infoderm / patients

:face_with_thermometer: Patients meteor app
GNU Affero General Public License v3.0
5 stars 2 forks source link

[Snyk] Fix for 2 vulnerabilities #1072

Open make-github-pseudonymous-again opened 1 month ago

make-github-pseudonymous-again commented 1 month ago

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
medium severity 601/1000
Why? Recently disclosed, Has a fix available, CVSS 6.3
Cross-site Scripting (XSS)
SNYK-JS-COOKIE-8163060
No No Known Exploit
high severity 701/1000
Why? Recently disclosed, Has a fix available, CVSS 8.3
Improper Verification of Cryptographic Signature
SNYK-JS-ELLIPTIC-8172694
No No Known Exploit

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: express The new version differs by 53 commits.
  • 8e229f9 4.21.1
  • a024c8a fix(deps): cookie@0.7.1
  • 7e562c6 4.21.0
  • 1bcde96 fix(deps): qs@6.13.0 (#5946)
  • 7d36477 fix(deps): serve-static@1.16.2 (#5951)
  • 40d2d8f fix(deps): finalhandler@1.3.1
  • 77ada90 Deprecate `"back"` magic string in redirects (#5935)
  • 21df421 4.20.0
  • 4c9ddc1 feat: upgrade to serve-static@0.16.0
  • 9ebe5d5 feat: upgrade to send@0.19.0 (#5928)
  • ec4a01b feat: upgrade to body-parser@1.20.3 (#5926)
  • 54271f6 fix: don't render redirect values in anchor href
  • 125bb74 path-to-regexp@0.1.10 (#5902)
  • 2a980ad merge-descriptors@1.0.3 (#5781)
  • a3e7e05 docs: specify new instructions for `question` and `discuss`
  • c5addb9 deps: path-to-regexp@0.1.8 (#5603)
  • e35380a docs: add @ IamLizu to the triage team (#5836)
  • f5b6e67 docs: update scorecard link (#5814)
  • 2177f67 docs: add OSSF Scorecard badge (#5436)
  • f4bd86e Replace Appveyor windows testing with GHA (#5599)
  • 2ec589c Fix Contributor Covenant link definition reference in attribution section (#5762)
  • 4cf7eed remove minor version pinning from ci (#5722)
  • 6d08471 📝 update people, add ctcpip to TC (#5683)
  • 61421a8 skip QUERY tests for Node 21 only, still not supported (#5695)
See the full diff
Package name: meteor-node-stubs The new version differs by 250 commits.
  • dcb285b Merge branch 'devel' into feature/elliptic-npm-update
  • 950658c Merge pull request #13306 from meteor/feature/prepare-v3-docs
  • 80252c1 Update elliptic
  • 36aa315 update docs path
  • f698cca Create the Not Found page
  • c4cd4d5 Merge pull request #13302 from meteor/v3/remove-old-changelogs
  • 8d7b179 Merge branch 'devel' into v3/remove-old-changelogs
  • 12375f9 Merge pull request #13279 from meteor/meteor-3-vue-3-tutorial
  • 973ee6a remove legacy
  • 812ad9b fix v1 reference
  • 2b27392 remove old changelogs
  • 56d093d Merge remote-tracking branch 'origin/meteor-3-vue-3-tutorial' into meteor-3-vue-3-tutorial
  • 2f62899 Add warning about the vue-meteor-tracker package
  • 2cd4242 Merge branch 'devel' into meteor-3-vue-3-tutorial
  • e37dccf Merge pull request #13237 from meteor/release-3.0.2
  • f51c910 publish a new version for email package
  • 3a00b11 update README.md
  • b29ceb6 Merge remote-tracking branch 'origin/release-3.0.2' into release-3.0.2
  • 8aebfa9 publish version 3.0.2 of the meteor installer
  • 75d0f92 Merge branch 'devel' into meteor-3-vue-3-tutorial
  • 5d9eaea Merge branch 'release-3.0.2' of https://github.com/meteor/meteor into release-3.0.2
  • 88dafd6 re-run checks
  • 921c61f update npm-shrinkwrap.json files
  • 9f5f3d8 Meteor version to 3.0.2 :comet:
See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information: 🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Cross-site Scripting (XSS)