Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

11 vulnerabilities must be fixed manually #20

Open
raphaelalvarenga opened this issue Jul 29, 2019 · 2 comments
Open

11 vulnerabilities must be fixed manually #20

raphaelalvarenga opened this issue Jul 29, 2019 · 2 comments
Assignees

Comments

@raphaelalvarenga
Copy link

@raphaelalvarenga raphaelalvarenga commented Jul 29, 2019

Hello,

I npm installed react-native-phone-call and the package manager alerted that there were 1666 high vulnerabilities and 11 low vulnerabilities to be fixed. I inserted "npm audit fix" and it fixed the high ones.

Now, it says: "11 vulnerabilities required manual review and could not be updated".

I'm using Expo. The report is:

Low Regular Expression Denial of Service

Package braces

Patched in >=2.3.1

Dependency of 261a5a0f90cf47bb4651d059c9a4782169305e0aad1a8cefc3ed9370dc0…

Path 261a5a0f90cf47bb4651d059c9a4782169305e0aad1a8cefc3ed9370dc0…
> @react-native-community/cli > metro > jest-haste-map >
micromatch > braces

More info https://npmjs.com/advisories/786

Low Regular Expression Denial of Service

Package braces

Patched in >=2.3.1

Dependency of 261a5a0f90cf47bb4651d059c9a4782169305e0aad1a8cefc3ed9370dc0…

Path 261a5a0f90cf47bb4651d059c9a4782169305e0aad1a8cefc3ed9370dc0…
> @react-native-community/cli > metro-config > metro >
jest-haste-map > micromatch > braces

More info https://npmjs.com/advisories/786

Low Regular Expression Denial of Service

Package braces

Patched in >=2.3.1

Dependency of 261a5a0f90cf47bb4651d059c9a4782169305e0aad1a8cefc3ed9370dc0…

Path 261a5a0f90cf47bb4651d059c9a4782169305e0aad1a8cefc3ed9370dc0…
> @react-native-community/cli > metro > metro-cache >
metro-core > jest-haste-map > micromatch > braces

More info https://npmjs.com/advisories/786

Low Regular Expression Denial of Service

Package braces

Patched in >=2.3.1

Dependency of 261a5a0f90cf47bb4651d059c9a4782169305e0aad1a8cefc3ed9370dc0…

Path 261a5a0f90cf47bb4651d059c9a4782169305e0aad1a8cefc3ed9370dc0…
> @react-native-community/cli > metro-config > metro >
metro-cache > metro-core > jest-haste-map > micromatch >
braces

More info https://npmjs.com/advisories/786

Low Regular Expression Denial of Service

Package braces

Patched in >=2.3.1

Dependency of 261a5a0f90cf47bb4651d059c9a4782169305e0aad1a8cefc3ed9370dc0…

Path 261a5a0f90cf47bb4651d059c9a4782169305e0aad1a8cefc3ed9370dc0…
> @react-native-community/cli > metro > metro-config >
metro-cache > metro-core > jest-haste-map > micromatch >
braces

More info https://npmjs.com/advisories/786

Low Regular Expression Denial of Service

Package braces

Patched in >=2.3.1

Dependency of 261a5a0f90cf47bb4651d059c9a4782169305e0aad1a8cefc3ed9370dc0…

Path 261a5a0f90cf47bb4651d059c9a4782169305e0aad1a8cefc3ed9370dc0…
> @react-native-community/cli > metro-config > metro-cache >
metro-core > jest-haste-map > micromatch > braces

More info https://npmjs.com/advisories/786

Low Regular Expression Denial of Service

Package braces

Patched in >=2.3.1

Dependency of 261a5a0f90cf47bb4651d059c9a4782169305e0aad1a8cefc3ed9370dc0…

Path 261a5a0f90cf47bb4651d059c9a4782169305e0aad1a8cefc3ed9370dc0…
> @react-native-community/cli > metro > metro-config >
metro-core > jest-haste-map > micromatch > braces

More info https://npmjs.com/advisories/786

Low Regular Expression Denial of Service

Package braces

Patched in >=2.3.1

Dependency of 261a5a0f90cf47bb4651d059c9a4782169305e0aad1a8cefc3ed9370dc0…

Path 261a5a0f90cf47bb4651d059c9a4782169305e0aad1a8cefc3ed9370dc0…
> @react-native-community/cli > metro-config > metro-core >
jest-haste-map > micromatch > braces

More info https://npmjs.com/advisories/786

Low Regular Expression Denial of Service

Package braces

Patched in >=2.3.1

Dependency of 261a5a0f90cf47bb4651d059c9a4782169305e0aad1a8cefc3ed9370dc0…

Path 261a5a0f90cf47bb4651d059c9a4782169305e0aad1a8cefc3ed9370dc0…
> @react-native-community/cli > metro > metro-core >
jest-haste-map > micromatch > braces

More info https://npmjs.com/advisories/786

Low Regular Expression Denial of Service

Package braces

Patched in >=2.3.1

Dependency of 261a5a0f90cf47bb4651d059c9a4782169305e0aad1a8cefc3ed9370dc0…

Path 261a5a0f90cf47bb4651d059c9a4782169305e0aad1a8cefc3ed9370dc0…
> @react-native-community/cli > metro-config > metro >
metro-core > jest-haste-map > micromatch > braces

More info https://npmjs.com/advisories/786

Low Regular Expression Denial of Service

Package braces

Patched in >=2.3.1

Dependency of 261a5a0f90cf47bb4651d059c9a4782169305e0aad1a8cefc3ed9370dc0…

Path 261a5a0f90cf47bb4651d059c9a4782169305e0aad1a8cefc3ed9370dc0…
> @react-native-community/cli > metro-core > jest-haste-map
> micromatch > braces

More info https://npmjs.com/advisories/786

found 11 low severity vulnerabilities in 37960 scanned packages
11 vulnerabilities require manual review. See the full report for details.

@issue-label-bot issue-label-bot bot added the bug label Jul 29, 2019
@issue-label-bot

This comment has been minimized.

Copy link

@issue-label-bot issue-label-bot bot commented Jul 29, 2019

Issue-Label Bot is automatically applying the label bug to this issue, with a confidence of 0.83. Please mark this comment with 👍 or 👎 to give our bot feedback!

Links: app homepage, dashboard and code for this bot.

@raphaelalvarenga

This comment has been minimized.

Copy link
Author

@raphaelalvarenga raphaelalvarenga commented Aug 8, 2019

Anyone?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
2 participants
You can’t perform that action at this time.