emanchado / narrows

Online storytelling system
http://hardcorenarrativist.org/narrows/
BSD 3-Clause "New" or "Revised" License
113 stars 7 forks source link

[Snyk] Fix for 6 vulnerabilities #45

Open emanchado opened 10 months ago

emanchado commented 10 months ago

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

#### Changes included in this PR - Changes to the following files to upgrade the vulnerable dependencies to a fixed version: - package.json #### Vulnerabilities that will be fixed ##### With an upgrade: Severity | Priority Score (*) | Issue | Breaking Change | Exploit Maturity :-------------------------:|-------------------------|:-------------------------|:-------------------------|:------------------------- ![high severity](https://res.cloudinary.com/snyk/image/upload/w_20,h_20/v1561977819/icon/h.png "high severity") | **696/1000**
**Why?** Proof of Concept exploit, Has a fix available, CVSS 7.5 | Regular Expression Denial of Service (ReDoS)
[SNYK-JS-ANSIREGEX-1583908](https://snyk.io/vuln/SNYK-JS-ANSIREGEX-1583908) | Yes | Proof of Concept ![critical severity](https://res.cloudinary.com/snyk/image/upload/w_20,h_20/v1561977819/icon/c.png "critical severity") | **679/1000**
**Why?** Has a fix available, CVSS 9.3 | Incomplete List of Disallowed Inputs
[SNYK-JS-BABELTRAVERSE-5962463](https://snyk.io/vuln/SNYK-JS-BABELTRAVERSE-5962463) | Yes | No Known Exploit ![medium severity](https://res.cloudinary.com/snyk/image/upload/w_20,h_20/v1561977819/icon/m.png "medium severity") | **586/1000**
**Why?** Proof of Concept exploit, Has a fix available, CVSS 5.3 | Regular Expression Denial of Service (ReDoS)
[SNYK-JS-GLOBPARENT-1016905](https://snyk.io/vuln/SNYK-JS-GLOBPARENT-1016905) | Yes | Proof of Concept ![medium severity](https://res.cloudinary.com/snyk/image/upload/w_20,h_20/v1561977819/icon/m.png "medium severity") | **641/1000**
**Why?** Proof of Concept exploit, Has a fix available, CVSS 6.4 | Prototype Pollution
[SNYK-JS-JSON5-3182856](https://snyk.io/vuln/SNYK-JS-JSON5-3182856) | Yes | Proof of Concept ![low severity](https://res.cloudinary.com/snyk/image/upload/w_20,h_20/v1561977819/icon/l.png "low severity") | **506/1000**
**Why?** Proof of Concept exploit, Has a fix available, CVSS 3.7 | Prototype Pollution
[SNYK-JS-MINIMIST-2429795](https://snyk.io/vuln/SNYK-JS-MINIMIST-2429795) | No | Proof of Concept ![medium severity](https://res.cloudinary.com/snyk/image/upload/w_20,h_20/v1561977819/icon/m.png "medium severity") | **601/1000**
**Why?** Proof of Concept exploit, Has a fix available, CVSS 5.6 | Prototype Pollution
[SNYK-JS-MINIMIST-559764](https://snyk.io/vuln/SNYK-JS-MINIMIST-559764) | No | Proof of Concept (*) Note that the real score may have changed since the PR was raised.
Commit messages
Package name: babel-brunch The new version differs by 6 commits.
  • 67bc0a6 Release 7.0.0.
  • 3919b52 7.0 (#67)
  • c42c598 Improve pattern example (#55)
  • df0e92b Refactoring, env, closing a bunch of issues (#53)
  • 2cff6ce Merge pull request #50 from kesha-antonov/master
  • f0b099b fix typo in readme
See the full diff
Package name: db-migrate The new version differs by 73 commits.
  • 49a849f remove node 6 from build array
  • 7cfdb3a 0.11.7
  • 8b5beac fix(vuln): backport #679
  • e183046 feat(staticLoader): a static loader to support packaging
  • cc19a2b resize big image
  • cf24965 resize big image
  • d6d8cdb add sponsor
  • 263db65 add changelog
  • e393d36 0.11.6
  • 006ef5e fix(plugin): handle non existent dependencies and improve UX
  • f27dce0 fix(plugin): allow no package.json
  • fae85cf fix(cwd): addition of cwd missed function definition
  • 3dae762 fix(plugin): respect options cwd (#618)
  • 108087d 0.11.5
  • 910f0bc Merge pull request #600 from artemjackson/master
  • 4cd5558 fix(lgtm): fix errors
  • c851b4a chore(ci): update dependencies
  • 9e6bafd chore(ci): adjusting makefile for new testing resources
  • 2b57d66 Merge pull request #599 from xcorail/master
  • 17a7386 Merge pull request #576 from pc-jedi/exitcode
  • 10f84f8 Merge pull request #596 from DanielRuf/ci/test-nodejs-6-8-10-11
  • 3c9a175 chore(ci): adjusting makefile for new testing resources
  • fcffd62 fix: Added warning on plugin loading failure
  • 85450c7 doc: Add LGTM.com code quality badges
See the full diff
Check the changes in this PR to ensure they won't cause issues with your project. ------------ **Note:** *You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.* For more information: 🧐 [View latest project report](https://app.snyk.io/org/emanchado/project/23b62348-d9b2-454a-8749-ec8c52ac9cec?utm_source=github&utm_medium=referral&page=fix-pr) 🛠 [Adjust project settings](https://app.snyk.io/org/emanchado/project/23b62348-d9b2-454a-8749-ec8c52ac9cec?utm_source=github&utm_medium=referral&page=fix-pr/settings) 📚 [Read more about Snyk's upgrade and patch logic](https://support.snyk.io/hc/en-us/articles/360003891078-Snyk-patches-to-fix-vulnerabilities) [//]: # (snyk:metadata:{"prId":"df180be0-4c36-4258-9a23-a09e42903e8c","prPublicId":"df180be0-4c36-4258-9a23-a09e42903e8c","dependencies":[{"name":"babel-brunch","from":"6.1.1","to":"7.0.0"},{"name":"db-migrate","from":"0.10.7","to":"0.11.7"},{"name":"sqlite3","from":"4.2.0","to":"5.0.3"}],"packageManager":"npm","projectPublicId":"23b62348-d9b2-454a-8749-ec8c52ac9cec","projectUrl":"https://app.snyk.io/org/emanchado/project/23b62348-d9b2-454a-8749-ec8c52ac9cec?utm_source=github&utm_medium=referral&page=fix-pr","type":"auto","patch":[],"vulns":["SNYK-JS-ANSIREGEX-1583908","SNYK-JS-BABELTRAVERSE-5962463","SNYK-JS-GLOBPARENT-1016905","SNYK-JS-JSON5-3182856","SNYK-JS-MINIMIST-2429795","SNYK-JS-MINIMIST-559764"],"upgrade":["SNYK-JS-ANSIREGEX-1583908","SNYK-JS-BABELTRAVERSE-5962463","SNYK-JS-GLOBPARENT-1016905","SNYK-JS-JSON5-3182856","SNYK-JS-MINIMIST-2429795","SNYK-JS-MINIMIST-559764"],"isBreakingChange":true,"env":"prod","prType":"fix","templateVariants":["priorityScore"],"priorityScoreList":[696,679,586,641,506,601],"remediationStrategy":"vuln"}) --- **Learn how to fix vulnerabilities with free interactive lessons:** 🦉 [Regular Expression Denial of Service (ReDoS)](https://learn.snyk.io/lesson/redos/?loc=fix-pr) 🦉 [Prototype Pollution](https://learn.snyk.io/lesson/prototype-pollution/?loc=fix-pr)