Closed atomist[bot] closed 3 years ago
This pull request fixes security vulnerabilities open on 6d2bfff but 1 moderate vulnerability remains open and needs manual review.
npm audit fix updated the following npm dependencies:
npm audit fix
glob-parent
Following security vulnerability is fixed:
Regular expression denial of service Upgrade to version 5.1.2 or later moderate · <5.1.2 · CVE-2020-28469 · automatic fix available
<5.1.2
glob-parent@5.1.1
@atomist/skill > @graphql-codegen/cli > @graphql-tools/load > globby > fast-glob > glob-parent
@atomist/skill > @graphql-codegen/cli > chokidar > glob-parent
@atomist/skill > @graphql-codegen/cli > graphql-config > @graphql-tools/load > globby > fast-glob > glob-parent
@atomist/skill > fast-glob > glob-parent
Following security vulnerability remains open and needs manual review:
Regular Expression Denial of Service Upgrade to version 6.2.2 or 7.4.6 or later moderate · >=5.0.0 <6.2.2 || >=7.0.0 <7.4.6 · CVE-2021-32640 · automatic fix available
>=5.0.0 <6.2.2 || >=7.0.0 <7.4.6
ws@7.4.5
@atomist/skill > @graphql-codegen/cli > @graphql-tools/prisma-loader > @graphql-tools/url-loader > ws
@atomist/skill > @graphql-codegen/cli > @graphql-tools/url-loader > ws
@atomist/skill > @graphql-codegen/cli > graphql-config > @graphql-tools/url-loader > ws
File changed:
package-lock.json
atomist/npm-vulnerability-scanner-skill · Configure
Pull request auto merged:
This pull request fixes security vulnerabilities open on 6d2bfff but 1 moderate vulnerability remains open and needs manual review.
npm audit fix
updated the following npm dependencies:glob-parent
5.1.1 > 5.1.2Fixed vulnerabilities
Following security vulnerability is fixed:
glob-parent
Regular expression denial of service Upgrade to version 5.1.2 or later moderate ·
<5.1.2
· CVE-2020-28469 · automatic fix availableglob-parent@5.1.1
· 4 vulnerable paths@atomist/skill > @graphql-codegen/cli > @graphql-tools/load > globby > fast-glob > glob-parent
@atomist/skill > @graphql-codegen/cli > chokidar > glob-parent
@atomist/skill > @graphql-codegen/cli > graphql-config > @graphql-tools/load > globby > fast-glob > glob-parent
@atomist/skill > fast-glob > glob-parent
Open vulnerabilities
Following security vulnerability remains open and needs manual review:
ws
Regular Expression Denial of Service Upgrade to version 6.2.2 or 7.4.6 or later moderate ·
>=5.0.0 <6.2.2 || >=7.0.0 <7.4.6
· CVE-2021-32640 · automatic fix availablews@7.4.5
· 3 vulnerable paths@atomist/skill > @graphql-codegen/cli > @graphql-tools/prisma-loader > @graphql-tools/url-loader > ws
@atomist/skill > @graphql-codegen/cli > @graphql-tools/url-loader > ws
@atomist/skill > @graphql-codegen/cli > graphql-config > @graphql-tools/url-loader > ws
File changed:
package-lock.json
atomist/npm-vulnerability-scanner-skill · Configure