Skip to content

Conversation

@adamlaska
Copy link
Owner

snyk-top-banner

Snyk has created this PR to fix 1 vulnerabilities in the npm dependencies of this project.

Snyk changed the following file(s):

  • package.json
⚠️ Warning
Failed to update the package-lock.json, please update manually before merging.

Vulnerabilities that will be fixed with an upgrade:

Issue Score
high severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-CROSSSPAWN-8303230
  828  

Important

  • Check the changes in this PR to ensure they won't cause issues with your project.
  • Max score is 1000. Note that the real score may have changed since the PR was raised.
  • This PR was automatically created by Snyk using the credentials of a real user.

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report
📜 Customise PR templates
🛠 Adjust project settings
📚 Read about Snyk's upgrade logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Regular Expression Denial of Service (ReDoS)

The following vulnerabilities are fixed with an upgrade:
- https://snyk.io/vuln/SNYK-JS-CROSSSPAWN-8303230
@google-cla
Copy link

google-cla bot commented Nov 13, 2024

Thanks for your pull request! It looks like this may be your first contribution to a Google open source project. Before we can look at your pull request, you'll need to sign a Contributor License Agreement (CLA).

View this failed invocation of the CLA check for more information.

For the most up to date status, view the checks section at the bottom of the pull request.

@socket-security
Copy link

New and removed dependencies detected. Learn more about Socket for GitHub ↗︎

Package New capabilities Transitives Size Publisher
npm/ajv@5.5.2 eval 0 2.09 MB esp
npm/async@1.0.0 None 0 99.4 kB aearly
npm/bluebird@3.5.2 environment, eval 0 620 kB esailija
npm/co@4.6.0 None 0 16 kB jongleberry
npm/colors@1.0.3 None 0 109 kB marak
npm/combined-stream@1.0.7 None 0 11.1 kB alexindigo
npm/cycle@1.0.3 None 0 8.1 kB dscape
npm/debug@3.2.5 environment 0 79.5 kB qix
npm/es6-promise@4.2.5 None 0 318 kB stefanpenner
npm/eyes@0.1.8 None 0 14 kB indexzero
npm/fast-deep-equal@1.1.0 None 0 5.25 kB esp
npm/form-data@2.3.2 filesystem, network +1 41.2 kB alexindigo
npm/har-validator@5.1.0 None 0 8.28 kB ahmadnassri
npm/https-proxy-agent@2.2.1 network 0 27.6 kB tootallnate
npm/json-schema-traverse@0.3.1 None 0 16.8 kB esp
npm/lodash@4.17.14 None 0 1.4 MB jdalton
npm/mime-db@1.36.0 None 0 184 kB dougwilson
npm/mime-types@2.1.20 None 0 14.9 kB dougwilson
npm/node-github-graphql@0.2.7 environment, network 0 7.71 kB wilsonchingg
npm/psl@1.1.29 None 0 550 kB lupomontero
npm/sshpk@1.14.2 None 0 209 kB arekinath
npm/stack-trace@0.0.10 None 0 8.85 kB felixge
npm/tunnel-agent@0.6.0 environment, network 0 16.7 kB mikeal
npm/tweetnacl@0.14.5 None 0 174 kB dchest
npm/type-check@0.3.2 None 0 20.9 kB gkz
npm/type-detect@4.0.8 None 0 42.1 kB chaijs
npm/type-fest@0.3.1 None 0 23 kB sindresorhus
npm/typedarray@0.0.6 None 0 26 kB substack
npm/uglify-js@3.3.28 eval, filesystem 0 684 kB alexlamsl
npm/uglify-js@3.6.5 eval, filesystem 0 757 kB alexlamsl
npm/unherit@1.1.2 None 0 5.43 kB wooorm
npm/unified-args@7.1.0 None 0 34.9 kB wooorm
npm/unified-engine@7.0.0 filesystem, unsafe 0 54.7 kB wooorm
npm/unified-lint-rule@1.0.4 None 0 5.65 kB wooorm
npm/unified-message-control@1.0.4 None 0 15.1 kB wooorm
npm/unified@7.1.0 None 0 55 kB wooorm
npm/union-value@1.0.1 None 0 6.83 kB doowb
npm/uniq@1.0.1 None 0 4.32 kB mikolalysenko
npm/unique-string@1.0.0 None 0 2.58 kB sindresorhus
npm/unist-util-find-all-after@1.0.4 None 0 12.5 kB wooorm
npm/unist-util-generated@1.1.4 None 0 6.28 kB wooorm
npm/unist-util-inspect@4.1.4 None 0 9.85 kB wooorm
npm/unist-util-is@3.0.0 None 0 11.1 kB wooorm
npm/unist-util-position@3.0.3 None 0 6.26 kB wooorm
npm/unist-util-remove-position@1.1.3 None 0 6.55 kB wooorm
npm/unist-util-stringify-position@1.1.2 None 0 6.55 kB wooorm
npm/unist-util-visit-parents@2.1.2 None 0 11.6 kB wooorm
npm/unist-util-visit@1.4.1 None 0 6.87 kB wooorm
npm/unpipe@1.0.0 None 0 4.31 kB dougwilson
npm/unset-value@1.0.0 None +2 20.7 kB jonschlinkert
npm/untildify@2.1.0 None 0 2.71 kB sindresorhus
npm/unyield@0.0.1 None 0 2.62 kB mattmueller
npm/update-notifier@3.0.1 environment, shell 0 14.7 kB sboudrias
npm/uri-js@4.2.2 None 0 533 kB garycourt
npm/urix@0.1.0 None 0 4.37 kB lydell
npm/url-parse-lax@3.0.0 None 0 4.23 kB sindresorhus
npm/use@3.1.1 None 0 9.51 kB jonschlinkert
npm/util-deprecate@1.0.2 None 0 5.48 kB tootallnate
npm/uuid@3.3.2 None 0 43.6 kB broofa
npm/uuid@3.3.3 None 0 34.7 kB broofa
npm/v8-compile-cache@2.1.0 environment, filesystem, unsafe 0 16.2 kB zertosh
npm/validate-npm-package-license@3.0.4 None 0 16.6 kB kemitchell
npm/verror@1.10.0 None 0 35.8 kB dap
npm/vfile-location@2.0.5 None 0 7.54 kB wooorm
npm/vfile-message@1.1.1 None 0 9.03 kB wooorm
npm/vfile-reporter@6.0.0 None 0 14.8 kB wooorm
npm/vfile-sort@2.2.1 None 0 5.93 kB wooorm
npm/vfile-statistics@1.1.3 None 0 6.76 kB wooorm
npm/vfile@3.0.1 unsafe +1 23.6 kB wooorm
npm/vnu-jar@19.9.4 None 0 28.9 MB sideshowbarker
npm/ware@1.3.0 None 0 6.17 kB ianstormtaylor
npm/which-module@1.0.0 None 0 4.16 kB nexdrew
npm/which@1.3.1 environment 0 9.42 kB isaacs
npm/wide-align@1.1.3 None 0 4.55 kB iarna
npm/widest-line@2.0.1 None 0 3.16 kB sindresorhus
npm/win-fork@1.1.1 environment, filesystem, shell 0 4.73 kB forbeslindesay
npm/winston@2.4.4 filesystem 0 190 kB indexzero
npm/wordwrap@0.0.3 None 0 37 kB substack
npm/wrap-ansi@2.1.0 None 0 7.79 kB sindresorhus
npm/wrap-fn@0.1.5 None 0 5.27 kB mattmueller
npm/wrapped@1.0.1 None 0 5.03 kB mattmueller
npm/wrappy@1.0.2 None 0 2.96 kB zkat
npm/write-file-atomic@2.4.3 None 0 12.2 kB isaacs
npm/write@1.0.3 filesystem 0 14.7 kB jonschlinkert
npm/x-is-string@0.1.0 None 0 4.67 kB mattesch
npm/xdg-basedir@3.0.0 environment 0 4.08 kB sindresorhus
npm/xml@1.0.1 None 0 23.4 kB dylang
npm/xtend@4.0.2 None 0 6.46 kB raynos
npm/y18n@3.2.1 filesystem 0 8.75 kB bcoe
npm/yallist@2.1.2 None 0 13.6 kB isaacs
npm/yaml-js@0.0.8 filesystem 0 498 kB connec
npm/yargs-parser@10.1.0 environment 0 48.4 kB bcoe
npm/yargs@13.3.0 environment, filesystem 0 228 kB bcoe

View full report↗︎

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants