ibm-ecosystem-engineering / ibm-gsi-cloudnative-journey

Cloud Native Learning Journey to enable GSI Partners to learn cloud native development with the IBM Enterprise Sandbox
https://ibm-ecosystem-lab.github.io/ibm-gsi-cloudnative-journey/
Apache License 2.0
4 stars 26 forks source link

[Snyk] Upgrade prismjs from 1.23.0 to 1.29.0 #299

Open mjperrins opened 1 month ago

mjperrins commented 1 month ago

This PR was automatically created by Snyk using the credentials of a real user.


![snyk-top-banner](https://github.com/andygongea/OWASP-Benchmark/assets/818805/c518c423-16fe-447e-b67f-ad5a49b5d123)

Snyk has created this PR to upgrade prismjs from 1.23.0 to 1.29.0.

:information_source: Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.
- The recommended version is **7 versions** ahead of your current version. - The recommended version was released on **2 years ago**. #### Issues fixed by the recommended upgrade: | | Issue | Score | Exploit Maturity | :-------------------------:|:-------------------------|:-------------------------|:------------------------- ![high severity](https://res.cloudinary.com/snyk/image/upload/w_20,h_20/v1561977819/icon/h.png 'high severity') | Regular Expression Denial of Service (ReDoS)
[SNYK-JS-PRISMJS-1314893](https://snyk.io/vuln/SNYK-JS-PRISMJS-1314893) | **372** | No Known Exploit ![high severity](https://res.cloudinary.com/snyk/image/upload/w_20,h_20/v1561977819/icon/h.png 'high severity') | Improper Input Validation
[SNYK-JS-URLPARSE-2407770](https://snyk.io/vuln/SNYK-JS-URLPARSE-2407770) | **372** | Proof of Concept ![high severity](https://res.cloudinary.com/snyk/image/upload/w_20,h_20/v1561977819/icon/h.png 'high severity') | Regular Expression Denial of Service (ReDoS)
[SNYK-JS-PRISMJS-1585202](https://snyk.io/vuln/SNYK-JS-PRISMJS-1585202) | **372** | Proof of Concept ![medium severity](https://res.cloudinary.com/snyk/image/upload/w_20,h_20/v1561977819/icon/m.png 'medium severity') | Open Redirect
[SNYK-JS-URLPARSE-1533425](https://snyk.io/vuln/SNYK-JS-URLPARSE-1533425) | **372** | Proof of Concept ![medium severity](https://res.cloudinary.com/snyk/image/upload/w_20,h_20/v1561977819/icon/m.png 'medium severity') | Access Restriction Bypass
[SNYK-JS-URLPARSE-2401205](https://snyk.io/vuln/SNYK-JS-URLPARSE-2401205) | **372** | Proof of Concept ![medium severity](https://res.cloudinary.com/snyk/image/upload/w_20,h_20/v1561977819/icon/m.png 'medium severity') | Authorization Bypass
[SNYK-JS-URLPARSE-2407759](https://snyk.io/vuln/SNYK-JS-URLPARSE-2407759) | **372** | Proof of Concept ![medium severity](https://res.cloudinary.com/snyk/image/upload/w_20,h_20/v1561977819/icon/m.png 'medium severity') | Authorization Bypass Through User-Controlled Key
[SNYK-JS-URLPARSE-2412697](https://snyk.io/vuln/SNYK-JS-URLPARSE-2412697) | **372** | Proof of Concept ![medium severity](https://res.cloudinary.com/snyk/image/upload/w_20,h_20/v1561977819/icon/m.png 'medium severity') | Cross-site Scripting (XSS)
[SNYK-JS-PRISMJS-2404333](https://snyk.io/vuln/SNYK-JS-PRISMJS-2404333) | **372** | No Known Exploit
Release notes
Package name: prismjs
  • 1.29.0 - 2022-08-23

    Release 1.29.0

      </li>
      <li>
        <b>1.28.0</b> - <a href="https://github.com/PrismJS/prism/releases/tag/v1.28.0">2022-04-17</a></br><p>Release 1.28.0</p>
      </li>
      <li>
        <b>1.27.0</b> - <a href="https://github.com/PrismJS/prism/releases/tag/v1.27.0">2022-02-17</a></br><p>Release 1.27.0</p>
      </li>
      <li>
        <b>1.26.0</b> - <a href="https://github.com/PrismJS/prism/releases/tag/v1.26.0">2022-01-06</a></br><p>Release 1.26.0</p>
      </li>
      <li>
        <b>1.25.0</b> - <a href="https://github.com/PrismJS/prism/releases/tag/v1.25.0">2021-09-16</a></br><p>Release 1.25.0</p>
      </li>
      <li>
        <b>1.24.1</b> - <a href="https://github.com/PrismJS/prism/releases/tag/v1.24.1">2021-07-03</a></br><p>Release 1.24.1</p>
      </li>
      <li>
        <b>1.24.0</b> - <a href="https://github.com/PrismJS/prism/releases/tag/v1.24.0">2021-06-27</a></br><p>Release 1.24.0</p>
      </li>
      <li>
        <b>1.23.0</b> - <a href="https://github.com/PrismJS/prism/releases/tag/v1.23.0">2020-12-31</a></br><p>Release 1.23.0</p>
      </li>
    </ul>
    from <a href="https://github.com/PrismJS/prism/releases">prismjs GitHub release notes</a>


[!IMPORTANT]

  • Check the changes in this PR to ensure they won't cause issues with your project.
  • This PR was automatically created by Snyk using the credentials of a real user.
  • Max score is 1000. Note that the real score may have changed since the PR was raised.

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information: