danwdart / projectchaplin

Free and Open Source Video Sharing Platform
GNU Affero General Public License v3.0
24 stars 11 forks source link

[Snyk] Fix for 2 vulnerabilities #241

Closed snyk-bot closed 11 months ago

snyk-bot commented 3 years ago

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
medium severity 551/1000
Why? Recently disclosed, Has a fix available, CVSS 5.3
Regular Expression Denial of Service (ReDoS)
SNYK-JS-POSTCSS-1255640
Yes No Known Exploit
high severity 758/1000
Why? Proof of Concept exploit, Recently disclosed, Has a fix available, CVSS 7.3
Access Restriction Bypass
SNYK-JS-XMLHTTPREQUESTSSL-1255647
Yes Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: css-loader The new version differs by 76 commits.
  • 1351e3a chore(release): 5.0.0
  • 747d62b feat: allow named exports to have underscores in names (#1209)
  • 7bfe85d chore(deps): update (#1208)
  • b5c9379 feat: postcss@8 (#1204)
  • 92fe103 docs: context is localIdentContext in README (#1202)
  • e5a9272 chore(deps): update (#1203)
  • 63b41be refactor: emoji deprecate
  • 9f974be feat: reduce runtime
  • d779eb1 feat: escape getLocalIdent by default (#1196)
  • dd52931 feat: hide warning on no plugins (#1195)
  • 52412f6 feat: improve error message
  • 0f95841 feat: add fallback if custom getLocalIdent returns null (#1193)
  • 2f1573f feat: auto enable icss modules
  • df111b8 test: import with file protocol
  • cfe669f refactor: remove icss option (#1189)
  • 57eb505 chore(release): 4.3.0
  • 3ddcc7b chore(deps): update deps (#1186)
  • 88b8ddc fix: line breaks in `url` function
  • 8b865fe test: source map (#1180)
  • ec58a7c feat: the `importLoaders` can be `string` (#1178)
  • df490c7 test: sass-loader next (#1177)
  • 26a3062 chore(release): 4.2.2
  • e42f046 refactor: improve sources handling in source maps (#1176)
  • 4ce556a docs: fix type (#1174)
See the full diff
Package name: socket.io-client The new version differs by 79 commits.
  • d28cde7 chore(release): 4.0.0
  • 43613d1 fix(bundle): restore support for JS modules
  • 6abfa1f feat: add autoUnref option
  • 5902365 feat: add support for typed events
  • 78ec5a6 chore(release): 3.1.2
  • 83a65be chore: bump engine.io-client version
  • 13b32b3 fix: restore support for web workers
  • 311c5d1 chore(release): 3.1.1
  • 7a0c2b5 fix: include the path in the manager ID
  • 61afc5d fix: remove polyfill for process in the bundle
  • 47f917a fix(typings): add return types and general-case overload signatures (#1440)
  • f02ab3b fix(typings): fix the type of the "query" option (#1439)
  • be81a2c chore: point towards the master branch for the CI badge
  • 0a63a17 refactor: remove unused line
  • 5529f34 chore(release): 3.1.0
  • 5d9b4eb chore: bump socket.io-parser version
  • 13e16b9 chore: bump engine.io-client version
  • fe97243 fix(typings): make Manager#opts public (#1437)
  • 4922e39 docs: points towards the website
  • bcdd3be chore(release): 3.0.5
  • cf9fc35 chore: bump debug version
  • 53c7374 fix: emit a connect_error event upon connection failure
  • b83f89c fix(typings): make sendBuffer and receiveBuffer public
  • 8c08c5d refactor: remove global polyfill from webpack config
See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information: 🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic