sanity-io / sanity-plugin-markdown

Markdown support in the Sanity Studio
MIT License
51 stars 8 forks source link

[Snyk] Fix for 11 vulnerabilities #99

Closed svcsnyksanity closed 2 months ago

svcsnyksanity commented 2 months ago

snyk-top-banner

Snyk has created this PR to fix 11 vulnerabilities in the npm dependencies of this project.

Snyk changed the following file(s):

Vulnerabilities that will be fixed with an upgrade:

Issue Score
critical severity Incomplete List of Disallowed Inputs
SNYK-JS-BABELTRAVERSE-5962462
  786  
high severity Uncontrolled resource consumption
SNYK-JS-BRACES-6838727
  696  
high severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-SEMVER-3247795
  696  
high severity Path Equivalence
SNYK-JS-VITE-5664718
  696  
high severity Access Control Bypass
SNYK-JS-VITE-6182924
  696  
high severity Improper Input Validation
SNYK-JS-FOLLOWREDIRECTS-6141137
  686  
medium severity Information Exposure
SNYK-JS-FOLLOWREDIRECTS-6444610
  646  
medium severity Prototype Pollution
SNYK-JS-TOUGHCOOKIE-5672873
  646  
medium severity Improper Access Control
SNYK-JS-VITE-6531286
  616  
low severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-WORDWRAP-3149973
  506  
medium severity Improper Input Validation
SNYK-JS-POSTCSS-5926692
  479  

[!IMPORTANT]

  • Check the changes in this PR to ensure they won't cause issues with your project.
  • Max score is 1000. Note that the real score may have changed since the PR was raised.
  • This PR was automatically created by Snyk using the credentials of a real user.

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information: ๐Ÿง View latest project report ๐Ÿ“œ Customise PR templates ๐Ÿ›  Adjust project settings ๐Ÿ“š Read about Snyk's upgrade logic


Learn how to fix vulnerabilities with free interactive lessons:

๐Ÿฆ‰ Uncontrolled resource consumption ๐Ÿฆ‰ Improper Input Validation ๐Ÿฆ‰ Prototype Pollution ๐Ÿฆ‰ More lessons are available in Snyk Learn

socket-security[bot] commented 2 months ago

New and removed dependencies detected. Learn more about Socket for GitHub โ†—๏ธŽ

Package New capabilities Transitives Size Publisher
npm/react@18.3.1 environment +2 339 kB react-bot
npm/sanity@3.35.0 network Transitive: environment, eval, filesystem, shell, unsafe +760 607 MB ricokahler
npm/styled-components@6.1.0 environment Transitive: filesystem +16 3.69 MB probablyup

๐Ÿšฎ Removed packages: npm/react@18.2.0), npm/sanity@3.1.4), npm/styled-components@5.3.6)

View full reportโ†—๏ธŽ