atomist-skills / docker-build-skill

Atomist Skill to build and push Docker images
Apache License 2.0
1 stars 0 forks source link

Fix 2 npm dependencies #344

Closed atomist[bot] closed 3 years ago

atomist[bot] commented 3 years ago

This pull request fixes all 2 moderate security vulnerabilities open on fdf7586.

npm audit fix updated the following npm dependencies:


Fixed vulnerabilities

Following security vulnerabilities are fixed:

jszip

Prototype Pollution Upgrade to version 3.7.0 or later moderate · <3.7.0 · CVE-2021-23413 · automatic fix available

jszip@3.6.0 · 1 vulnerable path
  • @atomist/skill > jszip

  • path-parse

    Regular Expression Denial of Service in path-parse Upgrade to version 1.0.7 or later moderate · <1.0.7 · CVE-2021-23343 · automatic fix available

    path-parse@1.0.6 · 1 vulnerable path
  • @kubernetes/client-node > shelljs > rechoir > resolve > path-parse

  • File changed:


    atomist/npm-vulnerability-scanner-skill · Configure

    atomist[bot] commented 3 years ago

    Pull request auto merged: