iotaledger / wasp

Node for IOTA Smart Contracts
Apache License 2.0
296 stars 147 forks source link

[Snyk] Fix for 2 vulnerabilities #3403

Closed begonaalvarezd closed 5 months ago

begonaalvarezd commented 5 months ago

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

#### Changes included in this PR - Changes to the following files to upgrade the vulnerable dependencies to a fixed version: - contracts/wasm/fairroulette/frontend/package.json #### Vulnerabilities that will be fixed ##### With an upgrade: Severity | Priority Score (*) | Issue | Breaking Change | Exploit Maturity :-------------------------:|-------------------------|:-------------------------|:-------------------------|:------------------------- ![high severity](https://res.cloudinary.com/snyk/image/upload/w_20,h_20/v1561977819/icon/h.png "high severity") | **661/1000**
**Why?** Recently disclosed, Has a fix available, CVSS 7.5 | Uncontrolled resource consumption
[SNYK-JS-BRACES-6838727](https://snyk.io/vuln/SNYK-JS-BRACES-6838727) | Yes | No Known Exploit ![high severity](https://res.cloudinary.com/snyk/image/upload/w_20,h_20/v1561977819/icon/h.png "high severity") | **661/1000**
**Why?** Recently disclosed, Has a fix available, CVSS 7.5 | Inefficient Regular Expression Complexity
[SNYK-JS-MICROMATCH-6838728](https://snyk.io/vuln/SNYK-JS-MICROMATCH-6838728) | Yes | No Known Exploit (*) Note that the real score may have changed since the PR was raised.
Commit messages
Package name: @typescript-eslint/eslint-plugin The new version differs by 250 commits.
  • 8894106 chore: publish v5.10.0
  • 5046882 fix(type-utils): intersection types involving readonly arrays are now handled in most cases (#4429)
  • 39a6806 fix(type-utils): isTypeReadonly now handles conditional types (#4421)
  • f4016c2 fix(eslint-plugin): [no-extra-semi] false negatives when used with eslint 8.3.0 (#4458)
  • 99ab193 fix(type-utils): union types always being marked as readonly (#4419)
  • ef3147c fix(type-utils): check IndexSignature internals when checking isTypeReadonly (#4417)
  • 3061ea9 chore: bump @ babel/types from 7.16.7 to 7.16.8 (#4454)
  • e56f1e5 fix(eslint-plugin): [no-invalid-this] crash when used with eslint 8.7.0 (#4448)
  • ba3d3a3 chore: bump eslint-plugin-jest from 25.3.4 to 25.7.0 (#4456)
  • 04cb5d8 chore: bump ts-jest from 27.1.2 to 27.1.3 (#4457)
  • d8e296d chore: bump webpack from 5.65.0 to 5.66.0 (#4455)
  • d053cde fix(eslint-plugin): [explicit-function-return-type] support AllowTypedFunctionExpression within AllowHigherOrderFunction (#4250)
  • 8a30108 chore: bump eslint-visitor-keys from 3.1.0 to 3.2.0 (#4452)
  • 377cbcf chore: bump rollup from 2.63.0 to 2.64.0 (#4450)
  • daf7990 chore: bump @ types/prettier from 2.4.2 to 2.4.3 (#4451)
  • 4cb46ff chore: bump downlevel-dts from 0.7.0 to 0.8.0 (#4447)
  • ff05dd8 test(type-utils): fix incorrect utils import (#4453)
  • 95aea18 refactor(eslint-plugin): [restrict-plus-operands] add better error messages (#4332)
  • ea85dda test(type-utils): add basic tests for isTypeReadonly (#4416)
  • c8e650f fix(eslint-plugin): [no-magic-numbers] handle bigint in class props (#4411)
  • 253bfa3 docs: fix typo in comment (#4445)
  • 4bda6ec chore: bump shelljs from 0.8.4 to 0.8.5 (#4442)
  • 9eb0a5b chore: bump follow-redirects from 1.14.5 to 1.14.7 (#4437)
  • 1d55a75 feat: rename `experimental-utils` to `utils` and make `experimental-utils` an alias to the new package (#4172)
See the full diff
Package name: svelte-preprocess The new version differs by 40 commits.
  • fdb8a90 chore(release): 5.0.2
  • 731516d fix: remove deprecated package @ types/sass (#583)
  • adb87b9 fix: add support for TypeScript 5 (#585)
  • 1097b79 docs: update issue link
  • 7428ee6 chore(release): 5.0.1
  • 278de4f chore: update sorcery (#571)
  • fdbbbb9 docs: Update documentation about Sass options
  • 4218419 docs: fix changelog
  • 83ee372 chore(release): 5.0.0
  • 537b975 chore(release): 5.0.0-alpha.1
  • f0382b6 docs: fix changelog
  • 2c0bd45 fix: map .sss as .css to support sugarss extension
  • 3f2687b fix: πŸ› add sugarss v3 and v4 as supported
  • 8ca4890 chore(release): 5.0.0-alpha.0
  • 3d60856 fix: πŸ› remove support for custom default languages
  • 2806ada feat: 🎸 bump minimum node version to 14
  • c98b3e9 chore: rename coffeescript to coffee in test
  • 3f01e23 test: fix scss dependencies test
  • 07bc8aa fix: πŸ› remove support for 'type' attribute
  • 9f4c29f chore: remove unused method
  • 240a588 docs: tell, that we use legacy api (#453)
  • a88a45c chore: update linter and formatter
  • 06fd5b9 chore: use sass types for legacy render API. Support sync version only
  • 1cb01f0 chore: fix type after svelte upgrade
See the full diff
Check the changes in this PR to ensure they won't cause issues with your project. ------------ **Note:** *You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.* For more information: 🧐 [View latest project report](https://app.snyk.io/org/iota-foundation/project/273c36f5-0494-4167-8e00-27bbaf0c61ad?utm_source=github&utm_medium=referral&page=fix-pr) πŸ›  [Adjust project settings](https://app.snyk.io/org/iota-foundation/project/273c36f5-0494-4167-8e00-27bbaf0c61ad?utm_source=github&utm_medium=referral&page=fix-pr/settings) πŸ“š [Read more about Snyk's upgrade and patch logic](https://support.snyk.io/hc/en-us/articles/360003891078-Snyk-patches-to-fix-vulnerabilities) [//]: # (snyk:metadata:{"prId":"4aa62d7c-a827-47d0-80e9-f14de99575d3","prPublicId":"4aa62d7c-a827-47d0-80e9-f14de99575d3","dependencies":[{"name":"@typescript-eslint/eslint-plugin","from":"4.33.0","to":"5.10.0"},{"name":"svelte-check","from":"2.10.3","to":"3.0.0"},{"name":"svelte-preprocess","from":"4.10.7","to":"5.0.2"}],"packageManager":"npm","projectPublicId":"273c36f5-0494-4167-8e00-27bbaf0c61ad","projectUrl":"https://app.snyk.io/org/iota-foundation/project/273c36f5-0494-4167-8e00-27bbaf0c61ad?utm_source=github&utm_medium=referral&page=fix-pr","type":"auto","patch":[],"vulns":["SNYK-JS-BRACES-6838727","SNYK-JS-MICROMATCH-6838728"],"upgrade":["SNYK-JS-BRACES-6838727","SNYK-JS-MICROMATCH-6838728"],"isBreakingChange":true,"env":"prod","prType":"fix","templateVariants":["priorityScore"],"priorityScoreList":[661,661],"remediationStrategy":"vuln"}) --- **Learn how to fix vulnerabilities with free interactive lessons:** πŸ¦‰ [Uncontrolled resource consumption](https://learn.snyk.io/lesson/redos/?loc=fix-pr)