requestly / requestly-desktop-app

Requestly Desktop App (Mac, Linux, Windows)
https://requestly.io/
GNU Affero General Public License v3.0
45 stars 10 forks source link

[Snyk] Security upgrade mockttp from 2.3.0 to 2.5.1 #84

Closed Dinex-dev closed 5 months ago

Dinex-dev commented 5 months ago

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

#### Changes included in this PR - Changes to the following files to upgrade the vulnerable dependencies to a fixed version: - release/app/package.json - release/app/package-lock.json #### Vulnerabilities that will be fixed ##### With an upgrade: Severity | Issue | Breaking Change | Exploit Maturity :-------------------------:|:-------------------------|:-------------------------|:------------------------- ![medium severity](https://res.cloudinary.com/snyk/image/upload/w_20,h_20/v1561977819/icon/m.png "medium severity") | Open Redirect
[SNYK-JS-NODEFORGE-2330875](https://snyk.io/vuln/SNYK-JS-NODEFORGE-2330875) | No | Proof of Concept ![medium severity](https://res.cloudinary.com/snyk/image/upload/w_20,h_20/v1561977819/icon/m.png "medium severity") | Prototype Pollution
[SNYK-JS-NODEFORGE-2331908](https://snyk.io/vuln/SNYK-JS-NODEFORGE-2331908) | No | No Known Exploit ![medium severity](https://res.cloudinary.com/snyk/image/upload/w_20,h_20/v1561977819/icon/m.png "medium severity") | Improper Verification of Cryptographic Signature
[SNYK-JS-NODEFORGE-2430337](https://snyk.io/vuln/SNYK-JS-NODEFORGE-2430337) | No | No Known Exploit ![high severity](https://res.cloudinary.com/snyk/image/upload/w_20,h_20/v1561977819/icon/h.png "high severity") | Improper Verification of Cryptographic Signature
[SNYK-JS-NODEFORGE-2430339](https://snyk.io/vuln/SNYK-JS-NODEFORGE-2430339) | No | No Known Exploit ![medium severity](https://res.cloudinary.com/snyk/image/upload/w_20,h_20/v1561977819/icon/m.png "medium severity") | Improper Verification of Cryptographic Signature
[SNYK-JS-NODEFORGE-2430341](https://snyk.io/vuln/SNYK-JS-NODEFORGE-2430341) | No | No Known Exploit ![critical severity](https://res.cloudinary.com/snyk/image/upload/w_20,h_20/v1561977819/icon/c.png "critical severity") | Remote Code Execution (RCE)
[SNYK-JS-VM2-5772823](https://snyk.io/vuln/SNYK-JS-VM2-5772823) | No | Proof of Concept ![critical severity](https://res.cloudinary.com/snyk/image/upload/w_20,h_20/v1561977819/icon/c.png "critical severity") | Remote Code Execution (RCE)
[SNYK-JS-VM2-5772825](https://snyk.io/vuln/SNYK-JS-VM2-5772825) | No | Mature
Commit messages
Package name: mockttp The new version differs by 26 commits.
  • fe5da42 2.5.1
  • 00eabb1 Merge pull request #69 to fix node-forge audit warnings
  • 91751ad Update package.json
  • f3b6cc9 Update package.json
  • c4a18bf Merge pull request #65 from ridarf/new-years-certificate-fix
  • baa66c7 Fix new years certificate instant expiry
  • d1f3647 2.5.0
  • f91f15f Avoid warnings about accessing statusMessage on HTTP/2 responses
  • 7f37653 Update httpolyglot to remove _stream_wrap deprecation warning
  • 7797320 Remove some now-unnecessary internal type definitions
  • 101e736 Use tls.DEFAULT_CIPHERS over defaultCipherList
  • d277b23 Twiddle our ciphers slightly to defeat TLS fingerprinting
  • 70c1996 Replace custom typings with the new @ types/native-duplexpair
  • a54b996 Add remotePort to all event data
  • 65d04e4 Add .forX() methods for rule building, deprecating .get, .post etc
  • 487d42e 2.4.0
  • 758e264 Cleanup some leftover unnecessary ProxyConfig code
  • 3397502 Update Mocha to resolve a minor audit warning
  • 2b47ee6 Switch to a temporary proxy-agent fork, to fix SOCKS + custom DNS
  • 713048c Expose rule parameter keys on standalone server instances too
  • 4ef7202 Add a method to query the rule parameters available
  • 76bdbbe Fix the Node dns.lookup type workaround
  • 7ed2549 Allow passing ProxyConfig arrays, to provide callback fallbacks
  • 19cb3f0 Add support for callback & standalone-server parameterized proxyConfig
See the full diff
Check the changes in this PR to ensure they won't cause issues with your project. ------------ **Note:** *You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.* For more information: 🧐 [View latest project report](https://app.snyk.io/org/sagar-r2x/project/ae0388a3-d7b1-49b0-b62a-b6125113feab?utm_source=github&utm_medium=referral&page=fix-pr) πŸ›  [Adjust project settings](https://app.snyk.io/org/sagar-r2x/project/ae0388a3-d7b1-49b0-b62a-b6125113feab?utm_source=github&utm_medium=referral&page=fix-pr/settings) πŸ“š [Read more about Snyk's upgrade and patch logic](https://support.snyk.io/hc/en-us/articles/360003891078-Snyk-patches-to-fix-vulnerabilities) [//]: # (snyk:metadata:{"prId":"926bcc9f-20ad-4452-bb13-24d3653eeea1","prPublicId":"926bcc9f-20ad-4452-bb13-24d3653eeea1","dependencies":[{"name":"mockttp","from":"2.3.0","to":"2.5.1"}],"packageManager":"npm","projectPublicId":"ae0388a3-d7b1-49b0-b62a-b6125113feab","projectUrl":"https://app.snyk.io/org/sagar-r2x/project/ae0388a3-d7b1-49b0-b62a-b6125113feab?utm_source=github&utm_medium=referral&page=fix-pr","type":"auto","patch":[],"vulns":["SNYK-JS-NODEFORGE-2330875","SNYK-JS-NODEFORGE-2331908","SNYK-JS-NODEFORGE-2430337","SNYK-JS-NODEFORGE-2430339","SNYK-JS-NODEFORGE-2430341","SNYK-JS-VM2-5772823","SNYK-JS-VM2-5772825"],"upgrade":["SNYK-JS-NODEFORGE-2330875","SNYK-JS-NODEFORGE-2331908","SNYK-JS-NODEFORGE-2430337","SNYK-JS-NODEFORGE-2430339","SNYK-JS-NODEFORGE-2430341","SNYK-JS-VM2-5772823","SNYK-JS-VM2-5772825"],"isBreakingChange":false,"env":"prod","prType":"fix","templateVariants":["updated-fix-title"],"priorityScoreList":[null,null,null,null,null,811,876],"remediationStrategy":"vuln"}) --- **Learn how to fix vulnerabilities with free interactive lessons:** πŸ¦‰ [Open Redirect](https://learn.snyk.io/lesson/open-redirect/?loc=fix-pr) πŸ¦‰ [Prototype Pollution](https://learn.snyk.io/lesson/prototype-pollution/?loc=fix-pr) πŸ¦‰ [Remote Code Execution (RCE)](https://learn.snyk.io/lesson/malicious-code-injection/?loc=fix-pr)