Skip to content
This repository was archived by the owner on Aug 19, 2021. It is now read-only.

[Snyk] Fix for 3 vulnerabilities#44

Open
goodrx-security wants to merge 1 commit into
masterfrom
snyk-fix-ff8e465b0cfdd84c4b3c6f0da3cbcbad
Open

[Snyk] Fix for 3 vulnerabilities#44
goodrx-security wants to merge 1 commit into
masterfrom
snyk-fix-ff8e465b0cfdd84c4b3c6f0da3cbcbad

Conversation

@goodrx-security
Copy link
Copy Markdown

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • package.json
    • package-lock.json

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
high severity 696/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
Prototype Pollution
SNYK-JS-IMMER-1019369
Yes Proof of Concept
medium severity 658/1000
Why? Proof of Concept exploit, Recently disclosed, Has a fix available, CVSS 5.3
Regular Expression Denial of Service (ReDoS)
SNYK-JS-LODASH-1018905
No Proof of Concept
high severity 753/1000
Why? Proof of Concept exploit, Recently disclosed, Has a fix available, CVSS 7.2
Command Injection
SNYK-JS-LODASH-1040724
No Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: html-webpack-plugin The new version differs by 66 commits.
  • eb73905 chore(release): 4.0.0
  • 42a6d4a Add typing for getHooks
  • a1a37cf Release html-webpack-plugin 4.0.0-beta.14
  • 97f9fb9 fix: load script files before style files files in defer script loading mode
  • e97ce17 Release html-webpack-plugin 4.0.0-beta.13
  • e448b5d Release html-webpack-plugin 4.0.0-beta.12
  • de315eb feat: Add defer script loading
  • 7df269f feat: Provide a verbose error message if html minification failed
  • 1d66e53 feat: merge templateParameters with default template parameters
  • dfb98e7 Fix typo in template option docts
  • 096a760 Fix broken links in examples
  • a195c34 docs: Update template-option documentation
  • 40b410e docs: Update example for template parameters
  • bf017f3 chore: Release 4.0.0-beta.11
  • 2549557 test: Don't use minification for speed measurement
  • de22fc2 test: Adjust measurment for node 6 on travis
  • 24bf1b5 fix: Update references to html-minifier
  • f4eafdc chore: Release 4.0.0-beta.10
  • a2ad30a refactor: Use getAssetPath instead of calling the hook directly
  • 2595a79 chore: Release 4.0.0-beta.9
  • c66766c feat: Add support for minifying inline ES6 inside html templates
  • 655cbcd Fix README typo
  • 6de319b update lodash dependency for prototype polution vulnerability
  • 35a1541 Properly encode file names emitted as part of URLs.

See the full diff

Package name: react-dev-utils The new version differs by 250 commits.
  • f92c37a Publish
  • cce32fa Update CHANGELOG
  • f710976 Prepare 4.0.3 release
  • 6947896 update immer to 8.0.1 to address vulnerability (#10412)
  • 18b5962 Upgrade eslint-webpack-plugin to fix opt-out flag (#10590)
  • 9722ef1 Bump webpack-dev-server 3.11.0 -> 3.11.1 (#10312)
  • 3f5dea9 tests: update test case to match the description (#10384)
  • 9c75260 Publish
  • 32c06e6 Prepare 4.0.2 release
  • b9963ab Add opt-out for eslint-webpack-plugin (#10170)
  • 8fa0a26 Add support for new BUILD_PATH advanced configuration variable (#8986)
  • 6a39607 appTsConfig immutability handling by immer (#10027)
  • d229676 Fix CI tests (#10217)
  • c9a24db docs: add missing override options for Jest config (#9473)
  • 0f6fc2b Update using-the-public-folder.md (#10314)
  • a504e9d fix(react-scripts): add missing peer dependency react and update react-refresh-webpack-plugin (#9872)
  • 282c03f Remove references to Node 8 (#10214)
  • 3968923 Revert "Update postcss packages" (#10216)
  • e039ad3 Move ESLint cache file into node_modules (#9977)
  • 6dce3f4 Upgrade sass-loader (#9988)
  • 54ad467 Recovered some integration tests (#10091)
  • 580ed5d Update postcss packages (#10003)
  • 8f2413e Improve vendor chunk names in development (#9569)
  • 723224f Upgrade @ svgr/webpack to fix build error (#10213)

See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants