Skip to content

Fix/security vulnerabilities#219

Open
Robert-Bosse wants to merge 6 commits intopluginpal:masterfrom
spring-media:fix/security-vulnerabilities
Open

Fix/security vulnerabilities#219
Robert-Bosse wants to merge 6 commits intopluginpal:masterfrom
spring-media:fix/security-vulnerabilities

Conversation

@Robert-Bosse
Copy link

No description provided.

Luca-Esposito and others added 6 commits September 21, 2023 09:31
- Upgrade lodash from ^4.17.21 to ^4.17.23 (Prototype Pollution - Medium)
- Add yarn resolutions to pin transitive dependencies:
  - minimatch@3.1.3 (ReDoS + Inefficient Algorithmic Complexity - High)
  - brace-expansion@1.1.12 (ReDoS - Low)
  - @babel/runtime@~7.26.10 (ReDoS - Medium)
  - lodash-es@4.17.23 (Prototype Pollution - Medium)
  - lodash@4.17.23 (Prototype Pollution - Medium)

Remaining: inflight@1.0.6 (Medium) - no fix available (unmaintained package)

All updates are patch/minor version bumps within compatible semver ranges.
No breaking changes introduced.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants