Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Snyk] Fix for 1 vulnerabilities #158

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

fix: package.json & package-lock.json to reduce vulnerabilities

aea6ceb
Select commit
Loading
Failed to load commit list.
Open

[Snyk] Fix for 1 vulnerabilities #158

fix: package.json & package-lock.json to reduce vulnerabilities
aea6ceb
Select commit
Loading
Failed to load commit list.
Mend Bolt for GitHub / WhiteSource Security Check failed May 27, 2024 in 8m 4s

Security Report

You have successfully remediated 22 vulnerabilities, but introduced 11 new vulnerabilities in this branch.

❌ New vulnerabilities:

CVE Severity CVSS Score Vulnerable Library Suggested Fix Issue
CVE-2020-36327

Path to vulnerable library: /vendor/bundle/ruby/3.2.0/cache/bundler-2.0.1.gem

Dependency Hierarchy:

-> ❌ bundler-2.0.1.gem (Vulnerable Library)

High 8.8 bundler-2.0.1.gem Upgrade to version: bundler - 2.2.10 None
CVE-2019-3881

Path to vulnerable library: /vendor/bundle/ruby/3.2.0/cache/bundler-2.0.1.gem

Dependency Hierarchy:

-> ❌ bundler-2.0.1.gem (Vulnerable Library)

High 7.8 bundler-2.0.1.gem Upgrade to version: v2.1.0.pre.3 None
CVE-2024-4068

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> browser-sync-2.26.4.tgz (Root Library)

   -> chokidar-2.1.2.tgz

     -> ❌ braces-2.3.2.tgz (Vulnerable Library)

High 7.5 braces-2.3.2.tgz Upgrade to version: braces - 3.0.3 None
CVE-2022-24772

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> language-3.0.0.tgz (Root Library)

   -> google-gax-1.15.4.tgz

     -> google-auth-library-5.10.1.tgz

       -> gtoken-4.1.4.tgz

         -> google-p12-pem-2.0.5.tgz

           -> ❌ node-forge-0.10.0.tgz (Vulnerable Library)

High 7.5 node-forge-0.10.0.tgz Upgrade to version: node-forge - 1.3.0 #115
CVE-2022-24771

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> language-3.0.0.tgz (Root Library)

   -> google-gax-1.15.4.tgz

     -> google-auth-library-5.10.1.tgz

       -> gtoken-4.1.4.tgz

         -> google-p12-pem-2.0.5.tgz

           -> ❌ node-forge-0.10.0.tgz (Vulnerable Library)

High 7.5 node-forge-0.10.0.tgz Upgrade to version: node-forge - 1.3.0 #116
CVE-2021-43809

Path to vulnerable library: /vendor/bundle/ruby/3.2.0/cache/bundler-2.0.1.gem

Dependency Hierarchy:

-> ❌ bundler-2.0.1.gem (Vulnerable Library)

High 7.3 bundler-2.0.1.gem Upgrade to version: bundler - 2.2.33 None
WS-2022-0008

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> language-3.0.0.tgz (Root Library)

   -> google-gax-1.15.4.tgz

     -> google-auth-library-5.10.1.tgz

       -> gtoken-4.1.4.tgz

         -> google-p12-pem-2.0.5.tgz

           -> ❌ node-forge-0.10.0.tgz (Vulnerable Library)

Medium 6.6 node-forge-0.10.0.tgz Upgrade to version: node-forge - 1.0.0 #101
CVE-2024-29041

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> screenshot-util-1.1.13.tgz (Root Library)

   -> ❌ express-4.16.4.tgz (Vulnerable Library)

Medium 6.1 express-4.16.4.tgz Upgrade to version: express - 4.19.0 None
CVE-2022-0122

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> language-3.0.0.tgz (Root Library)

   -> google-gax-1.15.4.tgz

     -> google-auth-library-5.10.1.tgz

       -> gtoken-4.1.4.tgz

         -> google-p12-pem-2.0.5.tgz

           -> ❌ node-forge-0.10.0.tgz (Vulnerable Library)

Medium 6.1 node-forge-0.10.0.tgz Upgrade to version: node-forge - 1.0.0 #99
CVE-2024-4067

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> browser-sync-2.26.4.tgz (Root Library)

   -> chokidar-2.1.2.tgz

     -> anymatch-2.0.0.tgz

       -> ❌ micromatch-3.1.10.tgz (Vulnerable Library)

Medium 5.3 micromatch-3.1.10.tgz Upgrade to version: micromatch - 4.0.6 None
CVE-2022-24773

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> language-3.0.0.tgz (Root Library)

   -> google-gax-1.15.4.tgz

     -> google-auth-library-5.10.1.tgz

       -> gtoken-4.1.4.tgz

         -> google-p12-pem-2.0.5.tgz

           -> ❌ node-forge-0.10.0.tgz (Vulnerable Library)

Medium 5.3 node-forge-0.10.0.tgz Upgrade to version: node-forge - 1.3.0 #114

✔️ Remediated vulnerabilities:

CVE Vulnerable Library
CVE-2023-33953 grpc-v1.19.0
WS-2020-0368 node-v7.6.0
CVE-2018-17567 jekyll-v3.7.1
CVE-2020-15168 node-fetch-2.3.0.tgz
CVE-2023-45853 node-v7.6.0
CVE-2021-23343 path-parse-1.0.6.tgz
CVE-2022-25878 protobufjs-6.8.8.tgz
CVE-2021-32740 addressable-addressable-2.6.0
CVE-2020-1971 ring-fips-20180730
CVE-2022-0235 node-fetch-2.3.0.tgz
CVE-2020-7768 grpc-1.19.0.tgz
CVE-2023-32732 grpc-v1.19.0
CVE-2020-7608 yargs-parser-5.0.0.tgz
CVE-2024-27088 es5-ext-0.10.49.tgz
CVE-2018-7159 io.js
CVE-2018-25032 node-v7.6.0
CVE-2022-37434 node-v7.6.0
CVE-2023-32731 grpc-v1.19.0
CVE-2020-28503 copy-props-2.0.4.tgz
CVE-2020-14001 kramdown-REL_1_17_0
CVE-2020-7768 grpc-js-0.3.6.tgz
CVE-2022-25878 protobufjs-5.0.3.tgz

Base branch total remaining vulnerabilities: 114
Base branch commit: null


Total libraries scanned: 772

Scan token: d766776b3f464b919986e84a11117423