Skip to content

[Snyk] Fix for 3 vulnerabilities#39

Open
INT2ECALL wants to merge 1 commit intomasterfrom
snyk-fix-03240eda40c7c1b93054f1b4b4e638d6
Open

[Snyk] Fix for 3 vulnerabilities#39
INT2ECALL wants to merge 1 commit intomasterfrom
snyk-fix-03240eda40c7c1b93054f1b4b4e638d6

Conversation

@INT2ECALL
Copy link
Copy Markdown
Owner

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • Themes/Adminlte/package.json
    • Themes/Adminlte/package-lock.json

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
high severity 828/1000
Why? Proof of Concept exploit, Recently disclosed, Has a fix available, CVSS 8.7
Improper Verification of Cryptographic Signature
SNYK-JS-ELLIPTIC-8187303
Yes Proof of Concept
medium severity 541/1000
Why? Recently disclosed, Has a fix available, CVSS 5.1
Cross-site Scripting (XSS)
SNYK-JS-JQUERYUI-8230415
Yes No Known Exploit
low severity 498/1000
Why? Proof of Concept exploit, Recently disclosed, Has a fix available, CVSS 2.1
Regular Expression Denial of Service (ReDoS)
SNYK-JS-VUE-8219889
Yes Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: admin-lte The new version differs by 250 commits.
  • e78ee8d prep version
  • 5198872 updated README.md
  • b7a1c87 fixed card default border after adding nav tabs support
  • 2ea45f2 fixed labels in issue templates
  • 6457d31 added forget password & recover password demo
  • c4b9059 added new issue templates
  • bed1408 updated install instructions in docs/index.md
  • 54adf72 fixed focus border in mozilla (bug with focusring removal)
  • d5404fb removed node_js 9 from .travis.yml
  • ec0cf8a corrected select2 paddings to change look similar to form-control/custom-form select
  • 4d13072 added job exclude in .travis.yml
  • 08c597d added .travis.yml
  • 67024d8 added .nav-legacy & .nav-collapse-hide-child docs part
  • 60830bb fixed select2 paddings/margins
  • 448556d fixed mozilla focusring outline
  • e8ddb64 removed mozilla dotted border from focus links
  • e7d646c some little fixes
  • 090bffc prep version
  • 9252541 enhanced scss structure & compiled size
  • f60e062 changed user-image size/margin in .user-menu
  • 139fbd3 fixed box-shadow with select2 bootstrap4 theme
  • 242ef89 fixed select2 init bug in forms/advanced.html
  • acf9fe8 added bs-custom-file-input plugin
  • 247b797 changed input placeholder color with lighten

See the full diff

Package name: gridstack The new version differs by 250 commits.
  • 6fb3d87 v0.5.4 release
  • 47c5a32 tweaks to cellHeight() tests
  • 31f35ef test case for #1068
  • 65accb4 reverted #1047 (updating styles)
  • 7463cef test case for #1054
  • 3c8d9d3 griditems with x=0 placement fix
  • b31a569 changed jquery to "^1.8 || 2 || 3"
  • 0a51f87 add `jquery-ui.js` minimal need
  • c3a5e03 readme tweak
  • b253aaa new `gridstack.poly.js` for IE and older browsers
  • 905f6c8 next release rev
  • ea9254d release 0.5.3 - part 2
  • 95f5a3a 0.5.3 release
  • 1ea827f changes.md tweaks
  • 3449bde renamed setGridWidth() to setColumn()
  • 9c60e28 format tweak to typescript def file
  • fffdfaf change grid prop to 'column' & 'maxRow' (singular)
  • a4e62e2 Merge pull request #1053 from adumesny/bugfix/810
  • 2f57d59 lint fix
  • b0435ba added obsoleteAttr() check
  • 0fc6185 obsoleteOpts() tweaks
  • 2299d03 options rename to `columns` & `maxRows`
  • cb76958 changes update
  • 673a92f many columns test case, some fixes

See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Cross-site Scripting (XSS)
🦉 Regular Expression Denial of Service (ReDoS)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants