Skip to content

[Snyk] Fix for 1 vulnerabilities#1

Open
naiba4 wants to merge 1 commit intomasterfrom
snyk-fix-84301215ee52bff119814d0943c47c09
Open

[Snyk] Fix for 1 vulnerabilities#1
naiba4 wants to merge 1 commit intomasterfrom
snyk-fix-84301215ee52bff119814d0943c47c09

Conversation

@naiba4
Copy link
Owner

@naiba4 naiba4 commented Dec 1, 2023

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to fix one or more vulnerable packages in the `yarn` dependencies of this project.

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • package.json

Note for zero-installs users

If you are using the Yarn feature zero-installs that was introduced in Yarn V2, note that this PR does not update the .yarn/cache/ directory meaning this code cannot be pulled and immediately developed on as one would expect for a zero-install project - you will need to run yarn to update the contents of the ./yarn/cache directory.
If you are not using zero-install you can ignore this as your flow should likely be unchanged.

⚠️ Warning
Failed to update the yarn.lock, please update manually before merging.

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
high severity 125/1000
Why? Confidentiality impact: None, Integrity impact: None, Availability impact: High, Scope: Unchanged, Exploit Maturity: No data, User Interaction (UI): None, Privileges Required (PR): None, Attack Complexity: Low, Attack Vector: Network, EPSS: 0.01055, Social Trends: No, Days since published: 0, Reachable: No, Transitive dependency: Yes, Is Malicious: No, Business Criticality: High, Provider Urgency: High, Package Popularity Score: 99, Impact: 5.99, Likelihood: 2.08, Score Version: V5
Missing Release of Resource after Effective Lifetime
SNYK-JS-INFLIGHT-6095116
Yes No Known Exploit

(*) Note that the real score may have changed since the PR was raised.

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Learn about vulnerability in an interactive lesson of Snyk Learn.

The following vulnerabilities are fixed with an upgrade:
- https://snyk.io/vuln/SNYK-JS-INFLIGHT-6095116
@openzeppelin-code
Copy link

[Snyk] Fix for 1 vulnerabilities

Generated at commit: beb637871c581b1d34f98bd4c4b8cebdccd14676

🚨 Report Summary

Severity Level Results
Contracts Critical
High
Medium
Low
Note
Total
0
0
0
0
0
0
Dependencies Critical
High
Medium
Low
Note
Total
0
0
0
0
0
0

For more details view the full report in OpenZeppelin Code Inspector

@socket-security
Copy link

Updated dependencies detected. Learn more about Socket for GitHub ↗︎

Packages Version New capabilities Transitives Size Publisher
semantic-release 19.0.5...22.0.8 None +90/-51 20.3 MB
markdownlint-cli 0.31.1...0.34.0 shell +16/-3 4.27 MB davidanson
cspell 5.21.2...6.31.3 network, filesystem +66/-49 5.87 MB jason-dent

@socket-security
Copy link

🚨 Potential security issues detected. Learn more about Socket for GitHub ↗︎

To accept the risk, merge this PR and you will not be notified again.

Issue Package Version Note Source
Bin script confusion npm 10.2.4
Chronological version anomaly npm 10.2.4
  • Previous Chronological: npm@9.9.2 (11/15/2023, 9:29:49 PM)
  • Previous Semver: npm@10.2.3 (11/2/2023, 7:52:30 PM)
Debug access npm 10.2.4
Dynamic require npm 10.2.4
Environment variable access npm 10.2.4
Filesystem access npm 10.2.4
Mixed license npm 10.2.4
  • License: Apache-2.0,Artistic-2.0,ISC,MIT,BSD-3-Clause,MIT-0,SSH-short,BlueOak-1.0.0,BSD-2-Clause,CC-BY-3.0,CC0-1.0
  • +259 more instances...
Modified license npm 10.2.4
Network access npm 10.2.4
Non OSI license npm 10.2.4
Bin script confusion glob 10.2.7
Chronological version anomaly cspell-io 6.31.3
Filesystem access cspell-io 6.31.3
Network access cspell-io 6.31.3
Chronological version anomaly cspell-trie-lib 6.31.3
Chronological version anomaly cspell-dictionary 6.31.3
Chronological version anomaly @cspell/cspell-json-reporter 6.31.3
Filesystem access @cspell/cspell-json-reporter 6.31.3
Chronological version anomaly cspell-glob 6.31.3
Chronological version anomaly @cspell/cspell-types 6.31.3
Chronological version anomaly @cspell/cspell-pipe 6.31.3
Chronological version anomaly cspell-lib 6.31.3
Environment variable access cspell-lib 6.31.3
Filesystem access cspell-lib 6.31.3
Chronological version anomaly cspell 6.31.3
Filesystem access cspell 6.31.3
Network access cspell 6.31.3
Chronological version anomaly cspell-grammar 6.31.3
Filesystem access cspell-grammar 6.31.3
Chronological version anomaly @cspell/cspell-bundled-dicts 6.31.3
Chronological version anomaly cspell-gitignore 6.31.3
Filesystem access cspell-gitignore 6.31.3
Chronological version anomaly @cspell/cspell-service-bus 6.31.3
Chronological version anomaly @cspell/strong-weak-map 6.31.3
Chronological version anomaly @cspell/dynamic-import 6.31.3
Empty package markdownlint-micromark 0.1.2
Major refactor markdownlint-micromark 0.1.2
  • Change Percentage: 42100.00
  • Current Line Count: 0
  • Previous Line Count: 0
  • Lines Changed: 421
No v1 markdownlint-micromark 0.1.2
Environment variable access minimatch 9.0.3
Environment variable access is-unicode-supported 2.0.0
Environment variable access jackspeak 2.3.6
Environment variable access meow 12.1.1
High entropy strings meow 12.1.1
Filesystem access cosmiconfig 8.3.6
Filesystem access path-scurry 1.10.1
Filesystem access @semantic-release/npm 11.0.1
Filesystem access conventional-changelog-writer 7.0.1
Major refactor hook-std 3.0.0
  • Change Percentage: 52.48
  • Current Line Count: 189
  • Previous Line Count: 194
  • Lines Changed: 201
Major refactor conventional-changelog-angular 7.0.0
  • Change Percentage: 102.83
  • Current Line Count: 165
  • Previous Line Count: 153
  • Lines Changed: 327
Mixed license @pkgjs/parseargs 0.11.0
No v1 @pkgjs/parseargs 0.11.0
Unmaintained @pkgjs/parseargs 0.11.0
  • Last Publish: 10/10/2022, 2:18:44 PM
New author url-join 5.0.0
New author normalize-package-data 6.0.0
New author get-stream 8.0.1

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants