Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Snyk] Fix for 1 vulnerabilities #58

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

sheshbabu
Copy link
Owner

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • package.json
    • package-lock.json

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
high severity 696/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
Regular Expression Denial of Service (ReDoS)
SNYK-JS-ANSIREGEX-1583908
Yes Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: lighthouse The new version differs by 248 commits.
  • 96eda60 v7.0.0 (#11839)
  • 2e3cd5c core(full-page-screenshot): handle ShadowRoots (#11852)
  • 966a206 report: fix element screenshot position, lifecycle, styles
  • 91092fc core(network): do not consider cross frame requests critical (#11851)
  • 7978f63 core(config): special case full-page-screenshot audit in filtering (#11829)
  • 9dbb0a5 tests(smoke): restore dbw_tester exception assertions (#11836)
  • a6738e0 core(emulation): refactor emulation settings & CLI flags (#11779)
  • ea5afa4 core(config): only allow lighthouse:default extension (#11835)
  • a30953c core(a11y): upgrade axe-core to 4.1.1, update a11y audits (#11661)
  • 6e0158d core(script-treemap-data): fix sourceRoot & missing coverage bugs (#11825)
  • ced75b5 misc: add log files to GCP run results (#11833)
  • f4904da core(uses-http2): remove mention of push (#11834)
  • ad97b21 tests: use font-size for non-composited animations in smoke tests (#11808)
  • 852e79a core(pwa): remove works-offline and offline-start-url audits (#11806)
  • 3d90a59 core(installable-manifest): use devtools InstallabilityErrors (#11745)
  • c6d1398 report(pwa): move service-worker to the pwa-optimized group (#11798)
  • 0f418a8 deps: update yargs to latest (#11794)
  • a589db5 deps: update old transitive deps (#11811)
  • 5fc0fce core(artifacts): merge ConsoleMessages and RuntimeExceptions artifacts (#11663)
  • 70106be core: support local plugins from global Lighthouse (#11696)
  • 5b4b47c misc: temporarily allow css in redirectPass (#11813)
  • 7915708 core(lantern): allow non-XHRs to depend on CPU Nodes (#11767)
  • 2aa9845 core(without-javascript): remove audit (#11711)
  • 6ad47fa tests: fix CI condition in download-devtools.sh (#11809 followup)

See the full diff

Package name: snyk The new version differs by 250 commits.
  • 3f52bdc Merge pull request #1669 from snyk/fix/dont-fail-on-request-big-payload
  • 47e106e fix: don't fail on request's big payload
  • 1228b55 Merge pull request #1624 from snyk/chore/cli-alert-improvement
  • fccd907 Merge pull request #1666 from snyk/chore/bump-cpp-test-timeout
  • 6772a3e Merge pull request #1649 from snyk/chore/deps-update
  • 89a7767 chore: update dependencies
  • eaf4915 test: wrap pagerduty await in try-catch, remove condition
  • 0576431 test: add pagerduty, check if test is running before attemmpting rerun
  • a08a938 chore: bump flaky cpp test timeout
  • ebb8dd7 Merge pull request #1656 from snyk/feat/protect-prime-time
  • 69cd590 test: fix flakey json output test
  • 3021bb2 Merge pull request #1663 from snyk/fix/upgrade-snyk-gradle-plugin
  • a988600 Merge pull request #1654 from snyk/feat/iac-experimental-terraform-support
  • b455497 feat: iac experimental tf support
  • 4848b7e chore: run tests in packages in CI
  • 3e7e99e feat: implement snyk protect
  • bb233f1 chore: enable prettier formatting in packages
  • fe0183d test: enable jest testing in snyk-protect workspace
  • 40ec817 test: test fixture for snyk protect
  • 7dfd3ea Merge pull request #1661 from snyk/test/fix-flake-with-dev-count-analysis
  • 02c99b8 test: remove tests previously migrated to jest
  • e203fd1 test: set timeout in beforeAll
  • d42f6d9 fix: update snyk-gradle-plugin to 3.13.2
  • 8cd9fbf Merge pull request #1662 from snyk/test/add-longer-timeouts

See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Learn about vulnerability in an interactive lesson of Snyk Learn.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants