8BitJonny / BeatMix

BeatMix let's you select a list of your favourite artists from which all tracks are put into one new playlist for you to hear all day long.
https://beatmix.app
GNU General Public License v3.0
7 stars 1 forks source link

[Snyk] Fix for 4 vulnerabilities #97

Open 8BitJonny opened 1 month ago

8BitJonny commented 1 month ago

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
medium severity 601/1000
Why? Recently disclosed, Has a fix available, CVSS 6.3
Cross-site Scripting (XSS)
SNYK-JS-COOKIE-8163060
Yes No Known Exploit
high severity 701/1000
Why? Recently disclosed, Has a fix available, CVSS 8.3
Improper Verification of Cryptographic Signature
SNYK-JS-ELLIPTIC-8172694
Yes No Known Exploit
medium severity 631/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 6.2
Missing Release of Resource after Effective Lifetime
SNYK-JS-INFLIGHT-6095116
Yes Proof of Concept
medium severity 479/1000
Why? Has a fix available, CVSS 5.3
Regular Expression Denial of Service (ReDoS)
SNYK-JS-MINIMATCH-3050818
Yes No Known Exploit

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: cookie-parser The new version differs by 42 commits.
  • 5d61e1e 1.4.7
  • ccf1f54 deps: cookie@0.7.2 (#116)
  • 429cfd4 ci: Use GITHUB_OUTPUT envvar instead of set-output command (#100)
  • ca4c97e ci: fix errors in ci pipeline for node 8 and 9 (#104)
  • 97bdf39 ci: add support for OSSF scorecard reporting (#103)
  • e5862bd build: Node.js@17.6
  • f0688d2 build: Node.js@14.19
  • 44ec541 build: Node.js@16.14
  • 695435a deps: cookie@0.4.2
  • f66e7e1 build: mocha@9.2.1
  • 05e40b1 build: Node.js@17.3
  • bc1d501 build: use supertest@3.4.2 for Node.js 6.x
  • dda4c5b 1.4.6
  • 8653e78 build: support Node.js 17.x
  • 6ec9c5b deps: cookie@0.4.1
  • ee68a8a build: eslint-plugin-standard@4.1.0
  • 7828d66 build: mocha@9.1.3
  • dafa811 build: use nyc for coverage testing
  • d80cf11 build: eslint-plugin-promise@4.3.1
  • c954873 build: supertest@6.1.6
  • 8ad6c54 build: mocha@8.4.0
  • 716f5a4 build: support Node.js 16.x
  • 90c418d build: eslint@7.32.0
  • a3cff78 build: support Node.js 15.x
See the full diff
Package name: express The new version differs by 250 commits.
  • 8e229f9 4.21.1
  • a024c8a fix(deps): cookie@0.7.1
  • 7e562c6 4.21.0
  • 1bcde96 fix(deps): qs@6.13.0 (#5946)
  • 7d36477 fix(deps): serve-static@1.16.2 (#5951)
  • 40d2d8f fix(deps): finalhandler@1.3.1
  • 77ada90 Deprecate `"back"` magic string in redirects (#5935)
  • 21df421 4.20.0
  • 4c9ddc1 feat: upgrade to serve-static@0.16.0
  • 9ebe5d5 feat: upgrade to send@0.19.0 (#5928)
  • ec4a01b feat: upgrade to body-parser@1.20.3 (#5926)
  • 54271f6 fix: don't render redirect values in anchor href
  • 125bb74 path-to-regexp@0.1.10 (#5902)
  • 2a980ad merge-descriptors@1.0.3 (#5781)
  • a3e7e05 docs: specify new instructions for `question` and `discuss`
  • c5addb9 deps: path-to-regexp@0.1.8 (#5603)
  • e35380a docs: add @ IamLizu to the triage team (#5836)
  • f5b6e67 docs: update scorecard link (#5814)
  • 2177f67 docs: add OSSF Scorecard badge (#5436)
  • f4bd86e Replace Appveyor windows testing with GHA (#5599)
  • 2ec589c Fix Contributor Covenant link definition reference in attribution section (#5762)
  • 4cf7eed remove minor version pinning from ci (#5722)
  • 6d08471 📝 update people, add ctcpip to TC (#5683)
  • 61421a8 skip QUERY tests for Node 21 only, still not supported (#5695)
See the full diff
Package name: gh-pages The new version differs by 197 commits.
  • 4b29930 6.2.0
  • a3df19c Log changes
  • 0b721f3 Merge pull request #581 from tschaub/updates
  • 13b6efc Update globby
  • 5a8c819 Merge pull request #578 from tschaub/dependabot/npm_and_yarn/sinon-19.0.2
  • bf7ed42 Merge pull request #579 from tschaub/dependabot/npm_and_yarn/eslint-8.57.1
  • e55b0dd Bump eslint from 8.57.0 to 8.57.1
  • b525485 Bump sinon from 18.0.0 to 19.0.2
  • fc668f2 Merge pull request #576 from tschaub/dependabot/npm_and_yarn/async-3.2.6
  • d55ea9f Bump async from 3.2.5 to 3.2.6
  • 202aa11 Merge pull request #573 from tschaub/dependabot/npm_and_yarn/mocha-10.7.3
  • 1938ffc Bump mocha from 10.7.0 to 10.7.3
  • bec3b5a Merge pull request #571 from tschaub/dependabot/npm_and_yarn/mocha-10.7.0
  • 8c3f124 Bump mocha from 10.6.0 to 10.7.0
  • bd04ece Merge pull request #569 from tschaub/dependabot/npm_and_yarn/mocha-10.6.0
  • ee1139a Bump mocha from 10.4.0 to 10.6.0
  • 7568804 Merge pull request #563 from tschaub/dependabot/npm_and_yarn/braces-3.0.3
  • ea804b2 Bump braces from 3.0.2 to 3.0.3
  • dd28911 Merge pull request #561 from tschaub/dependabot/npm_and_yarn/sinon-18.0.0
  • 0912f47 Bump sinon from 17.0.2 to 18.0.0
  • c9d7ef6 Merge pull request #557 from tschaub/dependabot/npm_and_yarn/sinon-17.0.2
  • fc349cb Bump sinon from 17.0.1 to 17.0.2
  • 985f370 Merge pull request #555 from tschaub/dependabot/npm_and_yarn/dir-compare-5.0.0
  • d4f6bd1 Bump dir-compare from 4.2.0 to 5.0.0
See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information: 🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Cross-site Scripting (XSS) 🦉 Regular Expression Denial of Service (ReDoS)