[Snyk] Fix for 2 vulnerabilities
Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.
Changes included in this Merge Request
- Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
- frontend/package.json
Vulnerabilities that will be fixed
With an upgrade:
Severity | Priority Score (*) | Issue | Breaking Change | Exploit Maturity |
---|---|---|---|---|
144/1000 Why? Confidentiality impact: None, Integrity impact: None, Availability impact: High, Scope: Unchanged, Exploit Maturity: Proof of Concept, User Interaction (UI): Required, Privileges Required (PR): None, Attack Complexity: Low, Attack Vector: Network, EPSS: 0.01055, Social Trends: No, Days since published: 0, Reachable: No, Transitive dependency: Yes, Is Malicious: No, Business Criticality: High, Provider Urgency: Medium, Package Popularity Score: 99, Impact: 5.99, Likelihood: 2.39, Score Version: V5 |
Uncontrolled Resource Consumption ('Resource Exhaustion') SNYK-JS-TAR-6476909 |
Yes | Proof of Concept | |
160/1000 Why? Confidentiality impact: High, Integrity impact: None, Availability impact: None, Scope: Changed, Exploit Maturity: Proof of Concept, User Interaction (UI): Required, Privileges Required (PR): None, Attack Complexity: Low, Attack Vector: Network, EPSS: 0.01055, Social Trends: No, Days since published: 0, Reachable: No, Transitive dependency: Yes, Is Malicious: No, Business Criticality: High, Provider Urgency: High, Package Popularity Score: 99, Impact: 6.65, Likelihood: 2.39, Score Version: V5 |
Path Traversal SNYK-JS-WEBPACKDEVMIDDLEWARE-6476555 |
Yes | Proof of Concept |
(*) Note that the real score may have changed since the PR was raised.
Commit messages
Package name: node-sass
The new version differs by 43 commits.- 7105b0a 5.0.0 (#3015)
- 0648b5a chore: Add Node 15 support (#2983)
- e2391c2 Add a deprecation message to the readme (#3011)
- 6a33e53 chore: Don't upload artifacts on PRs
- d763506 chore: Only run coverage on main repo
- d4ebe72 build(deps): update actions/setup-node requirement to v2.1.2
- 2bebe05 build(deps-dev): bump rimraf from 2.7.1 to 3.0.2
- f877689 chore: Don't double build DependaBot PRs
- b48fac4 chore: Add weekly DependaBot updates
- 91c40a0 Remove deprecated process.sass API
- 1f6df86 Replace lodash/assign in favor of the native Object.assign
- 522828a Remove workarounds for old Node.js versions
- 40e0f00 chore: Remove second NPM badge
- ab91bf6 chore: Remove Slack badge
- 6853a80 chore: Cleanup status badges
- fb1109c chore: Bump minimum engine version to v10
- d185440 chore: Add basic Node version support policy
- db25736 chore: Bump node-gyp to 7.1.0
- 2c5b110 chore: Bump cross-spawn to v7.0.3
- 38b9633 chore: Update Istanbul to NYC
- d63b5bf chore: Bump mocha to v8.1.3
- d0d8865 chore: Skip constructor tests on v14.6+
- ee3984d chore: Hoist test ESLint config
- feee448 chore: Remove disabled and recommended rules
Check the changes in this Merge Request to ensure they won't cause issues with your project.
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.
For more information: 🧐 View latest project report
Learn how to fix vulnerabilities with free interactive lessons: