Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update package.json #2019

Open
wants to merge 1 commit into
base: dev-master
Choose a base branch
from

Conversation

edk1kamel
Copy link

Please upgrade dependency to help address the following:

Run npm install [email protected] to resolve 3 vulnerabilities

Moderate Remote Memory Exposure
Package request
Dependency of request
Path request
More info https://npmjs.com/advisories/309

Moderate Regular Expression Denial of Service
Package mime
Dependency of request
Path request > form-data > mime
More info https://npmjs.com/advisories/535

Moderate Memory Exposure
Package tunnel-agent
Dependency of request
Path request > tunnel-agent
More info https://npmjs.com/advisories/598

                             Manual Review
         Some vulnerabilities require your attention to resolve
      Visit https://go.npm.me/audit-guide for additional guidance

Moderate Regular Expression Denial of Service
Package hawk
Patched in >=3.1.3 < 4.0.0 || >=4.1.1
Dependency of request
Path request > hawk
More info https://npmjs.com/advisories/77

Moderate Prototype Pollution
Package hoek
Patched in > 4.2.0 < 5.0.0 || >= 5.0.3
Dependency of request
Path request > hawk > boom > hoek
More info https://npmjs.com/advisories/566

Moderate Prototype Pollution
Package hoek
Patched in > 4.2.0 < 5.0.0 || >= 5.0.3
Dependency of request
Path request > hawk > cryptiles > boom > hoek
More info https://npmjs.com/advisories/566

Moderate Prototype Pollution
Package hoek
Patched in > 4.2.0 < 5.0.0 || >= 5.0.3
Dependency of request
Path request > hawk > hoek
More info https://npmjs.com/advisories/566

Moderate Prototype Pollution
Package hoek
Patched in > 4.2.0 < 5.0.0 || >= 5.0.3
Dependency of request
Path request > hawk > sntp > hoek
More info https://npmjs.com/advisories/566

found 8 moderate severity vulnerabilities in 32 scanned packages:1

Please upgrade dependency to help address the following: 

# Run  npm install [email protected]  to resolve 3 vulnerabilities
  Moderate        Remote Memory Exposure
  Package         request
  Dependency of   request
  Path            request
  More info       https://npmjs.com/advisories/309

  Moderate        Regular Expression Denial of Service
  Package         mime
  Dependency of   request
  Path            request > form-data > mime
  More info       https://npmjs.com/advisories/535

  Moderate        Memory Exposure
  Package         tunnel-agent
  Dependency of   request
  Path            request > tunnel-agent
  More info       https://npmjs.com/advisories/598


                                 Manual Review
             Some vulnerabilities require your attention to resolve
          Visit https://go.npm.me/audit-guide for additional guidance

  Moderate        Regular Expression Denial of Service
  Package         hawk
  Patched in      >=3.1.3 < 4.0.0 || >=4.1.1
  Dependency of   request
  Path            request > hawk
  More info       https://npmjs.com/advisories/77

  Moderate        Prototype Pollution
  Package         hoek
  Patched in      > 4.2.0 < 5.0.0 || >= 5.0.3
  Dependency of   request
  Path            request > hawk > boom > hoek
  More info       https://npmjs.com/advisories/566

  Moderate        Prototype Pollution
  Package         hoek
  Patched in      > 4.2.0 < 5.0.0 || >= 5.0.3
  Dependency of   request
  Path            request > hawk > cryptiles > boom > hoek
  More info       https://npmjs.com/advisories/566

  Moderate        Prototype Pollution
  Package         hoek
  Patched in      > 4.2.0 < 5.0.0 || >= 5.0.3
  Dependency of   request
  Path            request > hawk > hoek
  More info       https://npmjs.com/advisories/566

  Moderate        Prototype Pollution
  Package         hoek
  Patched in      > 4.2.0 < 5.0.0 || >= 5.0.3
  Dependency of   request
  Path            request > hawk > sntp > hoek
  More info       https://npmjs.com/advisories/566

found 8 moderate severity vulnerabilities in 32 scanned packages:1
@yahoocla
Copy link

Thank you for submitting this pull request, however I do not see a valid CLA on file for you. Before we can merge this request please visit https://yahoocla.herokuapp.com/ and agree to the terms. Thanks! 😄

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants