$ npm audit report
\# npm audit report
fast-xml-parser =4.2.4
fast-xml-parser regex vulnerability patch could be improved from a safety perspective - https://github.com/advisories/GHSA-gpv5-7x3g-ghjv
fix available via `npm audit fix`
node_modules/fast-xml-parser
@aws-sdk/client-sts 3.54.2 || 3.186.2 || 3.335.1 || >=3.347.1
Depends on vulnerable versions of fast-xml-parser
node_modules/@aws-sdk/client-sts
@aws-sdk/client-cognito-identity 3.54.2 || >=3.347.1
Depends on vulnerable versions of @aws-sdk/client-sts
node_modules/@aws-sdk/client-cognito-identity
@aws-sdk/credential-provider-cognito-identity >=3.347.1
Depends on vulnerable versions of @aws-sdk/client-cognito-identity
node_modules/@aws-sdk/credential-provider-cognito-identity
@aws-sdk/credential-providers >=3.347.1
Depends on vulnerable versions of @aws-sdk/client-cognito-identity
Depends on vulnerable versions of @aws-sdk/client-sts
Depends on vulnerable versions of @aws-sdk/credential-provider-cognito-identity
node_modules/@aws-sdk/credential-providers
glob-parent <5.1.2
Severity: high
glob-parent before 5.1.2 vulnerable to Regular Expression Denial of Service in enclosure regex - https://github.com/advisories/GHSA-ww39-953v-wcq6
fix available via `npm audit fix`
node_modules/glob-parent
chokidar 1.0.0-rc1 - 2.1.8
Depends on vulnerable versions of glob-parent
node_modules/chokidar
watchpack-chokidar2 *
Depends on vulnerable versions of chokidar
node_modules/watchpack-chokidar2
watchpack 1.7.2 - 1.7.5
Depends on vulnerable versions of watchpack-chokidar2
node_modules/watchpack
webpack 4.44.0 - 4.46.0
Depends on vulnerable versions of watchpack
node_modules/webpack
10 vulnerabilities (5 low, 5 high)
To address all issues, run:
npm audit fix
Still not sufficient: