Skip to content

Conversation

@AH7
Copy link
Owner

@AH7 AH7 commented Nov 28, 2023

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • package.json

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
medium severity 651/1000
Why? Mature exploit, Has a fix available, CVSS 5.3
Regular Expression Denial of Service (ReDoS)
SNYK-JS-ANGULAR-2772735
Yes Mature
medium severity 531/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 4.2
Cross-site Scripting (XSS)
SNYK-JS-ANGULAR-2949781
Yes Proof of Concept
medium severity 586/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 5.3
Regular Expression Denial of Service (ReDoS)
SNYK-JS-ANGULAR-3373044
Yes Proof of Concept
medium severity 586/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 5.3
Regular Expression Denial of Service (ReDoS)
SNYK-JS-ANGULAR-3373045
Yes Proof of Concept
medium severity 586/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 5.3
Regular Expression Denial of Service (ReDoS)
SNYK-JS-ANGULAR-3373046
Yes Proof of Concept
high severity 696/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
Regular Expression Denial of Service (ReDoS)
SNYK-JS-ANSIREGEX-1583908
Yes Proof of Concept
medium severity 636/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 6.3
Prototype Pollution
SNYK-JS-DOTPROP-543489
No Proof of Concept
medium severity 484/1000
Why? Has a fix available, CVSS 5.4
Open Redirect
SNYK-JS-GOT-2932019
No No Known Exploit
medium severity 479/1000
Why? Has a fix available, CVSS 5.3
Regular Expression Denial of Service (ReDoS)
SNYK-JS-MINIMATCH-3050818
No No Known Exploit
medium severity 646/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 6.5
Server-side Request Forgery (SSRF)
SNYK-JS-REQUEST-3361831
Yes Proof of Concept
medium severity 646/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 6.5
Prototype Pollution
SNYK-JS-TOUGHCOOKIE-5672873
Yes Proof of Concept
medium severity 601/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 5.6
Prototype Pollution
SNYK-JS-YARGSPARSER-560381
No Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: angular-ui-router The new version differs by 250 commits.
  • 1b34e08 chore(docs): Add publishdocs script
  • 4cdc307 chore(release): Fix artifacts uploda script
  • ea443d8 Release 1.0.0
  • 7018915 chore(build): bump core to 5.0.1
  • 4539e4a chore(travis): Fix travis
  • 74338aa chore(package): Rename angular-ui-router vestiges to @ uirouter/angularjs
  • 4919a3a Prep for @ uirouter/angularjs release 1.0.0
  • 07c9136 sq
  • 043be3e sq
  • dd26d49 feat(core): Add UMD bundle adapter for @ uirouter/core
  • a26ed81 chore(migrate): Add migration warning on install
  • 8d62b0d chore(core): Switch from ui-router-core to @ uirouter/core
  • af0b8d4 chore(*): artifact tagging script
  • 7a086ee fix(uiCanExit): Only process uiCanExit hook once during redirects
  • 8fe5b1f fix(view): Allow targeting nested named ui-view by simple ui-view name
  • ec6e5e4 fix(noImplicitAny): move noimplicitany compliance test file to correct location
  • df6ee24 fix(onEnter): Fix typescript typing for onEnter/onRetain/onExit
  • 4559c32 fix(routeToComponent): Bind resolves that start with data- or x-
  • 8e7386b chore(typescript): Add noImplicitAny compliance check in `test` script
  • 60e7407 chore(travis): bump travis node requirement
  • b4863cf chore(ISSUE_TEMPLATE): create issue template
  • a04674c chore(ISSUE_TEMPLATE): create issue template
  • 7573156 fix(views): Better validation of view declarations (throw when there are state-level and view-level conflicts)
  • 66103fc fix(views): Allow same views object to be reused in multiple states

See the full diff

Package name: npm The new version differs by 250 commits.
  • 3b4ba65 7.0.0
  • bbfc75d chore: fix weird .gitignore thing that happened somehow
  • 8a2d375 docs: changelog for v7.0.0
  • 365f2e7 read-package-json@3.0.0
  • fafb348 npm-package-arg@8.1.0
  • 9306c68 libnpmfund@1.0.1
  • 569cd64 libnpmfund@1.0.0
  • ac9fde7 Integration code for @ npmcli/arborist@1.0.0
  • 704b9cd @ npmcli/arborist@1.0.0
  • 3955bb9 hosted-git-info@3.0.6
  • da240ef fix: patch config.js to remove duplicate values
  • 9ae45a8 init-package-json@2.0.0
  • 41ab36d eslint@7.11.0
  • c474a15 npm-registry-fetch@8.1.5
  • efc6786 fix: make sure publishConfig is passed through
  • 1e4e6e9 docs: v7 using npm config refresh
  • 5c1c2da fix: init config aliases
  • 5bc7eb2 docs: v7 npm-install refresh
  • 1a35d87 7.0.0-rc.4
  • 7a5a557 docs: changelog for v7.0.0-rc.4
  • f0cf859 chore: dedupe deps
  • 0273745 make-fetch-happen@8.0.10
  • 7bd47ca @ npmcli/arborist@0.0.33
  • 9320b8e only escape arguments, not the command name

See the full diff

Package name: snyk The new version differs by 250 commits.
  • 933f3f1 feat: update snyk-resolve-deps to reduce size of dependencies
  • 042c476 feat: remove update notifier
  • 7e10aae feat: support yarn for protect scripts
  • 6b6ce94 fix: dont suggest reinstallation for yarn projects
  • 80e49fd fix: update test fixures expected version
  • 38f993f fix: compatability with new pip version (10.0.0)
  • db91114 feat: a seperate spinner for "Analyzing deps ..."
  • 6a77349 fix: update snyk-go-plugin 1.4.5 -> 1.4.6
  • 334f8b1 fix: remove vulns from analytics payload if present
  • 58b5437 chore: adds security document
  • b3d241a fix: bump snyk-python-plugin to better handle editable fragments
  • 66d658a fix: analytics report includes duration of execution
  • c2399ae feat: add severity-threshold flag
  • 9da056d fix: add --json to help docs
  • 46cb432 fix: bump sbt-plugin to 1.2.5 (better errors)
  • 5bf0f83 fix: debug on requests
  • 6847700 test: lock `nock` to 9.1.0
  • 65c6ac1 test: new policy fixtures
  • 54ffa86 fix: bump snyk-policy to allow unquoted dates
  • e70618d docs: update readme
  • a536ad5 fix: bump snyk-sbt-plugin to fix output format issue
  • d7d3353 fix: standardise handling of errors on snyk test
  • dd60fcc test: tests are not babelified, remove es6 syntax for 0.12 support
  • 297b3ac fix: bump debug to a non-vulnerable minimum version

See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Regular Expression Denial of Service (ReDoS)
🦉 Cross-site Scripting (XSS)
🦉 Prototype Pollution
🦉 More lessons are available in Snyk Learn

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants