Skip to content

chore: bump security related js vendor dependencies#40911

Merged
JammingBen merged 1 commit into
masterfrom
bump-dependencies-sec
Aug 8, 2023
Merged

chore: bump security related js vendor dependencies#40911
JammingBen merged 1 commit into
masterfrom
bump-dependencies-sec

Conversation

@fschade
Copy link
Copy Markdown
Contributor

@fschade fschade commented Aug 8, 2023

Description

Bump security related vendor js dependencies, some dependencies still do not have fixed the peer dependency.

Overview

https://github.com/owncloud/core/security/dependabot

Details

Insufficient validation when decoding a Socket.IO packet

https://github.com/owncloud/core/security/dependabot/34, no upstream solution available, bumped via yarn resolutions

TaffyDB can allow access to any data items in the DB

https://github.com/owncloud/core/security/dependabot/30, no upstream fix available, used to build the docs, not runtime related.

qs vulnerable to Prototype Pollution

https://github.com/owncloud/core/security/dependabot/27, no upstream solution available, bumped via yarn resolutions

@update-docs
Copy link
Copy Markdown

update-docs Bot commented Aug 8, 2023

Thanks for opening this pull request! The maintainers of this repository would appreciate it if you would create a changelog item based on your changes.

@sonarqubecloud
Copy link
Copy Markdown

sonarqubecloud Bot commented Aug 8, 2023

Kudos, SonarCloud Quality Gate passed!    Quality Gate passed

Bug A 0 Bugs
Vulnerability A 0 Vulnerabilities
Security Hotspot A 0 Security Hotspots
Code Smell A 0 Code Smells

No Coverage information No Coverage information
No Duplication information No Duplication information

@JammingBen JammingBen merged commit d8a088c into master Aug 8, 2023
@delete-merged-branch delete-merged-branch Bot deleted the bump-dependencies-sec branch August 8, 2023 09:13
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants