Capgemini / kuwit

This is http://KuWit.io 🤖 🤖 🤖 the AI bot who knows everything about Kubernetes. https://capgemini.github.io/bots/kuwit/
MIT License
7 stars 5 forks source link

[Snyk] Security upgrade node-kubernetes-client from 0.2.3 to 0.3.2 #16

Open snyk-bot opened 3 years ago

snyk-bot commented 3 years ago

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

merge advice

Changes included in this PR

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
low severity 399/1000
Why? Has a fix available, CVSS 3.7
Regular Expression Denial of Service (ReDoS)
npm:hawk:20160119
No No Known Exploit
medium severity 529/1000
Why? Has a fix available, CVSS 6.3
Prototype Pollution
npm:hoek:20180212
No No Known Exploit
medium severity 539/1000
Why? Has a fix available, CVSS 6.5
Timing Attack
npm:http-signature:20150122
No No Known Exploit
high severity 589/1000
Why? Has a fix available, CVSS 7.5
Denial of Service (DoS)
npm:qs:20140806
No No Known Exploit
medium severity 539/1000
Why? Has a fix available, CVSS 6.5
Denial of Service (DoS)
npm:qs:20140806-1
No No Known Exploit
high severity 589/1000
Why? Has a fix available, CVSS 7.5
Prototype Override Protection Bypass
npm:qs:20170213
No No Known Exploit
medium severity 469/1000
Why? Has a fix available, CVSS 5.1
Remote Memory Exposure
npm:request:20160119
No No Known Exploit
medium severity 576/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 5.1
Uninitialized Memory Exposure
npm:tunnel-agent:20170305
No Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: node-kubernetes-client The new version differs by 44 commits.
  • 6e4bf84 0.3.2
  • 75b5286 add support for any namespaced api
  • 62e01b5 Merge pull request #26 from emaildanwilson/addGCSupport
  • 6cc3cbb Merge pull request #27 from emaildanwilson/garbageCollect
  • 48b1171 0.3.1
  • a3cec34 pass in deletion options when recurse is true
  • 7e3e088 update dependencies and fix tests
  • 0acd07b Merge pull request #25 from emaildanwilson/bumpVersionForPublish
  • 4f8ac4a 0.3.0
  • 326da6e Merge pull request #21 from grdryn/get-qs
  • 495784e Merge pull request #18 from emaildanwilson/master
  • 2a0f85c Remove some broken code from `collection.get`
  • c1c860d Merge branch 'master' of https://github.com/emaildanwilson/node-kubernetes-client
  • 5166098 Merge pull request #1 from tenxcloud/master
  • 45da1b4 add details on using deployments
  • f14ca2f handle extensions/v1beta1
  • 3dcbea4 Merge pull request #14 from brendandburns/master
  • 8842406 Merge pull request #15 from emaildanwilson/master
  • c1e6ee9 Merge branch 'master' of https://github.com/emaildanwilson/node-kubernetes-client
  • c518aed add info on using options override
  • 20fa5f8 default namespace to default again
  • d2fc362 add support to override request settings for each client
  • e6066c1 Remove jshinthelper from dependencies
  • 6dfdfe4 Merge branch 'master' of https://github.com/emaildanwilson/node-kubernetes-client
See the full diff
With a Snyk patch:
Severity Priority Score (*) Issue Exploit Maturity
low severity 399/1000
Why? Has a fix available, CVSS 3.7
Regular Expression Denial of Service (ReDoS)
npm:mime:20170907
No Known Exploit

(*) Note that the real score may have changed since the PR was raised.

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information: 🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic