fix(dependencies): Upgraded dependencies to fix 3rd party vulnerabilities#20
Open
tchopra91 wants to merge 1 commit intoBALKANGraph:masterfrom
Open
fix(dependencies): Upgraded dependencies to fix 3rd party vulnerabilities#20tchopra91 wants to merge 1 commit intoBALKANGraph:masterfrom
tchopra91 wants to merge 1 commit intoBALKANGraph:masterfrom
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
// Run npm install puppeteer@13.7.0 to resolve 1 vulnerability
SEMVER WARNING: Recommended action is a potentially breaking change
High node-fetch is vulnerable to Exposure of Sensitive
Information to an Unauthorized Actor
Package node-fetch
Dependency of puppeteer
Path puppeteer > node-fetch
More info GHSA-r683-j2x4-v87g
// Run npm update color-string --depth 5 to resolve 1 vulnerability
Moderate Regular Expression Denial of Service (ReDOS)
Package color-string
Dependency of winston
Path winston > diagnostics > colorspace > color > color-string
More info GHSA-257v-vj4p-3w2h
// Run npm update lodash --depth 3 to resolve 4 vulnerabilities
Critical Prototype Pollution in lodash
Package lodash
Dependency of winston
Path winston > async > lodash
More info GHSA-jf85-cpcp-j695
High Command Injection in lodash
Package lodash
Dependency of winston
Path winston > async > lodash
More info GHSA-35jh-r3h4-6jhm
Moderate Regular Expression Denial of Service (ReDoS) in lodash
Package lodash
Dependency of winston
Path winston > async > lodash
More info GHSA-29mw-wpgm-hmr9
High Prototype Pollution in lodash
Package lodash
Dependency of winston
Path winston > async > lodash
More info GHSA-p6mc-m468-83gw
// Run npm update async --depth 2 to resolve 1 vulnerability
High Prototype Pollution in async
Package async
Dependency of winston
Path winston > async
More info GHSA-fwr7-v2mv-hh25
found 7 vulnerabilities (2 moderate, 4 high, 1 critical) in 160 scanned packages