saurabharch / rollout

Rollout Server is complete Marketing Automation Tools with Enrich XBOSS (Experience Business Operating Software System)
https://saurabharch.github.io/rollout/
MIT License
3 stars 3 forks source link

[Snyk] Fix for 10 vulnerabilities #401

Closed saurabharch closed 1 year ago

saurabharch commented 1 year ago

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

#### Changes included in this PR - Changes to the following files to upgrade the vulnerable dependencies to a fixed version: - package.json - package-lock.json - Adding or updating a Snyk policy (.snyk) file; this file is required in order to apply Snyk vulnerability patches. [Find out more](https://support.snyk.io/hc/en-us/articles/360003891078-Snyk-patches-to-fix-vulnerabilities). #### Vulnerabilities that will be fixed ##### With an upgrade: Severity | Priority Score (*) | Issue | Breaking Change | Exploit Maturity :-------------------------:|-------------------------|:-------------------------|:-------------------------|:------------------------- ![high severity](https://res.cloudinary.com/snyk/image/upload/w_20,h_20/v1561977819/icon/h.png "high severity") | **686/1000**
**Why?** Proof of Concept exploit, Has a fix available, CVSS 7.3 | Prototype Pollution
[SNYK-JS-FASTJSONPATCH-595663](https://snyk.io/vuln/SNYK-JS-FASTJSONPATCH-595663) | Yes | Proof of Concept ![medium severity](https://res.cloudinary.com/snyk/image/upload/w_20,h_20/v1561977819/icon/m.png "medium severity") | **484/1000**
**Why?** Has a fix available, CVSS 5.4 | Open Redirect
[SNYK-JS-GOT-2932019](https://snyk.io/vuln/SNYK-JS-GOT-2932019) | Yes | No Known Exploit ![medium severity](https://res.cloudinary.com/snyk/image/upload/w_20,h_20/v1561977819/icon/m.png "medium severity") | **454/1000**
**Why?** Has a fix available, CVSS 4.8 | Session Fixation
[SNYK-JS-PASSPORT-2840631](https://snyk.io/vuln/SNYK-JS-PASSPORT-2840631) | Yes | No Known Exploit ![high severity](https://res.cloudinary.com/snyk/image/upload/w_20,h_20/v1561977819/icon/h.png "high severity") | **731/1000**
**Why?** Proof of Concept exploit, Has a fix available, CVSS 8.2 | Prototype Pollution
[SNYK-JS-PROTOBUFJS-2441248](https://snyk.io/vuln/SNYK-JS-PROTOBUFJS-2441248) | Yes | Proof of Concept ![medium severity](https://res.cloudinary.com/snyk/image/upload/w_20,h_20/v1561977819/icon/m.png "medium severity") | **586/1000**
**Why?** Proof of Concept exploit, Has a fix available, CVSS 5.3 | Prototype Pollution
[SNYK-JS-XML2JS-5414874](https://snyk.io/vuln/SNYK-JS-XML2JS-5414874) | No | Proof of Concept ![high severity](https://res.cloudinary.com/snyk/image/upload/w_20,h_20/v1561977819/icon/h.png "high severity") | **579/1000**
**Why?** Has a fix available, CVSS 7.3 | Prototype Pollution
[npm:extend:20180424](https://snyk.io/vuln/npm:extend:20180424) | Yes | No Known Exploit ![high severity](https://res.cloudinary.com/snyk/image/upload/w_20,h_20/v1561977819/icon/h.png "high severity") | **741/1000**
**Why?** Mature exploit, Has a fix available, CVSS 7.1 | Regular Expression Denial of Service (ReDoS)
[npm:protobufjs:20180305](https://snyk.io/vuln/npm:protobufjs:20180305) | Yes | Mature (*) Note that the real score may have changed since the PR was raised.
Commit messages
Package name: is-online The new version differs by 2 commits.
See the full diff
Package name: minio The new version differs by 13 commits.
  • 36a8741 bump release tag to 7.1.0
  • 832ac71 Fixed issue with closing files in fPutObject() function (#1112)
  • 75ed013 Fixed error handling in putObject (#1132)
  • 14474b5 feat: specify custom transport agent parameter (#1104)
  • a2d2c0b fixbatch deletion in removeObjects (#1131)
  • 82b0659 Fix string interpolation of presignedPutObject (#1125)
  • 1941a39 Add AWS Sweden ( eu-north-1 ) region (#1126)
  • 8699e84 Bump xml2js from 0.4.23 to 0.5.0 (#1124)
  • 58a4fb4 Bump json5 from 2.2.1 to 2.2.3 (#1116)
  • 17f6b32 Bump decode-uri-component from 0.2.0 to 0.2.2 (#1117)
  • 5877baa Bump cookiejar from 2.1.3 to 2.1.4 (#1115)
  • abf3f4b docs: `makeBucket` `region` argument is optional (#1103)
  • ac243bb Update version to next release
See the full diff
Package name: passport The new version differs by 100 commits.
See the full diff
Package name: pkgcloud The new version differs by 6 commits.
  • a16c415 [dist] Version bump. 2.0.0
  • 9ac833c Update dependencies (#651)
  • e89f046 [BREAKING] Drop all legacy providers. (#652)
  • 44e08a0 Documentation fixes
  • ce4382f Issue 526 Fixed
  • 916fa68 Correct page title markdown formatting (#646)
See the full diff
##### With a [Snyk patch](https://support.snyk.io/hc/en-us/articles/360003891078-Snyk-patches-to-fix-vulnerabilities#patches): Severity | Priority Score (*) | Issue | Exploit Maturity :-------------------------:|-------------------------|:-------------------------|:------------------------- ![low severity](https://res.cloudinary.com/snyk/image/upload/w_20,h_20/v1561977819/icon/l.png "low severity") | **506/1000**
**Why?** Proof of Concept exploit, Has a fix available, CVSS 3.7 | Regular Expression Denial of Service (ReDoS)
[npm:debug:20170905](https://snyk.io/vuln/npm:debug:20170905) | Proof of Concept ![high severity](https://res.cloudinary.com/snyk/image/upload/w_20,h_20/v1561977819/icon/h.png "high severity") | **589/1000**
**Why?** Has a fix available, CVSS 7.5 | Regular Expression Denial of Service (ReDoS)
[npm:minimatch:20160620](https://snyk.io/vuln/npm:minimatch:20160620) | No Known Exploit ![low severity](https://res.cloudinary.com/snyk/image/upload/w_20,h_20/v1561977819/icon/l.png "low severity") | **399/1000**
**Why?** Has a fix available, CVSS 3.7 | Regular Expression Denial of Service (ReDoS)
[npm:ms:20170412](https://snyk.io/vuln/npm:ms:20170412) | No Known Exploit (*) Note that the real score may have changed since the PR was raised. Check the changes in this PR to ensure they won't cause issues with your project. ------------ **Note:** *You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.* For more information: 🧐 [View latest project report](https://app.snyk.io/org/saurabharch/project/11a87d0d-9dcf-4ad7-9703-76395070728a?utm_source=github&utm_medium=referral&page=fix-pr) 🛠 [Adjust project settings](https://app.snyk.io/org/saurabharch/project/11a87d0d-9dcf-4ad7-9703-76395070728a?utm_source=github&utm_medium=referral&page=fix-pr/settings) 📚 [Read more about Snyk's upgrade and patch logic](https://support.snyk.io/hc/en-us/articles/360003891078-Snyk-patches-to-fix-vulnerabilities) [//]: # (snyk:metadata:{"prId":"b2a59fcd-d96f-4612-8185-273948fd658c","prPublicId":"b2a59fcd-d96f-4612-8185-273948fd658c","dependencies":[{"name":"is-online","from":"9.0.1","to":"10.0.0"},{"name":"minio","from":"7.0.33","to":"7.1.0"},{"name":"passport","from":"0.4.1","to":"0.6.0"},{"name":"passport-twitter","from":"0.1.5","to":"1.0.0"},{"name":"pkgcloud","from":"1.7.0","to":"2.0.0"}],"packageManager":"npm","projectPublicId":"11a87d0d-9dcf-4ad7-9703-76395070728a","projectUrl":"https://app.snyk.io/org/saurabharch/project/11a87d0d-9dcf-4ad7-9703-76395070728a?utm_source=github&utm_medium=referral&page=fix-pr","type":"auto","patch":["npm:debug:20170905","npm:minimatch:20160620","npm:ms:20170412"],"vulns":["SNYK-JS-FASTJSONPATCH-595663","SNYK-JS-GOT-2932019","npm:minimatch:20160620","SNYK-JS-PASSPORT-2840631","SNYK-JS-PROTOBUFJS-2441248","npm:protobufjs:20180305","SNYK-JS-XML2JS-5414874","npm:debug:20170905","npm:extend:20180424","npm:ms:20170412"],"upgrade":["SNYK-JS-FASTJSONPATCH-595663","SNYK-JS-GOT-2932019","SNYK-JS-PASSPORT-2840631","SNYK-JS-PROTOBUFJS-2441248","SNYK-JS-XML2JS-5414874","npm:extend:20180424","npm:protobufjs:20180305"],"isBreakingChange":true,"env":"prod","prType":"fix","templateVariants":["priorityScore"],"priorityScoreList":[686,484,589,454,731,741,586,506,579,399],"remediationStrategy":"vuln"}) --- **Learn how to fix vulnerabilities with free interactive lessons:** 🦉 [Prototype Pollution](https://learn.snyk.io/lessons/prototype-pollution/javascript/?loc=fix-pr) 🦉 [Open Redirect](https://learn.snyk.io/lessons/open-redirect/javascript/?loc=fix-pr) 🦉 [Regular Expression Denial of Service (ReDoS)](https://learn.snyk.io/lessons/redos/javascript/?loc=fix-pr)
vercel[bot] commented 1 year ago

The latest updates on your projects. Learn more about Vercel for Git ↗︎

Name Status Preview Comments Updated (UTC)
rollout ❌ Failed (Inspect) Jun 28, 2023 10:51pm
github-actions[bot] commented 1 year ago

Stale pull request message