Skip to content

Develop#29

Merged
thkruz merged 3 commits into
masterfrom
develop
Aug 23, 2024
Merged

Develop#29
thkruz merged 3 commits into
masterfrom
develop

Conversation

@thkruz
Copy link
Copy Markdown
Owner

@thkruz thkruz commented Aug 23, 2024

No description provided.

@thkruz thkruz merged commit 3c23205 into master Aug 23, 2024
@github-actions
Copy link
Copy Markdown

# npm audit report

micromatch  *
Severity: moderate
Regular Expression Denial of Service (ReDoS) in micromatch - https://github.com/advisories/GHSA-952p-6rrq-rcjv
fix available via `npm audit fix --force`
Will install jest@25.0.0, which is a breaking change
node_modules/micromatch
  @jest/core  *
  Depends on vulnerable versions of @jest/console
  Depends on vulnerable versions of @jest/reporters
  Depends on vulnerable versions of @jest/test-result
  Depends on vulnerable versions of @jest/transform
  Depends on vulnerable versions of jest-config
  Depends on vulnerable versions of jest-haste-map
  Depends on vulnerable versions of jest-message-util
  Depends on vulnerable versions of jest-resolve
  Depends on vulnerable versions of jest-resolve-dependencies
  Depends on vulnerable versions of jest-runner
  Depends on vulnerable versions of jest-runtime
  Depends on vulnerable versions of jest-snapshot
  Depends on vulnerable versions of jest-watcher
  Depends on vulnerable versions of micromatch
  node_modules/@jest/core
    jest  >=24.2.0-alpha.0
    Depends on vulnerable versions of @jest/core
    Depends on vulnerable versions of jest-cli
    node_modules/jest
      ts-jest  >=25.10.0-alpha.1
      Depends on vulnerable versions of babel-jest
      Depends on vulnerable versions of jest
      node_modules/ts-jest
    jest-cli  >=23.5.0
    Depends on vulnerable versions of @jest/core
    Depends on vulnerable versions of @jest/test-result
    Depends on vulnerable versions of create-jest
    Depends on vulnerable versions of jest-config
    node_modules/jest-cli
  @jest/transform  *
  Depends on vulnerable versions of jest-haste-map
  Depends on vulnerable versions of micromatch
  node_modules/@jest/transform
    @jest/reporters  *
    Depends on vulnerable versions of @jest/console
    Depends on vulnerable versions of @jest/test-result
    Depends on vulnerable versions of @jest/transform
    Depends on vulnerable versions of jest-message-util
    node_modules/@jest/reporters
    babel-jest  >=24.2.0-alpha.0
    Depends on vulnerable versions of @jest/transform
    node_modules/babel-jest
      jest-config  18.1.0 - 19.0.4 || >=23.5.0
      Depends on vulnerable versions of @jest/test-sequencer
      Depends on vulnerable versions of babel-jest
      Depends on vulnerable versions of jest-circus
      Depends on vulnerable versions of jest-environment-node
      Depends on vulnerable versions of jest-resolve
      Depends on vulnerable versions of jest-runner
      Depends on vulnerable versions of micromatch
      node_modules/jest-config
        create-jest  >=29.7.0
        Depends on vulnerable versions of jest-config
        node_modules/create-jest
    jest-runner  >=21.0.0-alpha.1
    Depends on vulnerable versions of @jest/console
    Depends on vulnerable versions of @jest/environment
    Depends on vulnerable versions of @jest/test-result
    Depends on vulnerable versions of @jest/transform
    Depends on vulnerable versions of jest-environment-node
    Depends on vulnerable versions of jest-haste-map
    Depends on vulnerable versions of jest-message-util
    Depends on vulnerable versions of jest-resolve
    Depends on vulnerable versions of jest-runtime
    Depends on vulnerable versions of jest-watcher
    node_modules/jest-runner
    jest-runtime  >=18.1.0
    Depends on vulnerable versions of @jest/environment
    Depends on vulnerable versions of @jest/fake-timers
    Depends on vulnerable versions of @jest/globals
    Depends on vulnerable versions of @jest/test-result
    Depends on vulnerable versions of @jest/transform
    Depends on vulnerable versions of jest-haste-map
    Depends on vulnerable versions of jest-message-util
    Depends on vulnerable versions of jest-resolve
    Depends on vulnerable versions of jest-snapshot
    node_modules/jest-runtime
      jest-circus  >=20.1.0-alpha.1
      Depends on vulnerable versions of @jest/environment
      Depends on vulnerable versions of @jest/expect
      Depends on vulnerable versions of @jest/test-result
      Depends on vulnerable versions of jest-message-util
      Depends on vulnerable versions of jest-runtime
      Depends on vulnerable versions of jest-snapshot
      node_modules/jest-circus
    jest-snapshot  >=23.3.0
    Depends on vulnerable versions of @jest/transform
    Depends on vulnerable versions of expect
    Depends on vulnerable versions of jest-message-util
    node_modules/jest-snapshot
      jest-resolve-dependencies  >=23.3.0
      Depends on vulnerable versions of jest-snapshot
      node_modules/jest-resolve-dependencies
  fast-glob  *
  Depends on vulnerable versions of micromatch
  node_modules/fast-glob
    globby  >=8.0.0
    Depends on vulnerable versions of fast-glob
    node_modules/globby
      @typescript-eslint/typescript-estree  >=3.10.2-alpha.0
      Depends on vulnerable versions of globby
      node_modules/@typescript-eslint/typescript-estree
        @typescript-eslint/parser  >=3.10.2-alpha.0
        Depends on vulnerable versions of @typescript-eslint/typescript-estree
        node_modules/@typescript-eslint/parser
          @typescript-eslint/eslint-plugin  >=4.0.1-alpha.0
          Depends on vulnerable versions of @typescript-eslint/parser
          Depends on vulnerable versions of @typescript-eslint/type-utils
          Depends on vulnerable versions of @typescript-eslint/utils
          node_modules/@typescript-eslint/eslint-plugin
        @typescript-eslint/type-utils  >=5.9.2-alpha.0
        Depends on vulnerable versions of @typescript-eslint/typescript-estree
        Depends on vulnerable versions of @typescript-eslint/utils
        node_modules/@typescript-eslint/type-utils
        @typescript-eslint/utils  *
        Depends on vulnerable versions of @typescript-eslint/typescript-estree
        node_modules/@typescript-eslint/utils
  jest-haste-map  >=18.1.0
  Depends on vulnerable versions of micromatch
  node_modules/jest-haste-map
    @jest/test-sequencer  *
    Depends on vulnerable versions of @jest/test-result
    Depends on vulnerable versions of jest-haste-map
    node_modules/@jest/test-sequencer
    jest-resolve  18.1.0 - 19.0.2 || 24.2.0-alpha.0 - 24.5.0 || >=27.1.0
    Depends on vulnerable versions of jest-haste-map
    node_modules/jest-resolve
  jest-message-util  >=18.5.0-alpha.7da3df39
  Depends on vulnerable versions of micromatch
  node_modules/jest-message-util
    @jest/console  >=25.4.0
    Depends on vulnerable versions of jest-message-util
    node_modules/@jest/console
      @jest/test-result  >=25.4.0
      Depends on vulnerable versions of @jest/console
      node_modules/@jest/test-result
        jest-watcher  >=25.4.0
        Depends on vulnerable versions of @jest/test-result
        node_modules/jest-watcher
    @jest/fake-timers  *
    Depends on vulnerable versions of jest-message-util
    node_modules/@jest/fake-timers
      @jest/environment  *
      Depends on vulnerable versions of @jest/fake-timers
      node_modules/@jest/environment
        @jest/globals  *
        Depends on vulnerable versions of @jest/environment
        Depends on vulnerable versions of @jest/expect
        node_modules/@jest/globals
      jest-environment-node  >=24.2.0-alpha.0
      Depends on vulnerable versions of @jest/environment
      Depends on vulnerable versions of @jest/fake-timers
      node_modules/jest-environment-node
    expect  >=21.0.0-beta.1
    Depends on vulnerable versions of jest-message-util
    node_modules/expect
      @jest/expect  *
      Depends on vulnerable versions of expect
      Depends on vulnerable versions of jest-snapshot
      node_modules/@jest/expect
      @types/jest  >=28.1.7
      Depends on vulnerable versions of expect
      node_modules/@types/jest

36 moderate severity vulnerabilities

To address issues that do not require attention, run:
  npm audit fix

To address all issues (including breaking changes), run:
  npm audit fix --force

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant