dwp / govuk-casa

Framework for creating simple GOVUK Collect-And-Submit-Applications
ISC License
34 stars 24 forks source link

[Snyk] Fix for 1 vulnerabilities #46

Closed adam-moss closed 1 year ago

adam-moss commented 2 years ago

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

#### Changes included in this PR - Changes to the following files to upgrade the vulnerable dependencies to a fixed version: - examples/barebones/package.json #### Vulnerabilities that will be fixed ##### With an upgrade: Severity | Priority Score (*) | Issue | Breaking Change | Exploit Maturity :-------------------------:|-------------------------|:-------------------------|:-------------------------|:------------------------- ![high severity](https://res.cloudinary.com/snyk/image/upload/w_20,h_20/v1561977819/icon/h.png "high severity") | **768/1000**
**Why?** Proof of Concept exploit, Recently disclosed, Has a fix available, CVSS 7.5 | Regular Expression Denial of Service (ReDoS)
[SNYK-JS-MOMENT-2944238](https://snyk.io/vuln/SNYK-JS-MOMENT-2944238) | Yes | Proof of Concept (*) Note that the real score may have changed since the PR was raised.
Commit messages
Package name: @dwp/govuk-casa The new version differs by 48 commits.
  • ea00c18 chore(release): 7.0.1
  • 542cbee refactor: push to internal npm registry
  • 45442b3 chore(release): 7.0.0
  • 7f02fbe chore: update dependencies
  • 1553627 refactor(ci): avoid detached pipeline on dast job
  • 1010e6b refactor: simplify origin extraction from route creation
  • 56b9619 refactor: simplify field path parsing
  • b47778e refactor: apply regex sanitisation
  • 465cb16 chore(ci): add standard-version config
  • 0174423 refactor(ci): add dast tooling
  • e6a3ffd refactor(ci): move to using shared pipeline blueprints
  • 3b20f3d chore(ci): use the correct git hook for commitlint
  • c0303df refactor: husky config after upgrade
  • 1af9c3b chore: update dependencies
  • 70e30e2 chore: update dependencies
  • 103f679 chore: minor review fixes
  • 81b2669 chore: update dependencies
  • e7d6b0e chore: package 7.0.0-beta1
  • 42392d0 chore(ci): enable all jobs for 7.0.0
  • 3fb0ecd chore: lint fixes
  • bedf253 feat: add new wordCount validator
  • cddee56 fix: postalAddressObject welsh translations
  • 716c7f5 refactor: [bc] add govuk/ prefix to nunjucks macros
  • 60cdcdd refactor: extract some common functions into utils
See the full diff
Check the changes in this PR to ensure they won't cause issues with your project. ------------ **Note:** *You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.* For more information: šŸ§ [View latest project report](https://app.snyk.io/org/dwp-4cl/project/ea426cc2-84e4-4107-8c42-71959875ca3b?utm_source=github&utm_medium=referral&page=fix-pr) šŸ›  [Adjust project settings](https://app.snyk.io/org/dwp-4cl/project/ea426cc2-84e4-4107-8c42-71959875ca3b?utm_source=github&utm_medium=referral&page=fix-pr/settings) šŸ“š [Read more about Snyk's upgrade and patch logic](https://support.snyk.io/hc/en-us/articles/360003891078-Snyk-patches-to-fix-vulnerabilities) [//]: # (snyk:metadata:{"prId":"a57c8674-5201-4b72-aa93-df3f9bff3ac5","prPublicId":"a57c8674-5201-4b72-aa93-df3f9bff3ac5","dependencies":[{"name":"@dwp/govuk-casa","from":"6.8.4","to":"7.0.1"},{"name":"moment","from":"2.29.1","to":"2.29.4"}],"packageManager":"npm","projectPublicId":"ea426cc2-84e4-4107-8c42-71959875ca3b","projectUrl":"https://app.snyk.io/org/dwp-4cl/project/ea426cc2-84e4-4107-8c42-71959875ca3b?utm_source=github&utm_medium=referral&page=fix-pr","type":"auto","patch":[],"vulns":["SNYK-JS-MOMENT-2944238"],"upgrade":["SNYK-JS-MOMENT-2944238"],"isBreakingChange":true,"env":"prod","prType":"fix","templateVariants":["priorityScore"],"priorityScoreList":[768]}) --- **Learn how to fix vulnerabilities with free interactive lessons:** šŸ¦‰ [Learn about vulnerability in an interactive lesson of Snyk Learn.](https://learn.snyk.io?loc=fix-pr)