loft-sh / loft

Namespace & Virtual Cluster Manager for Kubernetes - Lightweight Virtual Clusters, Self-Service Provisioning for Engineers and 70% Cost Savings with Sleep Mode
https://loft.sh/docs/introduction
Other
737 stars 65 forks source link

[Snyk] Fix for 3 vulnerabilities #211

Open LukasGentele opened 2 years ago

LukasGentele commented 2 years ago

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to fix one or more vulnerable packages in the `yarn` dependencies of this project.

#### Changes included in this PR - Changes to the following files to upgrade the vulnerable dependencies to a fixed version: - docs/package.json - docs/yarn.lock #### Vulnerabilities that will be fixed ##### With an upgrade: Severity | Priority Score (*) | Issue | Breaking Change | Exploit Maturity :-------------------------:|-------------------------|:-------------------------|:-------------------------|:------------------------- ![medium severity](https://res.cloudinary.com/snyk/image/upload/w_20,h_20/v1561977819/icon/m.png "medium severity") | **591/1000**
**Why?** Proof of Concept exploit, Has a fix available, CVSS 5.4 | Cross-site Scripting (XSS)
[SNYK-JS-BRAINTREESANITIZEURL-2339882](https://snyk.io/vuln/SNYK-JS-BRAINTREESANITIZEURL-2339882) | Yes | Proof of Concept ![low severity](https://res.cloudinary.com/snyk/image/upload/w_20,h_20/v1561977819/icon/l.png "low severity") | **394/1000**
**Why?** Has a fix available, CVSS 3.6 | Code Injection
[SNYK-JS-MDXMERMAID-3009151](https://snyk.io/vuln/SNYK-JS-MDXMERMAID-3009151) | No | No Known Exploit ![medium severity](https://res.cloudinary.com/snyk/image/upload/w_20,h_20/v1561977819/icon/m.png "medium severity") | **586/1000**
**Why?** Proof of Concept exploit, Has a fix available, CVSS 5.3 | Information Exposure
[SNYK-JS-MERMAID-2936793](https://snyk.io/vuln/SNYK-JS-MERMAID-2936793) | Yes | Proof of Concept (*) Note that the real score may have changed since the PR was raised. Check the changes in this PR to ensure they won't cause issues with your project. ------------ **Note:** *You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.* For more information: 🧐 [View latest project report](https://app.snyk.io/org/loft-fzm/project/478fa249-ca8a-4a6a-8169-ee21dd27be69?utm_source=github&utm_medium=referral&page=fix-pr) 🛠 [Adjust project settings](https://app.snyk.io/org/loft-fzm/project/478fa249-ca8a-4a6a-8169-ee21dd27be69?utm_source=github&utm_medium=referral&page=fix-pr/settings) 📚 [Read more about Snyk's upgrade and patch logic](https://support.snyk.io/hc/en-us/articles/360003891078-Snyk-patches-to-fix-vulnerabilities) [//]: # (snyk:metadata:{"prId":"52b51edd-0591-4e64-97f6-3999a1e39be9","prPublicId":"52b51edd-0591-4e64-97f6-3999a1e39be9","dependencies":[{"name":"mdx-mermaid","from":"1.2.2","to":"1.3.0"},{"name":"mermaid","from":"8.14.0","to":"9.1.3"}],"packageManager":"yarn","projectPublicId":"478fa249-ca8a-4a6a-8169-ee21dd27be69","projectUrl":"https://app.snyk.io/org/loft-fzm/project/478fa249-ca8a-4a6a-8169-ee21dd27be69?utm_source=github&utm_medium=referral&page=fix-pr","type":"auto","patch":[],"vulns":["SNYK-JS-MERMAID-2936793","SNYK-JS-MDXMERMAID-3009151","SNYK-JS-BRAINTREESANITIZEURL-2339882"],"upgrade":["SNYK-JS-BRAINTREESANITIZEURL-2339882","SNYK-JS-MDXMERMAID-3009151","SNYK-JS-MERMAID-2936793"],"isBreakingChange":true,"env":"prod","prType":"fix","templateVariants":["priorityScore"],"priorityScoreList":[586,394,591]}) --- **Learn how to fix vulnerabilities with free interactive lessons:** 🦉 [Code Injection](https://learn.snyk.io/lessons/malicious-code-injection/javascript/?loc=fix-pr) 🦉 [Cross-site Scripting (XSS)](https://learn.snyk.io/lessons/xss/javascript/?loc=fix-pr)
netlify[bot] commented 2 years ago

Deploy Preview for loft-docs ready!

Name Link
Latest commit e741563ddcfe39148590560420d365af72d73f35
Latest deploy log https://app.netlify.com/sites/loft-docs/deploys/6332909ac6641f00085f45f3
Deploy Preview https://deploy-preview-211--loft-docs.netlify.app
Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.

To edit notification comments on pull requests, go to your Netlify site settings.