Skip to content
This repository has been archived by the owner on Oct 2, 2022. It is now read-only.

[Snyk] Fix for 20 vulnerabilities #4

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

snyk-bot
Copy link

@snyk-bot snyk-bot commented Apr 2, 2020

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • scripts/bench/package.json
    • scripts/bench/.snyk

Vulnerabilities that will be fixed

With an upgrade:
Severity Issue Breaking Change Exploit Maturity
high severity Prototype Pollution
SNYK-JS-HANDLEBARS-173692
No No Known Exploit
high severity Prototype Pollution
SNYK-JS-HANDLEBARS-174183
No No Known Exploit
high severity Prototype Pollution
SNYK-JS-HANDLEBARS-469063
No No Known Exploit
high severity Denial of Service (DoS)
SNYK-JS-HANDLEBARS-480388
No No Known Exploit
high severity Arbitrary Code Execution
SNYK-JS-HANDLEBARS-534478
No No Known Exploit
high severity Prototype Pollution
SNYK-JS-HANDLEBARS-534988
No No Known Exploit
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-MARKED-174116
No No Known Exploit
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-MARKED-451540
No No Known Exploit
medium severity Prototype Pollution
SNYK-JS-MINIMIST-559764
No Proof of Concept
high severity Directory Traversal
SNYK-JS-NODEGIT-542720
No No Known Exploit
high severity Improper Handling of Alternate Data Stream
SNYK-JS-NODEGIT-542721
No Mature
high severity Improper Handling of Alternate Data Stream
SNYK-JS-NODEGIT-542722
No No Known Exploit
high severity Improper Link Resolution Before File Access
SNYK-JS-NODEGIT-542723
No Mature
low severity Regular Expression Denial of Service (ReDoS)
npm:mime:20170907
No No Known Exploit
high severity Prototype Override Protection Bypass
npm:qs:20170213
No No Known Exploit
Commit messages
Package name: http-server The new version differs by 95 commits.

See the full diff

Package name: lighthouse The new version differs by 157 commits.

See the full diff

Package name: mime The new version differs by 4 commits.

See the full diff

Package name: minimist The new version differs by 13 commits.

See the full diff

Package name: nodegit The new version differs by 250 commits.

See the full diff

With a Snyk patch:
Severity Issue Exploit Maturity
low severity Regular Expression Denial of Service (ReDoS)
npm:debug:20170905
No Known Exploit
high severity Prototype Pollution
npm:extend:20180424
No Known Exploit
medium severity Prototype Pollution
npm:hoek:20180212
No Known Exploit
medium severity Uninitialized Memory Exposure
npm:stringstream:20180511
Mature
medium severity Regular Expression Denial of Service (ReDoS)
npm:tough-cookie:20170905
No Known Exploit

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:

🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant