Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Snyk] Fix for 68 vulnerabilities #1046

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

snyk-bot
Copy link

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • test/fixtures/demo-os/package.json
    • test/fixtures/demo-os/.snyk

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
high severity 696/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
Regular Expression Denial of Service (ReDoS)
SNYK-JS-ANSIREGEX-1583908
No Proof of Concept
high severity 706/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 7.7
Remote Memory Exposure
SNYK-JS-BL-608877
No Proof of Concept
high severity 614/1000
Why? Has a fix available, CVSS 8
Arbitrary File Write via Archive Extraction (Zip Slip)
SNYK-JS-BOWER-73627
No No Known Exploit
medium severity 586/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 5.3
Regular Expression Denial of Service (ReDoS)
SNYK-JS-COOKIEJAR-3149984
Yes Proof of Concept
critical severity 704/1000
Why? Has a fix available, CVSS 9.8
Arbitrary File Write via Archive Extraction (Zip Slip)
SNYK-JS-DECOMPRESSZIP-73598
No No Known Exploit
high severity /1000
Why?
Denial of Service (DoS)
SNYK-JS-ENGINEIO-1056749
No Proof of Concept
high severity /1000
Why?
Denial of Service (DoS)
SNYK-JS-ENGINEIO-3136336
No No Known Exploit
high severity /1000
Why?
Prototype Pollution
SNYK-JS-GETOBJECT-1054932
Yes No Known Exploit
medium severity 484/1000
Why? Has a fix available, CVSS 5.4
Open Redirect
SNYK-JS-GOT-2932019
No No Known Exploit
medium severity 636/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 6.3
Directory Traversal
SNYK-JS-GRUNT-2635969
Yes Proof of Concept
medium severity 646/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 6.5
Race Condition
SNYK-JS-GRUNT-2813632
Yes Proof of Concept
high severity 569/1000
Why? Has a fix available, CVSS 7.1
Arbitrary Code Execution
SNYK-JS-GRUNT-597546
Yes No Known Exploit
high severity 671/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 7
Remote Code Execution (RCE)
SNYK-JS-HANDLEBARS-1056767
No Proof of Concept
medium severity 601/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 5.6
Prototype Pollution
SNYK-JS-HANDLEBARS-1279029
No Proof of Concept
high severity 579/1000
Why? Has a fix available, CVSS 7.3
Prototype Pollution
SNYK-JS-HANDLEBARS-173692
No No Known Exploit
high severity 579/1000
Why? Has a fix available, CVSS 7.3
Prototype Pollution
SNYK-JS-HANDLEBARS-469063
No No Known Exploit
high severity 726/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 8.1
Arbitrary Code Execution
SNYK-JS-HANDLEBARS-534478
No Proof of Concept
critical severity 704/1000
Why? Has a fix available, CVSS 9.8
Prototype Pollution
SNYK-JS-HANDLEBARS-534988
No No Known Exploit
medium severity 646/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 6.5
Prototype Pollution
SNYK-JS-HANDLEBARS-567742
No Proof of Concept
high severity 584/1000
Why? Has a fix available, CVSS 7.4
Regular Expression Denial of Service (ReDoS)
SNYK-JS-HAWK-2808852
No No Known Exploit
high severity 619/1000
Why? Has a fix available, CVSS 8.1
Arbitrary Code Execution
SNYK-JS-JSYAML-174129
Yes No Known Exploit
medium severity 586/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 5.3
Regular Expression Denial of Service (ReDoS)
SNYK-JS-LODASH-1018905
Yes Proof of Concept
high severity 681/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 7.2
Command Injection
SNYK-JS-LODASH-1040724
Yes Proof of Concept
high severity 686/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 7.3
Prototype Pollution
SNYK-JS-LODASH-450202
Yes Proof of Concept
high severity 731/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 8.2
Prototype Pollution
SNYK-JS-LODASH-567746
Yes Proof of Concept
high severity 686/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 7.3
Prototype Pollution
SNYK-JS-LODASH-608086
Yes Proof of Concept
high severity 686/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 7.3
Prototype Pollution
SNYK-JS-LODASH-73638
Yes Proof of Concept
medium severity 541/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 4.4
Regular Expression Denial of Service (ReDoS)
SNYK-JS-LODASH-73639
Yes Proof of Concept
high severity 589/1000
Why? Has a fix available, CVSS 7.5
Regular Expression Denial of Service (ReDoS)
SNYK-JS-MINIMATCH-1019388
Yes No Known Exploit
medium severity 479/1000
Why? Has a fix available, CVSS 5.3
Regular Expression Denial of Service (ReDoS)
SNYK-JS-MINIMATCH-3050818
Yes No Known Exploit
low severity 506/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 3.7
Prototype Pollution
SNYK-JS-MINIMIST-2429795
Yes Proof of Concept
medium severity 601/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 5.6
Prototype Pollution
SNYK-JS-MINIMIST-559764
Yes Proof of Concept
high severity /1000
Why?
Regular Expression Denial of Service (ReDoS)
SNYK-JS-MOCHA-561476
Yes No Known Exploit
high severity 589/1000
Why? Has a fix available, CVSS 7.5
Prototype Pollution
SNYK-JS-MOUT-1014544
No No Known Exploit
high severity 696/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
Prototype Pollution
SNYK-JS-MOUT-2342654
No Proof of Concept
high severity 696/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
Prototype Poisoning
SNYK-JS-QS-3153490
Yes Proof of Concept
medium severity /1000
Why?
Insecure Defaults
SNYK-JS-SOCKETIO-1024859
No Proof of Concept
high severity /1000
Why?
Denial of Service (DoS)
SNYK-JS-SOCKETIOPARSER-1056752
No Proof of Concept
critical severity 704/1000
Why? Has a fix available, CVSS 9.8
Improper Input Validation
SNYK-JS-SOCKETIOPARSER-3091012
No No Known Exploit
high severity /1000
Why?
Denial of Service (DoS)
SNYK-JS-TRIMNEWLINES-1298042
No No Known Exploit
medium severity 479/1000
Why? Has a fix available, CVSS 5.3
Regular Expression Denial of Service (ReDoS)
SNYK-JS-UGLIFYJS-1727251
Yes No Known Exploit
medium severity 586/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 5.3
Regular Expression Denial of Service (ReDoS)
SNYK-JS-WS-1296835
No Proof of Concept
medium severity 658/1000
Why? Proof of Concept exploit, Recently disclosed, Has a fix available, CVSS 5.3
Prototype Pollution
SNYK-JS-XML2JS-5414874
Yes Proof of Concept
medium severity 484/1000
Why? Has a fix available, CVSS 5.4
XML External Entity (XXE) Injection
SNYK-JS-XMLDOM-1084960
Yes No Known Exploit
low severity 506/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 3.7
Regular Expression Denial of Service (ReDoS)
npm:debug:20170905
Yes Proof of Concept
high severity /1000
Why?
Prototype Pollution
npm:deep-extend:20180409
No Proof of Concept
high severity /1000
Why?
Prototype Pollution
npm:extend:20180424
Yes No Known Exploit
critical severity /1000
Why?
Arbitrary Code Injection
npm:growl:20160721
Yes No Known Exploit
medium severity /1000
Why?
Cross-site Scripting (XSS)
npm:handlebars:20151207
No No Known Exploit
low severity /1000
Why?
Regular Expression Denial of Service (ReDoS)
npm:hawk:20160119
No No Known Exploit
medium severity /1000
Why?
Prototype Pollution
npm:hoek:20180212
No Proof of Concept
medium severity /1000
Why?
Timing Attack
npm:http-signature:20150122
No No Known Exploit
medium severity 636/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 6.3
Prototype Pollution
npm:lodash:20180130
Yes Proof of Concept
low severity /1000
Why?
Regular Expression Denial of Service (ReDoS)
npm:mime:20170907
Yes No Known Exploit
high severity 589/1000
Why? Has a fix available, CVSS 7.5
Regular Expression Denial of Service (ReDoS)
npm:minimatch:20160620
Yes No Known Exploit
medium severity /1000
Why?
Regular Expression Denial of Service (ReDoS)
npm:ms:20151024
Yes No Known Exploit
low severity /1000
Why?
Regular Expression Denial of Service (ReDoS)
npm:ms:20170412
Yes No Known Exploit
high severity 589/1000
Why? Has a fix available, CVSS 7.5
Prototype Override Protection Bypass
npm:qs:20170213
Yes No Known Exploit
medium severity /1000
Why?
Remote Memory Exposure
npm:request:20160119
No No Known Exploit
medium severity /1000
Why?
Regular Expression Denial of Service (ReDoS)
npm:semver:20150403
No No Known Exploit
low severity /1000
Why?
Denial of Service (DoS)
npm:superagent:20170807
Yes No Known Exploit
medium severity /1000
Why?
Information Exposure
npm:superagent:20181108
Yes No Known Exploit
high severity /1000
Why?
Regular Expression Denial of Service (ReDoS)
npm:tough-cookie:20160722
No No Known Exploit
medium severity /1000
Why?
Regular Expression Denial of Service (ReDoS)
npm:tough-cookie:20170905
No No Known Exploit
medium severity /1000
Why?
Uninitialized Memory Exposure
npm:tunnel-agent:20170305
No Proof of Concept
high severity 629/1000
Why? Has a fix available, CVSS 8.3
Improper minification of non-boolean comparisons
npm:uglify-js:20150824
No No Known Exploit
medium severity 479/1000
Why? Has a fix available, CVSS 5.3
Regular Expression Denial of Service (ReDoS)
npm:uglify-js:20151024
No No Known Exploit

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: csscomb The new version differs by 50 commits.

See the full diff

Package name: grunt-contrib-compress The new version differs by 69 commits.

See the full diff

Package name: grunt-contrib-uglify The new version differs by 107 commits.

See the full diff

Package name: grunt-jscs The new version differs by 24 commits.
  • d13072f Release v2.3.0
  • d8fef95 Update jscs to 2.5.0 version
  • c272f8f Release v2.2.0
  • 4767f7f Check 4. and .12 nodes with travis CI
  • cc63399 Update "load-grunt-tasks" dependency
  • 1e4c9bf Use "idiomatic" preset instead of "jquery"
  • 0c86a48 Use new "Checker#execute" method
  • 6011f05 Release v2.1.0
  • 31f9ced Release v2.0.1
  • 3f2499e Update dependencies
  • 302d8da Use Travis CI container-based builds
  • 4a34df6 Release v2.0.0
  • 9e6d86e Update dependecies
  • 17f9e9c Bump jscs version to 2.0.0
  • 8715716 Fix code style issues
  • ad532e2 Update package.json
  • 49936c6 Add enmasse testing merge with path config and inline options
  • 330f2bc Merge branch 'remove-grunt-bump'
  • 34dba9c Change package.json indent size to 2
  • 8c7064b Document how to publish a new version
  • de383ba Create npm scripts to bump version
  • 1e60f29 Remove grunt-bump and the bump task
  • 37a7757 Correct docs example
  • b2d9ff9 Improve doc examples

See the full diff

Package name: grunt-mocha-cli The new version differs by 56 commits.

See the full diff

Package name: nock The new version differs by 250 commits.

See the full diff

Package name: supertest The new version differs by 72 commits.

See the full diff

Package name: testem The new version differs by 250 commits.

See the full diff

With a Snyk patch:
Severity Priority Score (*) Issue Exploit Maturity
low severity 506/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 3.7
Regular Expression Denial of Service (ReDoS)
npm:debug:20170905
Proof of Concept
medium severity 636/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 6.3
Prototype Pollution
npm:lodash:20180130
Proof of Concept
high severity 589/1000
Why? Has a fix available, CVSS 7.5
Regular Expression Denial of Service (ReDoS)
npm:minimatch:20160620
No Known Exploit
low severity /1000
Why?
Regular Expression Denial of Service (ReDoS)
npm:ms:20170412
No Known Exploit
medium severity 539/1000
Why? Has a fix available, CVSS 6.5
Denial of Service (DoS)
npm:qs:20140806-1
No Known Exploit

(*) Note that the real score may have changed since the PR was raised.

Some vulnerabilities couldn't be fully fixed and so Snyk will still find them when the project is tested again. This may be because the vulnerability existed within more than one direct dependency, but not all of the affected dependencies could be upgraded.

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic

[//]: # (snyk:metadata:{"prId":"c8961ffb-5dd7-42df-8132-fefdd92740fe","prPublicId":"c8961ffb-5dd7-42df-8132-fefdd92740fe","dependencies":[{"name":"bower","from":"1.4.1","to":"1.8.8"},{"name":"csscomb","from":"3.0.4","to":"3.1.0"},{"name":"grunt","from":"0.4.5","to":"1.5.3"},{"name":"grunt-cli","from":"0.1.13","to":"1.3.0"},{"name":"grunt-contrib-compress","from":"0.13.0","to":"1.3.0"},{"name":"grunt-contrib-uglify","from":"0.9.1","to":"4.0.1"},{"name":"grunt-contrib-watch","from":"0.6.1","to":"1.0.1"},{"name":"grunt-jscs","from":"1.8.0","to":"2.3.0"},{"name":"grunt-mocha-cli","from":"1.13.0","to":"5.0.0"},{"name":"matchdep","from":"0.3.0","to":"1.0.1"},{"name":"nock","from":"2.3.0","to":"8.0.0"},{"name":"nodemailer","from":"0.7.1","to":"1.0.0"},{"name":"supertest","from":"1.0.1","to":"3.0.0"},{"name":"testem","from":"0.8.3","to":"3.4.1"},{"name":"top-gh-contribs","from":"2.0.2","to":"2.0.3"}],"packageManager":"npm","projectPublicId":"4f7ed5c2-f1d8-467a-8a73-f0ca85d000ea","projectUrl":"https://app.snyk.io/org/luxmedia/project/4f7ed5c2-f1d8-467a-8a73-f0ca85d000ea?utm_source=github&utm_medium=referral&page=fix-pr","type":"auto","patch":["npm:debug:20170905","npm:lodash:20180130","npm:minimatch:20160620","npm:ms:20170412","npm:qs:20140806-1"],"vulns":["SNYK-JS-ANSIREGEX-1583908","SNYK-JS-BL-608877","SNYK-JS-BOWER-73627","SNYK-JS-COOKIEJAR-3149984","SNYK-JS-DECOMPRESSZIP-73598","SNYK-JS-ENGINEIO-1056749","SNYK-JS-ENGINEIO-3136336","SNYK-JS-GETOBJECT-1054932","SNYK-JS-GOT-2932019","SNYK-JS-GRUNT-2635969","SNYK-JS-GRUNT-2813632","SNYK-JS-GRUNT-597546","SNYK-JS-HANDLEBARS-1056767","SNYK-JS-HANDLEBARS-1279029","SNYK-JS-HANDLEBARS-173692","SNYK-JS-HANDLEBARS-469063","SNYK-JS-HANDLEBARS-534478","SNYK-JS-HANDLEBARS-534988","SNYK-JS-HANDLEBARS-567742","npm:handlebars:20151207","SNYK-JS-HAWK-2808852","npm:hawk:20160119","SNYK-JS-JSYAML-174129","SNYK-JS-LODASH-1018905","SNYK-JS-LODASH-1040724","SNYK-JS-LODASH-450202","SNYK-JS-LODASH-567746","SNYK-JS-LODASH-608086","SNYK-JS-LODASH-73638","SNYK-JS-LODASH-73639","npm:lodash:20180130","SNYK-JS-MINIMATCH-1019388","SNYK-JS-MINIMATCH-3050818","npm:minimatch:20160620","SNYK-JS-MINIMIST-2429795","SNYK-JS-MINIMIST-559764","SNYK-JS-MOCHA-561476","SNYK-JS-MOUT-1014544","SNYK-JS-MOUT-2342654","SNYK-JS-QS-3153490","npm:qs:20170213","npm:qs:20140806","npm:qs:20140806-1","npm:request:20160119","SNYK-JS-SOCKETIO-1024859","SNYK-JS-SOCKETIOPARSER-1056752","SNYK-JS-SOCKETIOPARSER-3091012","SNYK-JS-TRIMNEWLINES-1298042","SNYK-JS-UGLIFYJS-1727251","npm:uglify-js:20150824","npm:uglify-js:20151024","SNYK-JS-WS-1296835","SNYK-JS-XML2JS-5414874","SNYK-JS-XMLDOM-1084960","npm:debug:20170905","npm:deep-extend:20180409","npm:extend:20180424","npm:growl:20160721","npm:hoek:20180212","npm:http-signature:20150122","npm:mime:20170907","npm:ms:20151024","npm:ms:20170412","npm:semver:20150403","npm:superagent:20170807","npm:superagent:20181108","npm:tough-cookie:20160722","npm:tough-cookie:20170905","npm:tunnel-agent:20170305"],"upgrade":["SNYK-JS-ANSIREGEX-1583908","SNYK-JS-BL-608877","SNYK-JS-BOWER-73627","SNYK-JS-COOKIEJAR-3149984","SNYK-JS-DECOMPRESSZIP-73598","SNYK-JS-ENGINEIO-1056749","SNYK-JS-ENGINEIO-3136336","SNYK-JS-GETOBJECT-1054932","SNYK-JS-GOT-2932019","SNYK-JS-GRUNT-2635969","SNYK-JS-GRUNT-2813632","SNYK-JS-GRUNT-597546","SNYK-JS-HANDLEBARS-1056767","SNYK-JS-HANDLEBARS-1279029","SNYK-JS-HANDLEBARS-173692","SNYK-JS-HANDLEBARS-469063","SNYK-JS-HANDLEBARS-534478","SNYK-JS-HANDLEBARS-534988","SNYK-JS-HANDLEBARS-567742","SNYK-JS-HAWK-2808852","SNYK-JS-JSYAML-174129","SNYK-JS-LODASH-1018905","SNYK-JS-LODASH-1040724","SNYK-JS-LODASH-450202","SNYK-JS-LODASH-567746","SNYK-JS-LODASH-608086","SNYK-JS-LODASH-73638","SNYK-JS-LODASH-73639","SNYK-JS-MINIMATCH-1019388","SNYK-JS-MINIMATCH-3050818","SNYK-JS-MINIMIST-2429795","SNYK-JS-MINIMIST-559764","SNYK-JS-MOCHA-561476","SNYK-JS-MOUT-1014544","SNYK-JS-MOUT-2342654","SNYK-JS-QS-3153490","SNYK-JS-SOCKETIO-1024859","SNYK-JS-SOCKETIOPARSER-1056752","SNYK-JS-SOCKETIOPARSER-3091012","SNYK-JS-TRIMNEWLINES-1298042","SNYK-JS-UGLIFYJS-1727251","SNYK-JS-WS-1296835","SNYK-JS-XML2JS-5414874","SNYK-JS-XMLDOM-1084960","npm:debug:20170905","npm:deep-extend:20180409","npm:extend:20180424","npm:growl:20160721","npm:handlebars:20151207","npm:hawk:20160119","npm:hoek:20180212","npm:http-signature:20150122","npm:lodash:20180130","npm:mime:20170907","npm:minimatch:20160620","npm:ms:20151024","npm:ms:20170412","npm:qs:20170213","npm:request:20160119","npm:semver:20150403","npm:superagent:20170807","npm:superagent:20181108","npm:tough-cookie:20160722","npm:tough-cookie:20170905","npm:tunnel-agent:20170305","npm:uglify-js:20150824","npm:uglify-js:20151024"],"isBreakingChange":true,"env":"prod","prType":"fix","templateVariants":["priorityScore"],"priorityScoreList":[696,706,614,586,704,null,n...

… to reduce vulnerabilities

The following vulnerabilities are fixed with an upgrade:
- https://snyk.io/vuln/SNYK-JS-ANSIREGEX-1583908
- https://snyk.io/vuln/SNYK-JS-BL-608877
- https://snyk.io/vuln/SNYK-JS-BOWER-73627
- https://snyk.io/vuln/SNYK-JS-COOKIEJAR-3149984
- https://snyk.io/vuln/SNYK-JS-DECOMPRESSZIP-73598
- https://snyk.io/vuln/SNYK-JS-ENGINEIO-1056749
- https://snyk.io/vuln/SNYK-JS-ENGINEIO-3136336
- https://snyk.io/vuln/SNYK-JS-GETOBJECT-1054932
- https://snyk.io/vuln/SNYK-JS-GOT-2932019
- https://snyk.io/vuln/SNYK-JS-GRUNT-2635969
- https://snyk.io/vuln/SNYK-JS-GRUNT-2813632
- https://snyk.io/vuln/SNYK-JS-GRUNT-597546
- https://snyk.io/vuln/SNYK-JS-HANDLEBARS-1056767
- https://snyk.io/vuln/SNYK-JS-HANDLEBARS-1279029
- https://snyk.io/vuln/SNYK-JS-HANDLEBARS-173692
- https://snyk.io/vuln/SNYK-JS-HANDLEBARS-469063
- https://snyk.io/vuln/SNYK-JS-HANDLEBARS-534478
- https://snyk.io/vuln/SNYK-JS-HANDLEBARS-534988
- https://snyk.io/vuln/SNYK-JS-HANDLEBARS-567742
- https://snyk.io/vuln/SNYK-JS-HAWK-2808852
- https://snyk.io/vuln/SNYK-JS-JSYAML-174129
- https://snyk.io/vuln/SNYK-JS-LODASH-1018905
- https://snyk.io/vuln/SNYK-JS-LODASH-1040724
- https://snyk.io/vuln/SNYK-JS-LODASH-450202
- https://snyk.io/vuln/SNYK-JS-LODASH-567746
- https://snyk.io/vuln/SNYK-JS-LODASH-608086
- https://snyk.io/vuln/SNYK-JS-LODASH-73638
- https://snyk.io/vuln/SNYK-JS-LODASH-73639
- https://snyk.io/vuln/SNYK-JS-MINIMATCH-1019388
- https://snyk.io/vuln/SNYK-JS-MINIMATCH-3050818
- https://snyk.io/vuln/SNYK-JS-MINIMIST-2429795
- https://snyk.io/vuln/SNYK-JS-MINIMIST-559764
- https://snyk.io/vuln/SNYK-JS-MOCHA-561476
- https://snyk.io/vuln/SNYK-JS-MOUT-1014544
- https://snyk.io/vuln/SNYK-JS-MOUT-2342654
- https://snyk.io/vuln/SNYK-JS-QS-3153490
- https://snyk.io/vuln/SNYK-JS-SOCKETIO-1024859
- https://snyk.io/vuln/SNYK-JS-SOCKETIOPARSER-1056752
- https://snyk.io/vuln/SNYK-JS-SOCKETIOPARSER-3091012
- https://snyk.io/vuln/SNYK-JS-TRIMNEWLINES-1298042
- https://snyk.io/vuln/SNYK-JS-UGLIFYJS-1727251
- https://snyk.io/vuln/SNYK-JS-WS-1296835
- https://snyk.io/vuln/SNYK-JS-XML2JS-5414874
- https://snyk.io/vuln/SNYK-JS-XMLDOM-1084960
- https://snyk.io/vuln/npm:debug:20170905
- https://snyk.io/vuln/npm:deep-extend:20180409
- https://snyk.io/vuln/npm:extend:20180424
- https://snyk.io/vuln/npm:growl:20160721
- https://snyk.io/vuln/npm:handlebars:20151207
- https://snyk.io/vuln/npm:hawk:20160119
- https://snyk.io/vuln/npm:hoek:20180212
- https://snyk.io/vuln/npm:http-signature:20150122
- https://snyk.io/vuln/npm:lodash:20180130
- https://snyk.io/vuln/npm:mime:20170907
- https://snyk.io/vuln/npm:minimatch:20160620
- https://snyk.io/vuln/npm:ms:20151024
- https://snyk.io/vuln/npm:ms:20170412
- https://snyk.io/vuln/npm:qs:20170213
- https://snyk.io/vuln/npm:request:20160119
- https://snyk.io/vuln/npm:semver:20150403
- https://snyk.io/vuln/npm:superagent:20170807
- https://snyk.io/vuln/npm:superagent:20181108
- https://snyk.io/vuln/npm:tough-cookie:20160722
- https://snyk.io/vuln/npm:tough-cookie:20170905
- https://snyk.io/vuln/npm:tunnel-agent:20170305
- https://snyk.io/vuln/npm:uglify-js:20150824
- https://snyk.io/vuln/npm:uglify-js:20151024


The following vulnerabilities are fixed with a Snyk patch:
- https://snyk.io/vuln/npm:debug:20170905
- https://snyk.io/vuln/npm:lodash:20180130
- https://snyk.io/vuln/npm:minimatch:20160620
- https://snyk.io/vuln/npm:ms:20170412
- https://snyk.io/vuln/npm:qs:20140806-1
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant