Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Snyk] Fix for 28 vulnerabilities #8

Open
wants to merge 1 commit into
base: v1-dev
Choose a base branch
from

Conversation

snyk-bot
Copy link

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:

    • package.json
    • package-lock.json
  • Adding or updating a Snyk policy (.snyk) file; this file is required in order to apply Snyk vulnerability patches.
    Find out more.

Vulnerabilities that will be fixed

With an upgrade:
Severity Issue Breaking Change Exploit Maturity
medium severity Prototype Pollution
SNYK-JS-JQUERY-174006
No No Known Exploit
medium severity Denial of Service (DoS)
SNYK-JS-JSYAML-173999
No No Known Exploit
high severity Arbitrary Code Execution
SNYK-JS-JSYAML-174129
No No Known Exploit
high severity Prototype Pollution
SNYK-JS-LODASH-450202
Yes Proof of Concept
high severity Prototype Pollution
SNYK-JS-LODASH-73638
Yes No Known Exploit
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-LODASH-73639
Yes No Known Exploit
high severity NULL Pointer Dereference
SNYK-JS-NODESASS-535500
No No Known Exploit
high severity Out-of-bounds Read
SNYK-JS-NODESASS-535501
No No Known Exploit
high severity Uncontrolled Recursion
SNYK-JS-NODESASS-535503
No No Known Exploit
medium severity Resource Exhaustion
SNYK-JS-NODESASS-535504
No No Known Exploit
high severity NULL Pointer Dereference
SNYK-JS-NODESASS-535505
No No Known Exploit
medium severity Denial of Service (DoS)
SNYK-JS-NODESASS-540982
No No Known Exploit
medium severity Denial of Service (DoS)
SNYK-JS-NODESASS-542662
No No Known Exploit
low severity Regular Expression Denial of Service (ReDoS)
npm:braces:20180219
No Proof of Concept
medium severity Uninitialized Memory Exposure
npm:concat-stream:20160901
No Mature
medium severity Prototype Pollution
npm:hoek:20180212
No No Known Exploit
low severity Regular Expression Denial of Service (ReDoS)
npm:jasmine-core:20180216
Yes Proof of Concept
medium severity Prototype Pollution
npm:lodash:20180130
Yes No Known Exploit
medium severity Uninitialized Memory Exposure
npm:tunnel-agent:20170305
No Proof of Concept
Commit messages
Package name: grunt The new version differs by 42 commits.

See the full diff

Package name: grunt-contrib-jasmine The new version differs by 20 commits.

See the full diff

Package name: jasmine The new version differs by 32 commits.
  • 33c5f8c bump version to 3.1
  • bdc7ab4 Tell Jasmine-core not to handle load errors itself
  • ea0c23e better error reporting when an invalid --reporter is specified
  • 74d3e96 bump version to 3.0
  • b8cf9aa Merge branch 'master' into 3.0-features
  • 353fecc bump version to 2.99
  • 4d48e70 ignore package-lock so we always get new versions in CI
  • b831ccf Add --fail-fast to help message
  • 375b7aa Support stopping jasmine execution on first spec failure
  • 9aea4e9 Add ability to pass `--reporter` on the command line
  • 76f9fa2 Print full details for suite failures
  • 9cda3c3 Version bump to 2.9.0
  • 38d5568 Report how to re-run Jasmine with the current seed
  • 9af225e Run specs in random order by default
  • 1e5a1f6 Merge branch 'master' into 3.0-features
  • c3271d2 Use the correct `addMatchers` interface from core
  • f55808f Updated node.js versions
  • ca8e39b Ignore vim swap files
  • a17e3f9 Depend on core 3.0
  • 5643389 Added an editorconfig file
  • 894f6c3 Treat suites with focused specs as failures
  • dcca51c Removed deprecated completion callback from console reporter
  • 19ca208 Update dependencies
  • 44e28d6 Removed 0.10.x compatibility code

See the full diff

Package name: lint-staged The new version differs by 11 commits.

See the full diff

Package name: node-sass The new version differs by 130 commits.

See the full diff

Package name: phantomjs-prebuilt The new version differs by 6 commits.

See the full diff

With a Snyk patch:
Severity Issue Exploit Maturity
low severity Regular Expression Denial of Service (ReDoS)
npm:debug:20170905
No Known Exploit
high severity Prototype Pollution
npm:extend:20180424
No Known Exploit
medium severity Prototype Pollution
npm:hoek:20180212
No Known Exploit
medium severity Prototype Pollution
npm:lodash:20180130
No Known Exploit
low severity Regular Expression Denial of Service (ReDoS)
npm:mime:20170907
No Known Exploit
low severity Regular Expression Denial of Service (ReDoS)
npm:ms:20170412
No Known Exploit
high severity Prototype Override Protection Bypass
npm:qs:20170213
No Known Exploit
medium severity Uninitialized Memory Exposure
npm:stringstream:20180511
Mature
medium severity Regular Expression Denial of Service (ReDoS)
npm:tough-cookie:20170905
No Known Exploit
medium severity Uninitialized Memory Exposure
npm:tunnel-agent:20170305
Proof of Concept
medium severity Regular Expression Denial of Service (DoS)
npm:uglify-js:20151024
No Known Exploit
medium severity Insecure Randomness
npm:ws:20160920
No Known Exploit

Note that some vulnerabilities couldn’t be fully fixed, and so will still fail the Snyk test report.

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:

🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic

The following vulnerabilities are fixed with an upgrade:
- https://snyk.io/vuln/SNYK-JS-JQUERY-174006
- https://snyk.io/vuln/SNYK-JS-JSYAML-173999
- https://snyk.io/vuln/SNYK-JS-JSYAML-174129
- https://snyk.io/vuln/SNYK-JS-LODASH-450202
- https://snyk.io/vuln/SNYK-JS-LODASH-73638
- https://snyk.io/vuln/SNYK-JS-LODASH-73639
- https://snyk.io/vuln/SNYK-JS-NODESASS-535500
- https://snyk.io/vuln/SNYK-JS-NODESASS-535501
- https://snyk.io/vuln/SNYK-JS-NODESASS-535503
- https://snyk.io/vuln/SNYK-JS-NODESASS-535504
- https://snyk.io/vuln/SNYK-JS-NODESASS-535505
- https://snyk.io/vuln/SNYK-JS-NODESASS-540982
- https://snyk.io/vuln/SNYK-JS-NODESASS-542662
- https://snyk.io/vuln/npm:braces:20180219
- https://snyk.io/vuln/npm:concat-stream:20160901
- https://snyk.io/vuln/npm:hoek:20180212
- https://snyk.io/vuln/npm:jasmine-core:20180216
- https://snyk.io/vuln/npm:lodash:20180130
- https://snyk.io/vuln/npm:tunnel-agent:20170305


The following vulnerabilities are fixed with a Snyk patch:
- https://snyk.io/vuln/npm:debug:20170905
- https://snyk.io/vuln/npm:extend:20180424
- https://snyk.io/vuln/npm:hoek:20180212
- https://snyk.io/vuln/npm:lodash:20180130
- https://snyk.io/vuln/npm:mime:20170907
- https://snyk.io/vuln/npm:ms:20170412
- https://snyk.io/vuln/npm:qs:20170213
- https://snyk.io/vuln/npm:stringstream:20180511
- https://snyk.io/vuln/npm:tough-cookie:20170905
- https://snyk.io/vuln/npm:tunnel-agent:20170305
- https://snyk.io/vuln/npm:uglify-js:20151024
- https://snyk.io/vuln/npm:ws:20160920
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

On mobile phone screen, div with class 'drag-target' close right part of 'slide-nav' menu
1 participant