codeforboston / mbta-alerts

source code for @mbta_alerts bot
https://twitter.com/mbta_alerts
MIT License
27 stars 4 forks source link

Fix for 4 vulnerable dependency paths #11

Open snyk-community opened 7 years ago

snyk-community commented 7 years ago

mbta-alerts currently has a 12 vulnerable dependency paths, introducing 8 different types of known vulnerabilities.

This PR fixes vulnerable dependencies.

You can see Snyk test report of this project for details.

This PR changes Package.json to upgrade request to the newer 2.74.0 version, and will fix the vulnerabilities listed above.

You can get alerts and fix PRs for future vulnerabilities for free by watching this repo with Snyk.

Note this PR fixes all the vulnerabilities introduced trough request dependency, in order to be vulnerability free you will need to upgrade other dependencies as well.

Stay Secure, The Snyk Team

calvinmetcalf commented 7 years ago

I'm on vacation but will look into this when I'm back, not a big issue for us as we don't use this as server

On Tue, Oct 18, 2016, 4:43 PM Snyk Community notifications@github.com wrote:

mbta-alerts currently has a 12 vulnerable dependency paths, introducing 8 different types of known vulnerabilities.

This PR fixes vulnerable dependencies.

You can see Snyk test report https://snyk.io/test/github/codeforboston/mbta-alerts of this project for details.

This PR changes Package.json to upgrade request to the newer 2.74.0 version, and will fix the vulnerabilities listed above.

You can get alerts and fix PRs for future vulnerabilities for free by watching this repo with Snyk https://snyk.io/add.

Note this PR fixes all the vulnerabilities introduced trough request dependency, in order to be vulnerability free you will need to upgrade others dependencies as well.

Stay Secure,

The Snyk Team

You can view, comment on, or merge this pull request online at:

https://github.com/codeforboston/mbta-alerts/pull/11 Commit Summary

  • Fix for 4 vulnerable dependency paths

File Changes

Patch Links:

— You are receiving this because you are subscribed to this thread. Reply to this email directly, view it on GitHub https://github.com/codeforboston/mbta-alerts/pull/11, or mute the thread https://github.com/notifications/unsubscribe-auth/ABE4n6eJTGTq4jFahff5PZqTgS772ecZks5q1M0FgaJpZM4KZzh9 .