Skip to content

Conversation

@svcsnyksanity
Copy link

snyk-top-banner

Snyk has created this PR to fix 13 vulnerabilities in the yarn dependencies of this project.

Snyk changed the following file(s):

  • package.json
  • yarn.lock

Note for zero-installs users

If you are using the Yarn feature zero-installs that was introduced in Yarn V2, note that this PR does not update the .yarn/cache/ directory meaning this code cannot be pulled and immediately developed on as one would expect for a zero-install project - you will need to run yarn to update the contents of the ./yarn/cache directory.
If you are not using zero-install you can ignore this as your flow should likely be unchanged.

Vulnerabilities that will be fixed with an upgrade:

Issue Score
high severity Improper Input Validation
SNYK-JS-URLPARSE-2407770
  726  
high severity Improper Input Validation
SNYK-JS-URLPARSE-543307
  726  
high severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-TRIM-1017038
  696  
high severity Improper Input Validation
SNYK-JS-FOLLOWREDIRECTS-6141137
  686  
medium severity Information Exposure
SNYK-JS-EVENTSOURCE-2823375
  646  
medium severity Information Exposure
SNYK-JS-FOLLOWREDIRECTS-6444610
  646  
medium severity Access Restriction Bypass
SNYK-JS-URLPARSE-2401205
  641  
medium severity Authorization Bypass
SNYK-JS-URLPARSE-2407759
  641  
medium severity Authorization Bypass Through User-Controlled Key
SNYK-JS-URLPARSE-2412697
  631  
medium severity Information Exposure
SNYK-JS-FOLLOWREDIRECTS-2332181
  586  
medium severity Open Redirect
SNYK-JS-URLPARSE-1533425
  586  
medium severity Information Exposure
SNYK-JS-FOLLOWREDIRECTS-2396346
  514  
medium severity Improper Input Validation
SNYK-JS-URLPARSE-1078283
  479  

Important

  • Check the changes in this PR to ensure they won't cause issues with your project.
  • Max score is 1000. Note that the real score may have changed since the PR was raised.
  • This PR was automatically created by Snyk using the credentials of a real user.

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report
📜 Customise PR templates
🛠 Adjust project settings
📚 Read about Snyk's upgrade logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Improper Input Validation
🦉 Regular Expression Denial of Service (ReDoS)
🦉 Open Redirect

@socket-security
Copy link

New and removed dependencies detected. Learn more about Socket for GitHub ↗︎

Package New capabilities Transitives Size Publisher
npm/@sanity/client@6.21.3 None 0 2.16 MB sanity-io
npm/@sanity/eventsource@5.0.2 None 0 6.96 kB sanity-io
npm/@types/event-source-polyfill@1.0.5 None 0 5.2 kB types
npm/@types/eventsource@1.1.15 None 0 8.14 kB types
npm/@types/follow-redirects@1.14.4 None 0 8.29 kB types
npm/@types/node@22.5.4 None 0 2.2 MB types
npm/@types/progress-stream@2.0.5 None 0 6.73 kB types
npm/debug@4.1.1 environment 0 81.5 kB qix
npm/decompress-response@7.0.0 None 0 5.68 kB sindresorhus
npm/event-source-polyfill@1.0.31 network 0 58.1 kB yaffle
npm/eventsource@2.0.2 network 0 314 kB rexxars
npm/follow-redirects@1.15.8 None 0 30 kB olalonde, rubenverborgh
npm/get-it@8.6.5 None 0 705 kB armandocerna, ash, atombender, ...53 more
npm/is-retry-allowed@2.2.0 None 0 4.42 kB sindresorhus
npm/mimic-response@3.1.0 None 0 6 kB sindresorhus
npm/ms@2.1.1 None 0 6.82 kB leo
npm/rxjs@7.8.1 None 0 4.5 MB blesh
npm/tslib@2.7.0 None 0 86.2 kB typescript-bot
npm/undici-types@6.19.8 None 0 84.2 kB ethan_arrowood, matteo.collina

🚮 Removed packages: npm/@sanity/client@0.140.0), npm/@sanity/eventsource@0.140.0), npm/@sanity/generate-help-url@0.140.0), npm/@sanity/observable@0.140.0), npm/debug@2.6.9), npm/decompress-response@3.3.0), npm/deep-assign@2.0.0), npm/eventsource-polyfill@0.9.6), npm/eventsource@1.0.7), npm/follow-redirects@1.6.1), npm/for-each@0.3.3), npm/form-urlencoded@2.0.9), npm/get-it@4.0.4), npm/in-publish@2.0.0), npm/into-stream@3.1.0), npm/is-retry-allowed@1.1.0), npm/make-error@1.3.5), npm/mimic-response@1.0.1), npm/ms@2.0.0), npm/nano-pubsub@1.0.2), npm/original@1.0.2), npm/p-is-promise@1.1.0), npm/parse-headers@2.0.1), npm/querystringify@2.1.0), npm/requires-port@1.0.0), npm/rxjs@6.3.3), npm/same-origin@0.1.1), npm/simple-concat@1.0.0), npm/trim@0.0.1), npm/tslib@1.9.3), npm/url-parse@1.4.4), npm/uuid@3.3.2)

View full report↗︎

@nicholasklem
Copy link
Member

Closing automated Snyk PR

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

3 participants