-
-
Notifications
You must be signed in to change notification settings - Fork 247
70 done #41
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
70 done #41
Conversation
|
Review the following changes in direct dependencies. Learn more about Socket for GitHub.
|
|
Warning Review the following alerts detected in dependencies. According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.
|
|
Ok, I will check it out
…On Mon, Aug 11, 2025, 1:57 PM socket-security[bot] ***@***.***> wrote:
*socket-security[bot]* left a comment
(freeCodeCamp/learn-bash-scripting-by-building-five-programs#41)
<#41 (comment)>
Warning
*Review the following alerts detected in dependencies.*
According to your organization's Security Policy, it is recommended to
resolve "Warn" alerts. Learn more about Socket for GitHub
<https://socket.dev?utm_medium=gh>.
Action Severity Alert (click "▶" to expand/collapse)
Warn [image: Critical]
<https://socket.dev/dashboard/org/freeCodeCamp/diff-scan/08dbc24f-15b1-4167-9af8-b1deb2537479?tab=alerts&alert_item_key=QNbJv0ZmReC6OgJZAKLYK0le7hZy7h5TLrgckR_KJRcM>
***@***.*** has a Critical CVE.
*CVE:* GHSA-2j2x-2gpw-g8fm flat vulnerable to Prototype Pollution
(CRITICAL) <https://github.com/advisories/GHSA-2j2x-2gpw-g8fm>
*Affected versions:* < 5.0.1
*Patched version:* 5.0.1
*From:* .freeCodeCamp/package-lock.json
<https://github.com/freeCodeCamp/learn-bash-scripting-by-building-five-programs/pull/41/files#diff-d6f9fdbac25c7a148b634754100d6de2b6fcbbfc9cb7ed1ca5a7d5c01545a7e6>
→ ***@***.*** → ***@***.***
ℹ Read more on: This package
<https://socket.dev/npm/package/flat/overview/4.1.0> | This alert
<https://socket.dev/dashboard/org/freeCodeCamp/diff-scan/08dbc24f-15b1-4167-9af8-b1deb2537479?tab=alerts&alert_item_key=QNbJv0ZmReC6OgJZAKLYK0le7hZy7h5TLrgckR_KJRcM>
| What is a critical CVE? <https://socket.dev/alerts/criticalCVE>
*Next steps:* Take a moment to review the security alert above. Review
the linked package source code to understand the potential risk. Ensure the
package is not malicious before proceeding. If you're unsure how to
proceed, reach out to your security team or ask the Socket team for help at
***@***.***
*Suggestion:* Remove or replace dependencies that include known critical
CVEs. Consumers can use dependency overrides or npm audit fix --force to
remove vulnerable dependencies.
*Mark the package as acceptable risk*. To ignore this alert only in this
pull request, reply with the comment @SocketSecurity ignore ***@***.***
You can also ignore all packages with @SocketSecurity ignore-all. To
ignore an alert for all future pull requests, use Socket's Dashboard to
change the triage state of this alert
<https://socket.dev/dashboard/org/freeCodeCamp/diff-scan/08dbc24f-15b1-4167-9af8-b1deb2537479?tab=alerts&alert_item_key=QNbJv0ZmReC6OgJZAKLYK0le7hZy7h5TLrgckR_KJRcM>.
Warn [image: Critical]
<https://socket.dev/dashboard/org/freeCodeCamp/diff-scan/08dbc24f-15b1-4167-9af8-b1deb2537479?tab=alerts&alert_item_key=QLBAz5Orw5aPBalz5EW8NrxDFn0R_Xyk5Pz9yTNYMiYI>
***@***.*** has a Critical CVE.
*CVE:* GHSA-xvch-5gv4-984h Prototype Pollution in minimist (CRITICAL)
<https://github.com/advisories/GHSA-xvch-5gv4-984h>
*Affected versions:* >= 1.0.0 < 1.2.6; < 0.2.4
*Patched version:* 1.2.6
*From:* .freeCodeCamp/package-lock.json
<https://github.com/freeCodeCamp/learn-bash-scripting-by-building-five-programs/pull/41/files#diff-d6f9fdbac25c7a148b634754100d6de2b6fcbbfc9cb7ed1ca5a7d5c01545a7e6>
→ ***@***.*** → ***@***.***
ℹ Read more on: This package
<https://socket.dev/npm/package/minimist/overview/1.2.5> | This alert
<https://socket.dev/dashboard/org/freeCodeCamp/diff-scan/08dbc24f-15b1-4167-9af8-b1deb2537479?tab=alerts&alert_item_key=QLBAz5Orw5aPBalz5EW8NrxDFn0R_Xyk5Pz9yTNYMiYI>
| What is a critical CVE? <https://socket.dev/alerts/criticalCVE>
*Next steps:* Take a moment to review the security alert above. Review
the linked package source code to understand the potential risk. Ensure the
package is not malicious before proceeding. If you're unsure how to
proceed, reach out to your security team or ask the Socket team for help at
***@***.***
*Suggestion:* Remove or replace dependencies that include known critical
CVEs. Consumers can use dependency overrides or npm audit fix --force to
remove vulnerable dependencies.
*Mark the package as acceptable risk*. To ignore this alert only in this
pull request, reply with the comment @SocketSecurity ignore
***@***.*** You can also ignore all packages with @SocketSecurity
ignore-all. To ignore an alert for all future pull requests, use Socket's
Dashboard to change the triage state of this alert
<https://socket.dev/dashboard/org/freeCodeCamp/diff-scan/08dbc24f-15b1-4167-9af8-b1deb2537479?tab=alerts&alert_item_key=QLBAz5Orw5aPBalz5EW8NrxDFn0R_Xyk5Pz9yTNYMiYI>.
Warn [image: Critical]
<https://socket.dev/dashboard/org/freeCodeCamp/diff-scan/08dbc24f-15b1-4167-9af8-b1deb2537479?tab=alerts&alert_item_key=QuMYG1pO6NF45ScaoBrqK_Ea7KfR-JZ5K8nACmndfQLE>
***@***.*** has a Critical CVE.
*CVE:* GHSA-g4rg-993r-mgx7 Improper Neutralization of Special Elements
used in a Command in Shell-quote (CRITICAL)
<https://github.com/advisories/GHSA-g4rg-993r-mgx7>
*Affected versions:* < 1.7.3
*Patched version:* 1.7.3
*From:* .freeCodeCamp/package-lock.json
<https://github.com/freeCodeCamp/learn-bash-scripting-by-building-five-programs/pull/41/files#diff-d6f9fdbac25c7a148b634754100d6de2b6fcbbfc9cb7ed1ca5a7d5c01545a7e6>
→ ***@***.***
ℹ Read more on: This package
<https://socket.dev/npm/package/shell-quote/overview/1.7.2> | This alert
<https://socket.dev/dashboard/org/freeCodeCamp/diff-scan/08dbc24f-15b1-4167-9af8-b1deb2537479?tab=alerts&alert_item_key=QuMYG1pO6NF45ScaoBrqK_Ea7KfR-JZ5K8nACmndfQLE>
| What is a critical CVE? <https://socket.dev/alerts/criticalCVE>
*Next steps:* Take a moment to review the security alert above. Review
the linked package source code to understand the potential risk. Ensure the
package is not malicious before proceeding. If you're unsure how to
proceed, reach out to your security team or ask the Socket team for help at
***@***.***
*Suggestion:* Remove or replace dependencies that include known critical
CVEs. Consumers can use dependency overrides or npm audit fix --force to
remove vulnerable dependencies.
*Mark the package as acceptable risk*. To ignore this alert only in this
pull request, reply with the comment @SocketSecurity ignore
***@***.*** You can also ignore all packages with @SocketSecurity
ignore-all. To ignore an alert for all future pull requests, use Socket's
Dashboard to change the triage state of this alert
<https://socket.dev/dashboard/org/freeCodeCamp/diff-scan/08dbc24f-15b1-4167-9af8-b1deb2537479?tab=alerts&alert_item_key=QuMYG1pO6NF45ScaoBrqK_Ea7KfR-JZ5K8nACmndfQLE>.
View full report
<https://socket.dev/dashboard/org/freeCodeCamp/diff-scan/08dbc24f-15b1-4167-9af8-b1deb2537479?tab=alerts&action=error%2Cwarn>
—
Reply to this email directly, view it on GitHub
<#41 (comment)>,
or unsubscribe
<https://github.com/notifications/unsubscribe-auth/A4MJH2HAH3NYG25DH2MNULT3NBEHBAVCNFSM6AAAAACDSSHJO6VHI2DSMVQWIX3LMV43OSLTON2WKQ3PNVWWK3TUHMZTCNZTGY2DQNJZGE>
.
You are receiving this because you authored the thread.Message ID:
<freeCodeCamp/learn-bash-scripting-by-building-five-programs/pull/41/c3173648591
@github.com>
|
|
Looks like this PR was supposed to be made on your own fork, instead of the original boilerplate repository. This is a standard message notifying you that we've reviewed your pull request and have decided not to merge it. We would welcome future pull requests from you. Thank you and happy coding. |
|
okay. Thank you
…On Tue, Aug 12, 2025, 10:24 AM Krzysztof G. ***@***.***> wrote:
*gikf* left a comment
(freeCodeCamp/learn-bash-scripting-by-building-five-programs#41)
<#41 (comment)>
Hey @Mofazzal-Hossain-Evan <https://github.com/Mofazzal-Hossain-Evan>
Looks like this PR was supposed to be made on your own fork, instead of
the original boilerplate repository.
This is a standard message notifying you that we've reviewed your pull
request and have decided not to merge it. We would welcome future pull
requests from you.
Thank you and happy coding.
—
Reply to this email directly, view it on GitHub
<#41 (comment)>,
or unsubscribe
<https://github.com/notifications/unsubscribe-auth/A4MJH2HC6XJNYJXWEFVJPST3NFT7NAVCNFSM6AAAAACDSSHJO6VHI2DSMVQWIX3LMV43OSLTON2WKQ3PNVWWK3TUHMZTCNZXGY2DQNBRGA>
.
You are receiving this because you were mentioned.Message ID:
<freeCodeCamp/learn-bash-scripting-by-building-five-programs/pull/41/c3177648410
@github.com>
|
Checklist:
Update index.md)Closes #XXXXX