Open VictorGarridoAuth0 opened 2 months ago
Semgrep found 1 ssc-d5d8f586-e6e9-42b3-8b5b-ab176a2efd4e
finding:
Risk: npm 8.x before 8.11.0 is vulnerable to exposure of sensitive information to an unauthorized actor. The npm cli incorrectly ignores root-level .gitignore
and .npmignore
files when run in a workspace. Upgrade to npm 8.11.0.
Fix: Upgrade this library to at least version 8.11.0 at auth0-authorization-extension/package-lock.json:13586.
Reference(s): https://github.com/advisories/GHSA-hj9c-8jmm-8c52, CVE-2022-29244
Ignore this finding from ssc-d5d8f586-e6e9-42b3-8b5b-ab176a2efd4e.
Semgrep found 1 ssc-d5d8f586-e6e9-42b3-8b5b-ab176a2efd4e
finding:
Risk: npm 8.x before 8.11.0 is vulnerable to exposure of sensitive information to an unauthorized actor. The npm cli incorrectly ignores root-level .gitignore
and .npmignore
files when run in a workspace. Upgrade to npm 8.11.0.
Fix: Upgrade this library to at least version 8.11.0 at auth0-authorization-extension/package-lock.json:13586.
Reference(s): https://github.com/advisories/GHSA-hj9c-8jmm-8c52, CVE-2022-29244
Ignore this finding from ssc-d5d8f586-e6e9-42b3-8b5b-ab176a2efd4e.
Snyk has created this PR to fix 41 vulnerabilities in the npm dependencies of this project.
Snyk changed the following file(s):
package.json
package-lock.json
Vulnerabilities that will be fixed with an upgrade:
SNYK-JS-IP-6240864
SNYK-JS-LODASH-567746
SNYK-JS-HANDLEBARS-534478
SNYK-JS-PACRESOLVER-1564857
SNYK-JS-NETMASK-1089716
SNYK-JS-NETMASK-6056519
SNYK-JS-HANDLEBARS-534988
SNYK-JS-ANSIREGEX-1583908
SNYK-JS-LODASH-6139239
SNYK-JS-QS-3153490
SNYK-JS-SEMVER-3247795
SNYK-JS-INI-1048974
SNYK-JS-LODASH-450202
SNYK-JS-LODASH-608086
SNYK-JS-LODASH-73638
SNYK-JS-Y18N-1021887
npm:deep-extend:20180409
SNYK-JS-LODASH-1040724
SNYK-JS-HANDLEBARS-1056767
SNYK-JS-HANDLEBARS-567742
SNYK-JS-IP-7148531
SNYK-JS-REQUEST-3361831
SNYK-JS-TOUGHCOOKIE-5672873
SNYK-JS-JSONSCHEMA-1920922
SNYK-JS-DOTPROP-543489
npm:lodash:20180130
SNYK-JS-HTTPSPROXYAGENT-469131
SNYK-JS-AJV-584908
SNYK-JS-HANDLEBARS-1279029
SNYK-JS-MINIMIST-559764
SNYK-JS-HANDLEBARS-480388
SNYK-JS-HOSTEDGITINFO-1088355
SNYK-JS-LODASH-1018905
SNYK-JS-HANDLEBARS-173692
SNYK-JS-HANDLEBARS-174183
SNYK-JS-HANDLEBARS-469063
SNYK-JS-LODASH-73639
npm:brace-expansion:20170302
SNYK-JS-MINIMIST-2429795
npm:clean-css:20180306
SNYK-JS-MINIMATCH-3050818
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.
For more information: π§ View latest project report π Customise PR templates π Adjust project settings π Read about Snyk's upgrade logic
Learn how to fix vulnerabilities with free interactive lessons:
π¦ Prototype Pollution π¦ Regular Expression Denial of Service (ReDoS) π¦ Remote Code Execution (RCE) π¦ More lessons are available in Snyk Learn