fix available, CVSS 7.2
SNYK-JS-LODASHES-2434284
Why? Proof of Concept exploit, Has a fix available, CVSS 7.3
SNYK-JS-LODASHES-2434285
Why? Proof of Concept exploit, Has a fix available, CVSS 4.4
SNYK-JS-LODASHES-2434286
Why? Proof of Concept exploit, Has a fix available, CVSS 7.3
SNYK-JS-LODASHES-2434287
Why? Proof of Concept exploit, Has a fix available, CVSS 5.3
SNYK-JS-LODASHES-2434289
Why? Proof of Concept exploit, Has a fix available, CVSS 7.3
SNYK-JS-LODASHES-2434290
Why? Has a fix available, CVSS 5.5
SNYK-JS-LOG4JS-2348757
Why? Has a fix available, CVSS 7.5
SNYK-JS-MERGE-1040469
Why? Proof of Concept exploit, Has a fix available, CVSS 7.3
SNYK-JS-MERGE-1042987
Why? Has a fix available, CVSS 5.3
SNYK-JS-MINIMATCH-3050818
Why? Proof of Concept exploit, Has a fix available, CVSS 3.7
SNYK-JS-MINIMIST-2429795
Why? Proof of Concept exploit, Has a fix available, CVSS 5.6
SNYK-JS-MINIMIST-559764
Why? Has a fix available, CVSS 7.5
SNYK-JS-MOCHA-2863123
Why? Has a fix available, CVSS 7.5
SNYK-JS-MOMENT-2440688
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
SNYK-JS-MOMENT-2944238
Why? Has a fix available, CVSS 4
SNYK-JS-MONGODBJSMETRICS-1243685
Why? Has a fix available, CVSS 7.5
SNYK-JS-MOUT-1014544
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
SNYK-JS-MOUT-2342654
Why? Proof of Concept exploit, Has a fix available, CVSS 7.3
SNYK-JS-NCONF-2395478
Why? Proof of Concept exploit, Has a fix available, CVSS 7.7
SNYK-JS-NETMASK-1089716
Why? Has a fix available, CVSS 6.5
SNYK-JS-NODEFETCH-2342118
Why? Has a fix available, CVSS 5.9
SNYK-JS-NODEFETCH-674311
Why? Proof of Concept exploit, Has a fix available, CVSS 8.6
SNYK-JS-NODEMAILER-1038834
Why? Proof of Concept exploit, Has a fix available, CVSS 6.3
SNYK-JS-NODEMAILER-1296415
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
SNYK-JS-NTHCHECK-1586032
Why? Proof of Concept exploit, Has a fix available, CVSS 7.3
SNYK-JS-OBJECTPATH-1017036
Why? Proof of Concept exploit, Has a fix available, CVSS 5.6
SNYK-JS-OBJECTPATH-1569453
Why? Proof of Concept exploit, Has a fix available, CVSS 8.1
SNYK-JS-PACRESOLVER-1564857
Why? Proof of Concept exploit, Has a fix available, CVSS 5.3
SNYK-JS-PATHPARSE-1077067
Why? Proof of Concept exploit, Has a fix available, CVSS 6
SNYK-JS-PATHVAL-596926
Why? Proof of Concept exploit, Has a fix available, CVSS 5.3
SNYK-JS-POSTCSS-1255640
Why? Proof of Concept exploit, Has a fix available, CVSS 5.3
SNYK-JS-PROMPTS-1729737
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
SNYK-JS-QS-3153490
Why? Has a fix available, CVSS 5.3
SNYK-JS-RAMDA-1582370
Why? Has a fix available, CVSS 5.3
SNYK-JS-REDIS-1255645
Why? Proof of Concept exploit, Has a fix available, CVSS 6.5
SNYK-JS-SANITIZEHTML-1070780
Why? Has a fix available, CVSS 6.5
SNYK-JS-SANITIZEHTML-1070786
Why? Has a fix available, CVSS 5.3
SNYK-JS-SANITIZEHTML-2957526
Why? Has a fix available, CVSS 9.4
SNYK-JS-SANITIZEHTML-585892
Why? Has a fix available, CVSS 8.1
SNYK-JS-SHELLQUOTE-1766506
Why? Proof of Concept exploit, Has a fix available, CVSS 6.4
SNYK-JS-SNYK-3037342
Why? Proof of Concept exploit, Has a fix available, CVSS 5
SNYK-JS-SNYK-3038622
Why? Has a fix available, CVSS 5.8
SNYK-JS-SNYK-3111871
Why? Proof of Concept exploit, Has a fix available, CVSS 5
SNYK-JS-SNYKDOCKERPLUGIN-3039679
Why? Proof of Concept exploit, Has a fix available, CVSS 6.4
SNYK-JS-SNYKGOPLUGIN-3037316
Why? Proof of Concept exploit, Has a fix available, CVSS 5
SNYK-JS-SNYKGRADLEPLUGIN-3038624
Why? Proof of Concept exploit, Has a fix available, CVSS 5
SNYK-JS-SNYKMVNPLUGIN-3038623
Why? Proof of Concept exploit, Has a fix available, CVSS 5
SNYK-JS-SNYKPYTHONPLUGIN-3039677
Why? Proof of Concept exploit, Has a fix available, CVSS 5
SNYK-JS-SNYKSBTPLUGIN-3038626
Why? Proof of Concept exploit, Has a fix available, CVSS 5
SNYK-JS-SNYKSNYKCOCOAPODSPLUGIN-3038625
Why? Proof of Concept exploit, Has a fix available, CVSS 5.3
SNYK-JS-SOCKETIO-1024859
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
SNYK-JS-SOCKETIOPARSER-1056752
Why? Has a fix available, CVSS 9.8
SNYK-JS-SOCKETIOPARSER-3091012
Why?
SNYK-JS-SSH2-1656673
Why?
SNYK-JS-SSRI-1246392
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
SNYK-JS-TRIM-1017038
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
SNYK-JS-UAPARSERJS-1023599
Why?
SNYK-JS-UAPARSERJS-1072471
Why?
SNYK-JS-UAPARSERJS-610226
Why?
SNYK-JS-UGLIFYJS-1727251
Why?
SNYK-JS-UNDERSCORE-1080984
Why?
SNYK-JS-URLPARSE-1078283
Why?
SNYK-JS-URLPARSE-1533425
Why?
SNYK-JS-URLPARSE-2401205
Why?
SNYK-JS-URLPARSE-2407759
Why?
SNYK-JS-URLPARSE-2407770
Why?
SNYK-JS-URLPARSE-2412697
Why?
SNYK-JS-WS-1296835
Why?
SNYK-JS-XMLHTTPREQUESTSSL-1082936
Why?
SNYK-JS-XMLHTTPREQUESTSSL-1255647
Why? Proof of Concept exploit, Has a fix available, CVSS 7.3
SNYK-JS-Y18N-1021887
Why? Proof of Concept exploit, Has a fix available, CVSS 3.7
npm:braces:20180219
Why? Proof of Concept exploit, Has a fix available, CVSS 3.7
npm:debug:20170905
Why? Proof of Concept exploit, Has a fix available, CVSS 6.3
npm:lodash:20180130
Why?
npm:ms:20170412
Why?
npm:ws:20171108
(*) Note that the real score may have changed since the PR was raised.
Commit messages
Package name: adjust-sourcemap-loader
The new version differs by 21 commits.See the full diff
Package name: aws-sdk
The new version differs by 250 commits.See the full diff
Package name: body-parser
The new version differs by 177 commits.See the full diff
Package name: cacache
The new version differs by 9 commits.See the full diff
Package name: cached-path-relative
The new version differs by 2 commits.See the full diff
Package name: caniuse-api
The new version differs by 14 commits.See the full diff
Package name: create-react-context
The new version differs by 4 commits.See the full diff
Package name: css-loader
The new version differs by 71 commits.See the full diff
Package name: detective-less
The new version differs by 11 commits.See the full diff
Package name: engine.io
The new version differs by 45 commits.See the full diff
Package name: engine.io-client
The new version differs by 56 commits.See the full diff
Package name: eslint-plugin-mocha
The new version differs by 164 commits.