Closed atomist[bot] closed 3 years ago
This pull request fixes all 2 moderate security vulnerabilities open on fdf7586.
npm audit fix updated the following npm dependencies:
npm audit fix
jszip
path-parse
Following security vulnerabilities are fixed:
Prototype Pollution Upgrade to version 3.7.0 or later moderate · <3.7.0 · CVE-2021-23413 · automatic fix available
<3.7.0
jszip@3.6.0
@atomist/skill > jszip
Regular Expression Denial of Service in path-parse Upgrade to version 1.0.7 or later moderate · <1.0.7 · CVE-2021-23343 · automatic fix available
<1.0.7
path-parse@1.0.6
@kubernetes/client-node > shelljs > rechoir > resolve > path-parse
File changed:
package-lock.json
atomist/npm-vulnerability-scanner-skill · Configure
Pull request auto merged:
This pull request fixes all 2 moderate security vulnerabilities open on fdf7586.
npm audit fix
updated the following npm dependencies:jszip
3.6.0 > 3.7.1path-parse
1.0.6 > 1.0.7Fixed vulnerabilities
Following security vulnerabilities are fixed:
jszip
Prototype Pollution Upgrade to version 3.7.0 or later moderate ·
<3.7.0
· CVE-2021-23413 · automatic fix availablejszip@3.6.0
· 1 vulnerable path@atomist/skill > jszip
path-parse
Regular Expression Denial of Service in path-parse Upgrade to version 1.0.7 or later moderate ·
<1.0.7
· CVE-2021-23343 · automatic fix availablepath-parse@1.0.6
· 1 vulnerable path@kubernetes/client-node > shelljs > rechoir > resolve > path-parse
File changed:
package-lock.json
atomist/npm-vulnerability-scanner-skill · Configure