Open svcsnyksanity opened 1 month ago
New and removed dependencies detected. Learn more about Socket for GitHub โ๏ธ
Package | New capabilities | Transitives | Size | Publisher |
---|---|---|---|---|
npm/@sanity/pkg-utils@6.11.4 | environment Transitive: eval, filesystem, network, shell, unsafe | +270 |
593 MB | sanity-io |
๐ฎ Removed packages: npm/@sanity/pkg-utils@6.11.2
Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.
Changes included in this PR
Vulnerabilities that will be fixed
With an upgrade:
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
SNYK-JS-BRACES-6838727
(*) Note that the real score may have changed since the PR was raised.
Check the changes in this PR to ensure they won't cause issues with your project.
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.
For more information: ๐ง View latest project report
๐ Adjust project settings
๐ Read more about Snyk's upgrade and patch logic
Learn how to fix vulnerabilities with free interactive lessons:
๐ฆ Uncontrolled resource consumption