recurly / starsky

High-level, opinionated RabbitMQ for Node.
MIT License
4 stars 1 forks source link

[Snyk] Fix for 1 vulnerabilities #24

Open snyk-bot opened 4 years ago

snyk-bot commented 4 years ago

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

Vulnerabilities that will be fixed

With a Snyk patch:
Severity Issue Exploit Maturity
medium severity Prototype Pollution
SNYK-JS-LODASH-567746
Proof of Concept

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:

🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic

guardrails[bot] commented 4 years ago

:warning: We detected security issues in this pull request:

Vulnerable Libraries (2) - [growl@1.7.0](https://github.com/recurly/starsky/blob/821f0edd559e746908b5ad2997a029ce5f4a0efe/package.json#Lnull) upgrade to `>=1.10.2` - [minimatch@0.2.14](https://github.com/recurly/starsky/blob/821f0edd559e746908b5ad2997a029ce5f4a0efe/package.json#Lnull) upgrade to `>=3.0.2` More info on how to fix Vulnerable Libraries in [Javascript](https://www.guardrails.io/docs/en/vulnerabilities/javascript/using_vulnerable_libraries.html?utm_source=ghpr).

👉 Go to the dashboard for detailed results.

📥 Happy? Share your feedback with us.