Skip to content

Conversation

@twilio-product-security

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • package.json

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
high severity 676/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 7.1
Cross-site Request Forgery (CSRF)
SNYK-JS-AXIOS-6032459
Yes Proof of Concept
medium severity 586/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 5.3
Regular Expression Denial of Service (ReDoS)
SNYK-JS-AXIOS-6124857
Yes Proof of Concept
high severity 661/1000
Why? Recently disclosed, Has a fix available, CVSS 7.5
Prototype Pollution
SNYK-JS-AXIOS-6144788
Yes No Known Exploit

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: @twilio/cli-core The new version differs by 85 commits.
  • b44939c chore(release): set `package.json` to 7.19.1 [skip ci]
  • abdcab0 oaiFix: Updated api definitions
  • 27a03a0 skipped healthcheck api (#238)
  • 0f52d2b chore: skip healthcheck api (#236)
  • caf0f9e chore(deps): bump axios from 0.25.0 to 1.6.0 (#232)
  • c049924 chore(release): set `package.json` to 7.19.0 [skip ci]
  • 065c83d oaiFeat: Updated api definitions
  • bcc1409 chore(release): set `package.json` to 7.18.3 [skip ci]
  • 5371835 oaiFix: Updated api definitions
  • 4fb1f6e chore(release): set `package.json` to 7.18.2 [skip ci]
  • d433194 oaiFix: Updated api definitions
  • eaa2017 chore(release): set `package.json` to 7.18.1 [skip ci]
  • fafccb5 oaiFix: Updated api definitions
  • f0c1508 chore(release): set `package.json` to 7.18.0 [skip ci]
  • 7e9d339 oaiFeat: Updated api definitions
  • 236906b chore(release): set `package.json` to 7.17.0 [skip ci]
  • a82d96f oaiFeat: Updated api definitions
  • 98e3628 chore(release): set `package.json` to 7.16.0 [skip ci]
  • f46ac8a oaiFeat: Updated api definitions
  • 6d4dfa1 chore(release): set `package.json` to 7.15.0 [skip ci]
  • b3a7f5d oaiFeat: Updated api definitions
  • 50dad61 chore(release): set `package.json` to 7.14.0 [skip ci]
  • deed5ec oaiFeat: Updated api definitions
  • 2675034 chore(release): set `package.json` to 7.13.0 [skip ci]

See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Cross-site Request Forgery (CSRF)
🦉 Regular Expression Denial of Service (ReDoS)
🦉 Prototype Pollution

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

2 participants