wikimedia / banana-i18n

banana-i18n - Javascript Internationalization library
https://wikimedia.github.io/banana-i18n/
MIT License
80 stars 27 forks source link

Update npm dependencies to fix security issues #67

Closed Abijeet closed 2 years ago

Abijeet commented 2 years ago

Security issue with mocha still needs to be addressed. It requires updating to mocha 9.2.2 or 10.0.0

Report follows below:

ansi-regex 3.0.0 Severity: high Inefficient Regular Expression Complexity in chalk/ansi-regex - https://github.com/advisories/GHSA-93q8-gq69-wqmw fix available via npm audit fix node_modules/wide-align/node_modules/ansi-regex

follow-redirects <1.14.8 Severity: moderate Exposure of Sensitive Information to an Unauthorized Actor in follow-redirects - https://github.com/advisories/GHSA-pw2r-vq6v-hr8c fix available via npm audit fix node_modules/follow-redirects

minimist <1.2.6 Severity: critical Prototype Pollution in minimist - https://github.com/advisories/GHSA-xvch-5gv4-984h fix available via npm audit fix node_modules/minimist

nanoid 3.0.0 - 3.1.30 Severity: moderate Exposure of Sensitive Information to an Unauthorized Actor in nanoid - https://github.com/advisories/GHSA-qrpm-p2h7-hrv2 fix available via npm audit fix --force Will install mocha@10.0.0, which is a breaking change node_modules/nanoid mocha 8.2.0 - 9.1.4 Depends on vulnerable versions of nanoid node_modules/mocha

5 vulnerabilities (3 moderate, 1 high, 1 critical)