Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Dependencies Need Updates #41

Open
Zwiqler94 opened this issue Feb 2, 2022 · 0 comments
Open

Dependencies Need Updates #41

Zwiqler94 opened this issue Feb 2, 2022 · 0 comments

Comments

@Zwiqler94
Copy link

# npm audit report

extend  <2.0.2
Severity: moderate
Prototype Pollution in extend - https://github.com/advisories/GHSA-qrmc-fj45-qfc2
fix available via `npm audit fix --force`
Will install soda-js@0.2.1, which is a breaking change
node_modules/extend
  superagent  <=3.6.3
  Depends on vulnerable versions of extend
  Depends on vulnerable versions of form-data
  Depends on vulnerable versions of mime
  Depends on vulnerable versions of qs
  node_modules/superagent
    soda-js  >=0.2.2
    Depends on vulnerable versions of superagent
    node_modules/soda-js

mime  <1.4.1
Severity: moderate
Regular Expression Denial of Service in mime - https://github.com/advisories/GHSA-wrvr-8mpx-r7pp
fix available via `npm audit fix --force`
Will install soda-js@0.2.1, which is a breaking change
node_modules/form-data/node_modules/mime
node_modules/superagent/node_modules/mime
  form-data  0.0.2 - 0.1.4
  Depends on vulnerable versions of mime
  node_modules/form-data
    superagent  <=3.6.3
    Depends on vulnerable versions of extend
    Depends on vulnerable versions of form-data
    Depends on vulnerable versions of mime
    Depends on vulnerable versions of qs
    node_modules/superagent
      soda-js  >=0.2.2
      Depends on vulnerable versions of superagent
      node_modules/soda-js

qs  <6.0.4
Severity: high
Prototype Pollution Protection Bypass in qs - https://github.com/advisories/GHSA-gqgv-6jq5-jjj9
fix available via `npm audit fix --force`
Will install soda-js@0.2.1, which is a breaking change
node_modules/superagent/node_modules/qs
  superagent  <=3.6.3
  Depends on vulnerable versions of extend
  Depends on vulnerable versions of form-data
  Depends on vulnerable versions of mime
  Depends on vulnerable versions of qs
  node_modules/superagent
    soda-js  >=0.2.2
    Depends on vulnerable versions of superagent
    node_modules/soda-js

superagent  <=3.6.3
Severity: high
Large gzip Denial of Service in superagent - https://github.com/advisories/GHSA-8225-6cvr-8pqp
Depends on vulnerable versions of extend
Depends on vulnerable versions of form-data
Depends on vulnerable versions of mime
Depends on vulnerable versions of qs
fix available via `npm audit fix --force`
Will install soda-js@0.2.1, which is a breaking change
node_modules/superagent
  soda-js  >=0.2.2
  Depends on vulnerable versions of superagent
  node_modules/soda-js
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant