Skip to content

[Snyk] Fix for 8 vulnerabilities#6

Open
rx007 wants to merge 1 commit into
masterfrom
snyk-fix-1f921667eb866e2b5ad2806ad13cd525
Open

[Snyk] Fix for 8 vulnerabilities#6
rx007 wants to merge 1 commit into
masterfrom
snyk-fix-1f921667eb866e2b5ad2806ad13cd525

Conversation

@rx007

@rx007 rx007 commented Nov 27, 2023

Copy link
Copy Markdown
Owner

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • package.json

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
medium severity 651/1000
Why? Mature exploit, Has a fix available, CVSS 5.3
Regular Expression Denial of Service (ReDoS)
SNYK-JS-ANGULAR-2772735
Yes Mature
medium severity 531/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 4.2
Cross-site Scripting (XSS)
SNYK-JS-ANGULAR-2949781
Yes Proof of Concept
medium severity 586/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 5.3
Regular Expression Denial of Service (ReDoS)
SNYK-JS-ANGULAR-3373044
Yes Proof of Concept
medium severity 586/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 5.3
Regular Expression Denial of Service (ReDoS)
SNYK-JS-ANGULAR-3373045
Yes Proof of Concept
medium severity 586/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 5.3
Regular Expression Denial of Service (ReDoS)
SNYK-JS-ANGULAR-3373046
Yes Proof of Concept
high severity 696/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
Regular Expression Denial of Service (ReDoS)
SNYK-JS-ANSIREGEX-1583908
Yes Proof of Concept
medium severity 646/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 6.5
Server-side Request Forgery (SSRF)
SNYK-JS-REQUEST-3361831
Yes Proof of Concept
medium severity 646/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 6.5
Prototype Pollution
SNYK-JS-TOUGHCOOKIE-5672873
Yes Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: angular-ui-router The new version differs by 250 commits.
  • 1b34e08 chore(docs): Add publishdocs script
  • 4cdc307 chore(release): Fix artifacts uploda script
  • ea443d8 Release 1.0.0
  • 7018915 chore(build): bump core to 5.0.1
  • 4539e4a chore(travis): Fix travis
  • 74338aa chore(package): Rename angular-ui-router vestiges to @ uirouter/angularjs
  • 4919a3a Prep for @ uirouter/angularjs release 1.0.0
  • 07c9136 sq
  • 043be3e sq
  • dd26d49 feat(core): Add UMD bundle adapter for @ uirouter/core
  • a26ed81 chore(migrate): Add migration warning on install
  • 8d62b0d chore(core): Switch from ui-router-core to @ uirouter/core
  • af0b8d4 chore(*): artifact tagging script
  • 7a086ee fix(uiCanExit): Only process uiCanExit hook once during redirects
  • 8fe5b1f fix(view): Allow targeting nested named ui-view by simple ui-view name
  • ec6e5e4 fix(noImplicitAny): move noimplicitany compliance test file to correct location
  • df6ee24 fix(onEnter): Fix typescript typing for onEnter/onRetain/onExit
  • 4559c32 fix(routeToComponent): Bind resolves that start with data- or x-
  • 8e7386b chore(typescript): Add noImplicitAny compliance check in `test` script
  • 60e7407 chore(travis): bump travis node requirement
  • b4863cf chore(ISSUE_TEMPLATE): create issue template
  • a04674c chore(ISSUE_TEMPLATE): create issue template
  • 7573156 fix(views): Better validation of view declarations (throw when there are state-level and view-level conflicts)
  • 66103fc fix(views): Allow same views object to be reused in multiple states

See the full diff

Package name: npm The new version differs by 250 commits.
  • 3b4ba65 7.0.0
  • bbfc75d chore: fix weird .gitignore thing that happened somehow
  • 8a2d375 docs: changelog for v7.0.0
  • 365f2e7 read-package-json@3.0.0
  • fafb348 npm-package-arg@8.1.0
  • 9306c68 libnpmfund@1.0.1
  • 569cd64 libnpmfund@1.0.0
  • ac9fde7 Integration code for @ npmcli/arborist@1.0.0
  • 704b9cd @ npmcli/arborist@1.0.0
  • 3955bb9 hosted-git-info@3.0.6
  • da240ef fix: patch config.js to remove duplicate values
  • 9ae45a8 init-package-json@2.0.0
  • 41ab36d eslint@7.11.0
  • c474a15 npm-registry-fetch@8.1.5
  • efc6786 fix: make sure publishConfig is passed through
  • 1e4e6e9 docs: v7 using npm config refresh
  • 5c1c2da fix: init config aliases
  • 5bc7eb2 docs: v7 npm-install refresh
  • 1a35d87 7.0.0-rc.4
  • 7a5a557 docs: changelog for v7.0.0-rc.4
  • f0cf859 chore: dedupe deps
  • 0273745 make-fetch-happen@8.0.10
  • 7bd47ca @ npmcli/arborist@0.0.33
  • 9320b8e only escape arguments, not the command name

See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Regular Expression Denial of Service (ReDoS)
🦉 Cross-site Scripting (XSS)
🦉 Server-side Request Forgery (SSRF)
🦉 More lessons are available in Snyk Learn

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants