pustovitDmytro / lalaps

autofix security issues.
MIT License
0 stars 1 forks source link

Chore: fixes some npm audit vulnerabilities #67

Open lalaps[bot] opened 2 years ago

lalaps[bot] commented 2 years ago

This PR fixes some of found vulnerabilities.

Fixed 6 of 19 npm vulnerabilities. 13 issues left. Success Rate: 31.6%

Vulnerabilities:

Inefficient Regular Expression Complexity in chalk/ansi-regex Library: ansi-regex Affected versions: >=3.0.0 <3.0.1 Severity: high Fix: :heavy_check_mark: true Root Libraries:

decode-uri-component vulnerable to Denial of Service (DoS) Library: decode-uri-component Affected versions: <=0.2.0 Severity: low Fix: :x: 11.2.0 Root Libraries:

ejs template injection vulnerability Library: ejs Affected versions: <3.1.7 Severity: critical Fix: :x: 3.11.1 Root Libraries:

Exposure of Sensitive Information to an Unauthorized Actor in follow-redirects Library: follow-redirects Affected versions: <1.14.8 Severity: moderate Fix: :heavy_check_mark: true Root Libraries:

minimatch ReDoS vulnerability Library: minimatch Affected versions: <3.0.5 Severity: high Fix: :x: true Root Libraries:

Prototype Pollution in minimist Library: minimist Affected versions: <1.2.6 Severity: critical Fix: :heavy_check_mark: true Root Libraries:

Path Traversal: 'dir/../../filename' in moment.locale Library: moment Affected versions: <2.29.2 Severity: high Fix: :heavy_check_mark: true Root Libraries:

Command Injection in moment-timezone Library: moment-timezone Affected versions: >=0.1.0 <0.5.35 Severity: low Fix: :heavy_check_mark: true Root Libraries:

Packing does not respect root-level ignore files in workspaces Library: npm Affected versions: >=7.9.0 <8.11.0 Severity: high Fix: :heavy_check_mark: true Root Libraries:

Authorization Bypass in parse-path Library: parse-path Affected versions: <5.0.0 Severity: high Fix: :x: true Root Libraries:

Cross site scripting in parse-url Library: parse-url Affected versions: <6.0.1 Severity: moderate Fix: :heavy_check_mark: true Root Libraries:

Exposure of Sensitive Information to an Unauthorized Actor in semantic-release Library: semantic-release Affected versions: >=17.0.4 <19.0.3 Severity: moderate Fix: :heavy_check_mark: true Root Libraries:

Regular expression denial of service in semver-regex Library: semver-regex Affected versions: <3.1.4 Severity: low Fix: :heavy_check_mark: true Root Libraries:

Command injection in simple-git Library: simple-git Affected versions: <3.3.0 Severity: high Fix: :x: 3.15.1 Root Libraries:

You can wait for the next updates with a full fix or merge immediately. In case of closing this PR, it will be recreated. If that's undesired, modify config.


This change is Reviewable

sonarcloud[bot] commented 1 year ago

Kudos, SonarCloud Quality Gate passed!    Quality Gate passed

Bug A 0 Bugs
Vulnerability A 0 Vulnerabilities
Security Hotspot A 0 Security Hotspots
Code Smell A 0 Code Smells

No Coverage information No Coverage information
No Duplication information No Duplication information