UKHomeOfficeForms / hof

Bootstrap a HOF project
MIT License
15 stars 17 forks source link

[Snyk] Security upgrade hof-frontend-toolkit from 1.1.0 to 2.1.1 #192

Closed snyk-bot closed 3 years ago

snyk-bot commented 3 years ago

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
high severity 589/1000
Why? Has a fix available, CVSS 7.5
Regular Expression Denial of Service (ReDoS)
SNYK-JS-MINIMATCH-1019388
Yes No Known Exploit
medium severity 601/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 5.6
Prototype Pollution
SNYK-JS-MINIMIST-559764
Yes Proof of Concept
high severity 579/1000
Why? Has a fix available, CVSS 7.3
Insecure Randomness
npm:crypto-browserify:20140722
Yes No Known Exploit
high severity 589/1000
Why? Has a fix available, CVSS 7.5
Regular Expression Denial of Service (ReDoS)
npm:minimatch:20160620
Yes No Known Exploit
medium severity 479/1000
Why? Has a fix available, CVSS 5.3
Content Injection due to quoteless attributes
npm:mustache:20151207
Yes No Known Exploit
high severity 634/1000
Why? Has a fix available, CVSS 8.4
Command Injection
npm:shell-quote:20160621
Yes No Known Exploit
medium severity 479/1000
Why? Has a fix available, CVSS 5.3
Regular Expression Denial of Service (ReDoS)
npm:uglify-js:20151024
Yes No Known Exploit

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: hof-frontend-toolkit The new version differs by 22 commits.
  • 26780bb 2.1.1
  • b475ef9 Merge pull request #10 from UKHomeOfficeForms/lennym-patch-1
  • cebe37c Move browserify to a dev dependency
  • 4823524 2.1.0
  • 7bbbff5 Merge pull request #8 from UKHomeOfficeForms/improvement/remove-content-id-styling
  • 683d2dd Remove styling bound to `#content`
  • a1b55e0 Merge pull request #9 from UKHomeOfficeForms/bugfix/missing-peer-dependencies
  • 5dc3d50 Update karma phantom versions
  • 39dc115 Add mocha as a dev dependency
  • 5ec1a9e 2.0.1
  • 74ba557 Merge pull request #7 from UKHomeOfficeForms/bugfix/unignore-mixins-file
  • 5166f57 Use modern travis
  • cd96911 Remove mixins.scss from gitignore
  • 9fae8c0 2.0.0
  • 5d0d5e4 Merge pull request #5 from UKHomeOfficeForms/improvement/remove-build-step
  • fa27ff4 Remove build step which compiles template
  • 8c9e407 Merge pull request #6 from UKHomeOfficeForms/improvement/remove-underscore
  • 45e6c0c Merge pull request #4 from UKHomeOfficeForms/feature/confirm-page
  • 73558bb Add confirm page table styles
  • a4d0311 Merge pull request #3 from UKHomeOfficeForms/feature/alert-styles
  • 425b6ac Remove underscore dependency
  • 749f10c Add alerts module
See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information: 🧐 View latest project report

πŸ›  Adjust project settings

πŸ“š Read more about Snyk's upgrade and patch logic