ianperrin / MMM-ModuleScheduler

A MagicMirror helper module to schedule the display of modules and sending of notifications.
MIT License
101 stars 13 forks source link

Vulnerability Issue #45

Open funk0id opened 10 months ago

funk0id commented 10 months ago

2 vulnerabilities (1 moderate, 1 high) are being reported, npm audit fix returns the following...

npm audit report

minimatch <3.0.5 Severity: high minimatch ReDoS vulnerability - https://github.com/advisories/GHSA-f8q6-p94x-37v3 fix available via npm audit fix --force Will install mocha@10.2.0, which is a breaking change node_modules/minimatch mocha 5.1.0 - 9.2.1 Depends on vulnerable versions of minimatch Depends on vulnerable versions of nanoid node_modules/mocha

nanoid 3.0.0 - 3.1.30 Severity: moderate Exposure of Sensitive Information to an Unauthorized Actor in nanoid - https://github.com/advisories/GHSA-qrpm-p2h7-hrv2 fix available via npm audit fix --force Will install mocha@10.2.0, which is a breaking change node_modules/nanoid

3 vulnerabilities (1 moderate, 2 high)

To address all issues (including breaking changes), run: npm audit fix --force