Open snyk-bot opened 2 years ago
(*) Note that the real score may have changed since the PR was raised.
Check the changes in this PR to ensure they won't cause issues with your project.
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.
For more information: 🧐 View latest project report
🛠 Adjust project settings
📚 Read more about Snyk's upgrade and patch logic
Learn how to fix vulnerabilities with free interactive lessons:
🦉 Cross-site Scripting (XSS) 🦉 Regular Expression Denial of Service (ReDoS) 🦉 Buffer Overflow 🦉 More lessons are available in Snyk Learn
Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.
Changes included in this PR
Vulnerabilities that will be fixed
With an upgrade:
Why? Has a fix available, CVSS 6.5
SNYK-JS-CSVPARSE-467403
Why? Proof of Concept exploit, Has a fix available, CVSS 5.3
SNYK-JS-LODASH-1018905
Why? Proof of Concept exploit, Has a fix available, CVSS 7.2
SNYK-JS-LODASH-1040724
Why? Proof of Concept exploit, Has a fix available, CVSS 7.3
SNYK-JS-LODASH-450202
Why? Proof of Concept exploit, Has a fix available, CVSS 8.2
SNYK-JS-LODASH-567746
Why? Proof of Concept exploit, Has a fix available, CVSS 7.3
SNYK-JS-LODASH-608086
Why? Proof of Concept exploit, Has a fix available, CVSS 7.3
SNYK-JS-LODASH-73638
Why? Proof of Concept exploit, Has a fix available, CVSS 4.4
SNYK-JS-LODASH-73639
Why? Proof of Concept exploit, Has a fix available, CVSS 3.7
SNYK-JS-MINIMIST-2429795
Why? Proof of Concept exploit, Has a fix available, CVSS 5.6
SNYK-JS-MINIMIST-559764
Why? Proof of Concept exploit, Has a fix available, CVSS 7.3
SNYK-JS-SEQUELIZE-174147
Why? Proof of Concept exploit, Has a fix available, CVSS 9.4
SNYK-JS-SEQUELIZE-2932027
Why? Has a fix available, CVSS 7
SNYK-JS-SEQUELIZE-2959225
Why? Proof of Concept exploit, Has a fix available, CVSS 7.3
SNYK-JS-SEQUELIZE-450221
Why? Proof of Concept exploit, Has a fix available, CVSS 7.3
SNYK-JS-SEQUELIZE-450222
Why? Has a fix available, CVSS 6.5
SNYK-JS-SEQUELIZE-543029
Why? Proof of Concept exploit, Has a fix available, CVSS 5.3
SNYK-JS-VALIDATOR-1090599
Why? Proof of Concept exploit, Has a fix available, CVSS 5.3
SNYK-JS-VALIDATOR-1090600
Why? Proof of Concept exploit, Has a fix available, CVSS 5.3
SNYK-JS-VALIDATOR-1090601
Why? Proof of Concept exploit, Has a fix available, CVSS 5.3
SNYK-JS-VALIDATOR-1090602
Why? Has a fix available, CVSS 6.5
npm:http-signature:20150122
Why? Proof of Concept exploit, Has a fix available, CVSS 6.3
npm:lodash:20180130
Why? Mature exploit, Has a fix available, CVSS 2.2
npm:mysql:20170317
Why? Has a fix available, CVSS 7.5
npm:negotiator:20160616
Why? Has a fix available, CVSS 7.5
npm:qs:20170213
Why? Has a fix available, CVSS 6.5
npm:restify:20160225
Why? Has a fix available, CVSS 6.5
npm:sequelize:20160115
Why? Has a fix available, CVSS 4.8
npm:sequelize:20160329
Why? Has a fix available, CVSS 9.8
npm:sequelize:20160718
Why? Proof of Concept exploit, Has a fix available, CVSS 5.1
npm:tunnel-agent:20170305
Why? Has a fix available, CVSS 5.3
npm:validator:20160218
(*) Note that the real score may have changed since the PR was raised.
Commit messages
Package name: mysql
The new version differs by 214 commits.Package name: restify
The new version differs by 250 commits.Package name: sequelize
The new version differs by 250 commits.Check the changes in this PR to ensure they won't cause issues with your project.
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.
For more information: 🧐 View latest project report
🛠 Adjust project settings
📚 Read more about Snyk's upgrade and patch logic
Learn how to fix vulnerabilities with free interactive lessons:
🦉 Cross-site Scripting (XSS) 🦉 Regular Expression Denial of Service (ReDoS) 🦉 Buffer Overflow 🦉 More lessons are available in Snyk Learn