dchege711 / study_buddy

I read a lot, but remember too little. I write this web app to scratch my own itch.
https://cards.curiosities.dev/
MIT License
2 stars 0 forks source link

[Security] npm audit fix --force #133

Closed dchege711 closed 1 year ago

dchege711 commented 1 year ago

Still not sufficient:

$ npm audit report
\# npm audit report

fast-xml-parser  =4.2.4
fast-xml-parser regex vulnerability patch could be improved from a safety perspective - https://github.com/advisories/GHSA-gpv5-7x3g-ghjv
fix available via `npm audit fix`
node_modules/fast-xml-parser
  @aws-sdk/client-sts  3.54.2 || 3.186.2 || 3.335.1 || >=3.347.1
  Depends on vulnerable versions of fast-xml-parser
  node_modules/@aws-sdk/client-sts
    @aws-sdk/client-cognito-identity  3.54.2 || >=3.347.1
    Depends on vulnerable versions of @aws-sdk/client-sts
    node_modules/@aws-sdk/client-cognito-identity
      @aws-sdk/credential-provider-cognito-identity  >=3.347.1
      Depends on vulnerable versions of @aws-sdk/client-cognito-identity
      node_modules/@aws-sdk/credential-provider-cognito-identity
    @aws-sdk/credential-providers  >=3.347.1
    Depends on vulnerable versions of @aws-sdk/client-cognito-identity
    Depends on vulnerable versions of @aws-sdk/client-sts
    Depends on vulnerable versions of @aws-sdk/credential-provider-cognito-identity
    node_modules/@aws-sdk/credential-providers

glob-parent  <5.1.2
Severity: high
glob-parent before 5.1.2 vulnerable to Regular Expression Denial of Service in enclosure regex - https://github.com/advisories/GHSA-ww39-953v-wcq6
fix available via `npm audit fix`
node_modules/glob-parent
  chokidar  1.0.0-rc1 - 2.1.8
  Depends on vulnerable versions of glob-parent
  node_modules/chokidar
    watchpack-chokidar2  *
    Depends on vulnerable versions of chokidar
    node_modules/watchpack-chokidar2
      watchpack  1.7.2 - 1.7.5
      Depends on vulnerable versions of watchpack-chokidar2
      node_modules/watchpack
        webpack  4.44.0 - 4.46.0
        Depends on vulnerable versions of watchpack
        node_modules/webpack

10 vulnerabilities (5 low, 5 high)

To address all issues, run:
  npm audit fix
render[bot] commented 1 year ago

Your Render PR Server URL is https://flashcards-pr-133.onrender.com.

Follow its progress at https://dashboard.render.com/web/srv-ci7ufp5ph6ekmbg2d6rg.