Skip to content

[Snyk] Fix for 15 vulnerabilities - #29

Open
nrpatten wants to merge 1 commit into
masterfrom
snyk-fix-7f0844a39d5919f97f38d955f77d9f9b
Open

[Snyk] Fix for 15 vulnerabilities#29
nrpatten wants to merge 1 commit into
masterfrom
snyk-fix-7f0844a39d5919f97f38d955f77d9f9b

Conversation

@nrpatten

Copy link
Copy Markdown
Owner

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:

    • package.json
  • Adding or updating a Snyk policy (.snyk) file; this file is required in order to apply Snyk vulnerability patches.
    Find out more.

Vulnerabilities that will be fixed

With an upgrade:
SeverityPriority Score (*)IssueBreaking ChangeExploit Maturity
high severity619/1000
Why? Has a fix available, CVSS 8.1
Prototype Pollution
SNYK-JS-AJV-584908
NoNo Known Exploit
high severity584/1000
Why? Has a fix available, CVSS 7.4
Regular Expression Denial of Service (ReDoS)
SNYK-JS-HAWK-2808852
NoNo Known Exploit
medium severity509/1000
Why? Has a fix available, CVSS 5.9
Denial of Service (DoS)
SNYK-JS-JSYAML-173999
NoNo Known Exploit
high severity619/1000
Why? Has a fix available, CVSS 8.1
Arbitrary Code Execution
SNYK-JS-JSYAML-174129
NoNo Known Exploit
medium severity529/1000
Why? Has a fix available, CVSS 6.3
Non-Constant Time String Comparison
npm:cookie-signature:20160804
NoNo Known Exploit
medium severity484/1000
Why? Has a fix available, CVSS 5.4
Cross-site Scripting (XSS)
npm:express:20140912
NoNo Known Exploit
high severity589/1000
Why? Has a fix available, CVSS 7.5
Regular Expression Denial of Service (ReDoS)
npm:fresh:20170908
YesNo Known Exploit
low severity399/1000
Why? Has a fix available, CVSS 3.7
Regular Expression Denial of Service (ReDoS)
npm:mime:20170907
YesNo Known Exploit
high severity589/1000
Why? Has a fix available, CVSS 7.5
Regular Expression Denial of Service (ReDoS)
npm:negotiator:20160616
YesNo Known Exploit
high severity589/1000
Why? Has a fix available, CVSS 7.5
Denial of Service (DoS)
npm:qs:20140806
NoNo Known Exploit
medium severity539/1000
Why? Has a fix available, CVSS 6.5
Denial of Service (DoS)
npm:qs:20140806-1
NoNo Known Exploit
high severity589/1000
Why? Has a fix available, CVSS 7.5
Prototype Override Protection Bypass
npm:qs:20170213
YesNo Known Exploit
medium severity429/1000
Why? Has a fix available, CVSS 4.3
Directory Traversal
npm:send:20140912
YesNo Known Exploit
medium severity479/1000
Why? Has a fix available, CVSS 5.3
Root Path Disclosure
npm:send:20151103
YesNo Known Exploit

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: js-yaml The new version differs by 211 commits.
  • 665aadd 3.13.1 released
  • da8ecf2 Browser files rebuild
  • b2f9e88 Merge pull request #480 from nodeca/toString
  • e18afbf Fix possible code execution in (already unsafe) load()
  • 9d4ce5e 3.13.0 released
  • f64c673 Browser files rebuild
  • a567ef3 Restrict data types for object keys
  • 59b6e76 Fix test name
  • e4267fc 3.12.2 released
  • 7231a49 Browser files rebuild
  • 99c0bf9 Fix for issue #468 includes passing test (#469)
  • b6d2609 3.12.1 released
  • 7b68122 Browser files rebuild
  • 784d1d0 Add "noArrayIndent" option (#461)
  • 00bba11 Fix description of onWarning (#460)
  • 2d1fbed Travis-CI: increase tests timeout
  • 5cdad9b 3.12.0 released
  • ef00891 Browser files rebuild
  • 337595a Dev deps bump
  • 290705b Support arrow functions without a block statement (#421)
  • bab69b5 Check for leading newlines when determining if block indentation indicator is needed (#404)
  • bb7f0cf Add property based tests to assess load reverses dump (#398)
  • f2bb207 3.11.0 released
  • b7eb2e6 Browser files rebuild

See the full diff

Package name: request The new version differs by 44 commits.
  • 6420240 2.88.0
  • bd22e21 fix: massive dependency upgrade, fixes all production vulnerabilities
  • 925849a Merge pull request #2996 from kwonoj/fix-uuid
  • 7b68551 fix(uuid): import versioned uuid
  • 5797963 Merge pull request #2994 from dlecocq/oauth-sign-0.9.0
  • 628ff5e Update to oauth-sign 0.9.0
  • 10987ef Merge pull request #2993 from simov/fix-header-tests
  • cd848af These are not going to fail if there is a server listening on those ports
  • a92e138 #515, #2894 Strip port suffix from Host header if the protocol is known. (#2904)
  • 45ffc4b Improve AWS SigV4 support. (#2791)
  • a121270 Merge pull request #2977 from simov/update-cert
  • bd16414 Update test certificates
  • 536f0e7 2.87.1
  • 02fc5b1 Update changelog
  • de1ed5a 2.87.0
  • a6741d4 Replace hawk dependency with a local implemenation (#2943)
  • a7f0a36 2.86.1
  • 8f2fd4d Update changelog
  • 386c7d8 2.86.0
  • 76a6e5b Merge pull request #2885 from ChALkeR/patch-1
  • db76838 Merge branch 'patch-1' of github.com:ChALkeR/request
  • fb7aeb3 Merge pull request #2942 from simov/fix-tests
  • e47ce95 Add Node v10 build target explicitly
  • 0c5db42 Skip status code 105 on Node > v10

See the full diff

With a Snyk patch:
SeverityPriority Score (*)IssueExploit Maturity
medium severity479/1000
Why? Has a fix available, CVSS 5.3
Regular Expression Denial of Service (ReDoS)
npm:uglify-js:20151024
No Known Exploit

(*) Note that the real score may have changed since the PR was raised.

Check the changes in this PR to ensure they won't cause issues with your project.


Note:You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Directory Traversal
🦉 Denial of Service (DoS)
🦉 Denial of Service (DoS)
🦉 More lessons are available in Snyk Learn

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@nrpatten@snyk-bot