cesko-digital / nasi-politici

Největší otevřená databáze českých politiků a političek. Zjistěte si, kdo vám vládne.
https://www.nasipolitici.cz
MIT License
20 stars 7 forks source link

[Snyk] Fix for 12 vulnerabilities #152

Open snyk-bot opened 3 years ago

snyk-bot commented 3 years ago

Snyk has created this PR to fix one or more vulnerable packages in the `yarn` dependencies of this project.

Changes included in this PR

Vulnerabilities that will be fixed

With an upgrade:
Severity Issue Breaking Change Exploit Maturity
high severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-ANSIREGEX-1583908
Yes Proof of Concept
high severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-AXIOS-1579269
No Proof of Concept
high severity Arbitrary File Overwrite
SNYK-JS-TAR-1536528
Yes No Known Exploit
high severity Arbitrary File Overwrite
SNYK-JS-TAR-1536531
Yes No Known Exploit
low severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-TAR-1536758
Yes No Known Exploit
high severity Arbitrary File Write
SNYK-JS-TAR-1579147
Yes No Known Exploit
high severity Arbitrary File Write
SNYK-JS-TAR-1579152
Yes No Known Exploit
high severity Arbitrary File Write
SNYK-JS-TAR-1579155
Yes No Known Exploit
high severity Denial of Service (DoS)
SNYK-JS-TRIMNEWLINES-1298042
Yes No Known Exploit
high severity Denial of Service (DoS)
SNYK-JS-XLSX-1311137
No Proof of Concept
high severity Denial of Service (DoS)
SNYK-JS-XLSX-1311139
No Proof of Concept
high severity Denial of Service (DoS)
SNYK-JS-XLSX-1311141
No Proof of Concept

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information: 🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic