WoTTsecurity / api

API and Dashboard
https://dash.wott.io
MIT License
0 stars 2 forks source link

[Snyk] Fix for 1 vulnerabilities #902

Open snyk-bot opened 3 years ago

snyk-bot commented 3 years ago

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

As this is a private repository, Snyk-bot does not have access. Therefore, this PR has been created automatically, but appears to have been created by a real user.

Changes included in this PR

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
high severity 661/1000
Why? Recently disclosed, Has a fix available, CVSS 7.5
Regular Expression Denial of Service (ReDoS)
SNYK-JS-NORMALIZEURL-1296539
Yes No Known Exploit

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: mini-css-extract-plugin The new version differs by 51 commits.
  • 6ebe51d chore(release): 1.1.0
  • 9ae47e5 fix: remove `normalize-url` from deps (#623)
  • 71a9ce9 fix: ignore modules without identifier (#627)
  • 028b4f2 docs: use css-minimizer-webpack-plugin (#624)
  • e8a2d5a feat: added `attributes` option
  • a5f17c4 feat: added the `insert` option
  • 3d017a2 docs: improve readme (#616)
  • 2946edc ci: update (#614)
  • 2b432e9 refactor: removed unused option hmr (#608)
  • 975cfda chore(tool): fix (#607)
  • fae8ed0 test: devtool
  • 884cbfe docs: fix ambiguous docs (#605)
  • 7335077 docs: clean unused link in readme (#604)
  • 787b6d2 docs: improve readme (#603)
  • 315bbac chore(release): 1.0.0
  • 2a3b4a8 refactor: next
  • b935f26 chore(release): 0.12.0
  • bc0ca2c test: improve (#601)
  • 5fafdf8 feat opt-in to transitive only side effects (webpack@5) (#599)
  • ef4bd79 test: empty chunk
  • 0494230 chore(release): 0.11.3
  • 6e09a51 fix: better support for webpack 5 (#595)
  • bb09d75 chore(release): 0.11.2
  • e4ddf29 test: cache (#588)
See the full diff
Package name: optimize-css-assets-webpack-plugin The new version differs by 5 commits.
  • 09d29b3 5.0.5
  • d0a7da7 feat(deps): update dependencies (#154)
  • 41d1e23 Redirect to css-minimizer-webpack-plugin for webpack 5 or above
  • e9b84f1 5.0.4
  • b3a3ada Update dependencies (#133)
See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information: 🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic