Fleet-Hawks-Inc / fh-cloud-app

Repository for cloud app / frontend
1 stars 0 forks source link

[Snyk] Fix for 5 vulnerabilities #3402

Open kunalfleethawks opened 2 years ago

kunalfleethawks commented 2 years ago

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

:sparkles: Snyk has automatically assigned this pull request, set who gets assigned.

As this is a private repository, Snyk-bot does not have access. Therefore, this PR has been created automatically, but appears to have been created by a real user.

Changes included in this PR

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
medium severity 616/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 5.9
Regular Expression Denial of Service (ReDoS)
SNYK-JS-JSPDF-1073626
No Proof of Concept
medium severity 636/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 6.3
Cross-site Scripting (XSS)
SNYK-JS-JSPDF-568273
No Proof of Concept
medium severity 636/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 6.3
Cross-site Scripting (XSS)
SNYK-JS-JSPDF-575256
No Proof of Concept
medium severity 586/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 5.3
Regular Expression Denial of Service (ReDoS)
SNYK-JS-LODASH-1018905
No Proof of Concept
high severity 681/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 7.2
Command Injection
SNYK-JS-LODASH-1040724
No Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: html2pdf.js The new version differs by 9 commits.
  • 43a2f8b Build v0.10.0
  • 5be22be Add bundled and min files back into npm
  • 78580ea Remove dist from git tracking
  • 3f762d5 Prevent publishing bundles/mins/tests to npm
  • d97c69e Upgrade dependencies to fix audit issues (#462)
  • e2bcb98 Fix set-pageSize behaviour (#455)
  • 3b2d8cf Add automated testing and snapshots with pdftest (#454)
  • 7c78308 Merge pull request #369 from jakewhelan/jwhelan-fix-jspdf
  • 0d072c0 fix: set jspdf to 1.4.1 to avoid semver resolution of newer versions
See the full diff
Package name: lodash The new version differs by 1 commits.
See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information: 🧐 View latest project report

πŸ‘©β€πŸ’» Set who automatically gets assigned

πŸ›  Adjust project settings

πŸ“š Read more about Snyk's upgrade and patch logic


Learn how to fix vulnerabilities with free interactive lessons:

πŸ¦‰ Regular Expression Denial of Service (ReDoS) πŸ¦‰ Cross-site Scripting (XSS) πŸ¦‰ Cross-site Scripting (XSS) πŸ¦‰ More lessons are available in Snyk Learn

commit-lint[bot] commented 2 years ago

Bug Fixes

Contributors

snyk-bot

Commit-Lint commands
You can trigger Commit-Lint actions by commenting on this PR: - `@Commit-Lint merge patch` will merge dependabot PR on "patch" versions (X.X.Y - Y change) - `@Commit-Lint merge minor` will merge dependabot PR on "minor" versions (X.Y.Y - Y change) - `@Commit-Lint merge major` will merge dependabot PR on "major" versions (Y.Y.Y - Y change) - `@Commit-Lint merge disable` will desactivate merge dependabot PR - `@Commit-Lint review` will approve dependabot PR - `@Commit-Lint stop review` will stop approve dependabot PR