Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update dependency minor versions #591

Merged
merged 1 commit into from
Jun 14, 2023
Merged

Update dependency minor versions #591

merged 1 commit into from
Jun 14, 2023

Conversation

cristianrgreco
Copy link
Collaborator

@cristianrgreco cristianrgreco commented Jun 14, 2023

Resolves following audit report:

# npm audit report

fast-xml-parser  <4.2.4
Severity: high
fast-xml-parser vulnerable to Regex Injection via Doctype Entities - https://github.com/advisories/GHSA-6w63-h3fj-q4vw
fix available via `npm audit fix`
node_modules/fast-xml-parser
  @aws-sdk/client-sts  <=3.54.1 || 3.55.0 - 3.186.1 || 3.188.0 - 3.335.0 || 3.337.0 - 3.347.0
  Depends on vulnerable versions of fast-xml-parser
  node_modules/@aws-sdk/client-sts
    @aws-sdk/client-cognito-identity  3.12.0 - 3.54.1 || 3.55.0 - 3.347.0
    Depends on vulnerable versions of @aws-sdk/client-sts
    node_modules/@aws-sdk/client-cognito-identity
      @aws-sdk/credential-provider-cognito-identity  3.12.0 - 3.347.0
      Depends on vulnerable versions of @aws-sdk/client-cognito-identity
      node_modules/@aws-sdk/credential-provider-cognito-identity
    @aws-sdk/credential-providers  <=3.347.0
    Depends on vulnerable versions of @aws-sdk/client-cognito-identity
    Depends on vulnerable versions of @aws-sdk/client-sts
    Depends on vulnerable versions of @aws-sdk/credential-provider-cognito-identity
    node_modules/@aws-sdk/credential-providers

5 high severity vulnerabilities

@netlify
Copy link

netlify bot commented Jun 14, 2023

Deploy Preview for testcontainers-node ready!

Name Link
🔨 Latest commit cfe3be0
🔍 Latest deploy log https://app.netlify.com/sites/testcontainers-node/deploys/648965ad87232500089caae5
😎 Deploy Preview https://deploy-preview-591--testcontainers-node.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.

To edit notification comments on pull requests, go to your Netlify site settings.

@cristianrgreco cristianrgreco self-assigned this Jun 14, 2023
@cristianrgreco cristianrgreco added maintenance Improvements that do not change functionality patch Backward compatible bug fix labels Jun 14, 2023
@cristianrgreco cristianrgreco marked this pull request as ready for review June 14, 2023 14:36
@cristianrgreco cristianrgreco merged commit 8dbf885 into main Jun 14, 2023
@cristianrgreco cristianrgreco deleted the update-deps-14-06 branch June 14, 2023 14:36
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
maintenance Improvements that do not change functionality patch Backward compatible bug fix
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant