Skip to content

[Snyk] Fix for 2 vulnerabilities#1172

Open
shadow81627 wants to merge 1 commit intomasterfrom
snyk-fix-37b5c1d3b0fec5508a85d93c6df0abd3
Open

[Snyk] Fix for 2 vulnerabilities#1172
shadow81627 wants to merge 1 commit intomasterfrom
snyk-fix-37b5c1d3b0fec5508a85d93c6df0abd3

Conversation

@shadow81627
Copy link
Copy Markdown
Owner

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • package.json

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
high severity 482/1000
Why? Proof of Concept exploit, CVSS 7.5
Regular Expression Denial of Service (ReDoS)
SNYK-JS-NTHCHECK-1586032
No Proof of Concept
medium severity /1000
Why?
Remote Code Execution (RCE)
SNYK-JS-SHARP-2848109
No No Known Exploit

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: sharp The new version differs by 13 commits.
  • db654de Release v0.30.5
  • a6aeef6 Install: pass `PKG_CONFIG_PATH` via env rather than substitution
  • 7bf6cbd Docs: correct links to libvips documentation
  • 04c31b3 Install: warn about filesystem owner running npm v8+ as root
  • ee9cdb6 Bump deps
  • 8960eb8 Docs: changelog entry for #3218
  • 54d9dc4 Fix rotate-then-extract for EXIF orientation 2 (#3218)
  • 51b4a7c Add support for --libc flag to improve cross-platform install (#3160)
  • 5b03579 Docs: more details about concurrency, parallelism, threads
  • 58c2af3 Docs: improve output format info for toBuffer
  • ee948ac Docs: changelog and credit for #3196
  • 66a3ce5 Allow installation of prebuilt libvips binary from filesystem (#3196)
  • 75e5afc Docs: fix typo in gif example (#3201)

See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Regular Expression Denial of Service (ReDoS)

@vercel
Copy link
Copy Markdown

vercel bot commented Feb 24, 2023

The latest updates on your projects. Learn more about Vercel for Git ↗︎

Name Status Preview Comments Updated
daim ❌ Failed (Inspect) Feb 24, 2023 at 11:41PM (UTC)

@cloudflare-workers-and-pages
Copy link
Copy Markdown

cloudflare-workers-and-pages bot commented Feb 24, 2023

Deploying with  Cloudflare Pages  Cloudflare Pages

Latest commit: 788403e
Status:🚫  Build failed.

View logs

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants