Skip to content

Conversation

@tf-security
Copy link
Contributor

snyk-top-banner

Snyk has created this PR to fix 1 vulnerabilities in the yarn dependencies of this project.

Snyk changed the following file(s):

  • packages/demo-nextjs/package.json

Note for zero-installs users

If you are using the Yarn feature zero-installs that was introduced in Yarn V2, note that this PR does not update the .yarn/cache/ directory meaning this code cannot be pulled and immediately developed on as one would expect for a zero-install project - you will need to run yarn to update the contents of the ./yarn/cache directory.
If you are not using zero-install you can ignore this as your flow should likely be unchanged.

⚠️ Warning
Failed to update the yarn.lock, please update manually before merging. 

Vulnerabilities that will be fixed with an upgrade:

Issue Score
critical severity Improper Authorization
SNYK-JS-NEXT-9508709
  240  

Important

  • Check the changes in this PR to ensure they won't cause issues with your project.
  • Max score is 1000. Note that the real score may have changed since the PR was raised.
  • This PR was automatically created by Snyk using the credentials of a real user.

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report
📜 Customise PR templates
🛠 Adjust project settings
📚 Read about Snyk's upgrade logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Improper Authorization

@tf-security tf-security requested a review from a team as a code owner March 21, 2025 18:26
@tf-security
Copy link
Contributor Author

tf-security commented Mar 21, 2025

🎉 Snyk checks have passed. No issues have been found so far.

security/snyk check is complete. No issues have been found. (View Details)

license/snyk check is complete. No issues have been found. (View Details)

code/snyk check is complete. No issues have been found. (View Details)

@gitstream-cm
Copy link

gitstream-cm bot commented Mar 21, 2025

This PR is missing a Jira ticket reference in the title or description.
Please add a Jira ticket reference to the title or description of this PR.

@gitstream-cm
Copy link

gitstream-cm bot commented Mar 21, 2025

🥷 Code experts: tf-IT

tf-IT has most 👩‍💻 activity in the files.

See details

packages/demo-nextjs/package.json

Activity based on git-commit:

tf-IT
MAR 2 additions & 2 deletions
FEB
JAN 2 additions & 2 deletions
DEC
NOV 2 additions & 2 deletions
OCT

Knowledge based on git-blame:

To learn more about /:\ gitStream - Visit our Docs

@typeform-ops-gha
Copy link

[BOT] Preview available with hash 83aa61d320d18465947296e7c14193e25631e295 here.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment