Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Snyk] Security upgrade gatsby-remark-relative-images from 2.0.2 to 2.0.4 #1282

Merged

Conversation

snyk-bot
Copy link
Contributor

@snyk-bot snyk-bot commented May 9, 2023

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • package.json
    • package-lock.json

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
medium severity 586/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 5.3
Regular Expression Denial of Service (ReDoS)
SNYK-JS-LODASH-1018905
No Proof of Concept
high severity 681/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 7.2
Command Injection
SNYK-JS-LODASH-1040724
No Proof of Concept
high severity 696/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
Regular Expression Denial of Service (ReDoS)
SNYK-JS-NTHCHECK-1586032
No Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Regular Expression Denial of Service (ReDoS)

@snyk-bot snyk-bot requested a review from a team as a code owner May 9, 2023 07:55
@spectro-prow
Copy link

Hi @snyk-bot. Thanks for your PR.

I'm waiting for a spectrocloud member to verify that this patch is reasonable to test. If it is, they should reply with /ok-to-test on its own line. Until that is done, I will not automatically test new commits in this PR, but the usual testing commands by org members will still work. Regular contributors should join the org to skip this step.

Once the patch is verified, the new status will be reflected by the ok-to-test label.

I understand the commands that are listed here.

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository.

@netlify
Copy link

netlify bot commented May 9, 2023

Deploy Preview for docs-spectrocloud ready!

Name Link
🔨 Latest commit 618cdc2
🔍 Latest deploy log https://app.netlify.com/sites/docs-spectrocloud/deploys/64656f283c649b0008871814
😎 Deploy Preview https://deploy-preview-1282--docs-spectrocloud.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.

To edit notification comments on pull requests, go to your Netlify site settings.

@spectro-prow
Copy link

[APPROVALNOTIFIER] This PR is NOT APPROVED

This pull-request has been approved by: karl-cardenas-coding, snyk-bot
To complete the pull request process, please assign
You can assign the PR to them by writing /assign in a comment when ready.

The full list of commands accepted by this bot can be found here.

Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@karl-cardenas-coding karl-cardenas-coding merged commit b20c684 into master May 18, 2023
8 checks passed
@karl-cardenas-coding karl-cardenas-coding deleted the snyk-fix-0e2c56cd65d458aba0a1328a36804679 branch May 18, 2023 00:32
github-actions bot pushed a commit that referenced this pull request May 23, 2023
# [3.4.0](v3.3.0...v3.4.0) (2023-05-23)

### Bug Fixes

* package.json & package-lock.json to reduce vulnerabilities ([#1282](#1282)) ([b20c684](b20c684))
* upgrade antd from 4.24.8 to 4.24.9 ([#1290](#1290)) ([d5f9771](d5f9771))
* upgrade react-instantsearch-dom from 6.39.0 to 6.39.1 ([#1238](#1238)) ([678b82b](678b82b))
* upgrade sharp from 0.30.5 to 0.32.0 ([#1243](#1243)) ([7167c1b](7167c1b))

### Features

* release 3.4 ([#1229](#1229)) ([e2bf1cb](e2bf1cb)), closes [#1246](#1246) [#906](#906) [#1248](#1248) [#1247](#1247)
@github-actions
Copy link
Contributor

🎉 This PR is included in version 3.4.0 🎉

The release is available on GitHub release

Your semantic-release bot 📦🚀

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

3 participants