Skip to content

Conversation

f4lco0n
Copy link
Owner

@f4lco0n f4lco0n commented Feb 11, 2024

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • package.json
    • package-lock.json

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
high severity 823/1000
Why? Proof of Concept exploit, Recently disclosed, Has a fix available, CVSS 8.6
Server-side Request Forgery (SSRF)
SNYK-JS-IP-6240864
Yes Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: @npmcli/arborist The new version differs by 250 commits.

See the full diff

Package name: @npmcli/run-script The new version differs by 36 commits.

See the full diff

Package name: @npmcli/template-oss The new version differs by 68 commits.

See the full diff

Package name: libnpmaccess The new version differs by 250 commits.

See the full diff

Package name: libnpmdiff The new version differs by 250 commits.

See the full diff

Package name: libnpmexec The new version differs by 250 commits.

See the full diff

Package name: libnpmfund The new version differs by 250 commits.

See the full diff

Package name: libnpmhook The new version differs by 250 commits.

See the full diff

Package name: libnpmorg The new version differs by 250 commits.

See the full diff

Package name: libnpmpack The new version differs by 250 commits.

See the full diff

Package name: libnpmsearch The new version differs by 250 commits.

See the full diff

Package name: libnpmversion The new version differs by 250 commits.

See the full diff

Package name: node-gyp The new version differs by 40 commits.

See the full diff

Package name: npm-profile The new version differs by 27 commits.

See the full diff

Package name: npm-registry-fetch The new version differs by 27 commits.

See...

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

2 participants