demo-media-site-nextjs
demo-media-site-nextjs copied to clipboard
[Snyk] Security upgrade sanity from 3.28.0 to 3.67.0
Snyk has created this PR to fix 4 vulnerabilities in the npm dependencies of this project.
Snyk changed the following file(s):
package.jsonpackage-lock.json
Vulnerabilities that will be fixed with an upgrade:
| Issue | Score | |
|---|---|---|
| Missing Release of Resource after Effective Lifetime SNYK-JS-INFLIGHT-6095116 |
631 | |
| Information Exposure SNYK-JS-VITE-8023174 |
621 | |
| Improper Access Control SNYK-JS-VITE-6531286 |
616 | |
| Cross-site Scripting (XSS) SNYK-JS-VITE-8022916 |
436 |
[!IMPORTANT]
- Check the changes in this PR to ensure they won't cause issues with your project.
- Max score is 1000. Note that the real score may have changed since the PR was raised.
- This PR was automatically created by Snyk using the credentials of a real user.
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.
For more information:
🧐 View latest project report
📜 Customise PR templates
🛠 Adjust project settings
📚 Read about Snyk's upgrade logic
Learn how to fix vulnerabilities with free interactive lessons:
The latest updates on your projects. Learn more about Vercel for Git ↗︎
| Name | Status | Preview | Comments | Updated (UTC) |
|---|---|---|---|---|
| demo-media-site-nextjs | ❌ Failed (Inspect) | Dec 10, 2024 11:16pm |
New and removed dependencies detected. Learn more about Socket for GitHub ↗︎
| Package | New capabilities | Transitives | Size | Publisher |
|---|---|---|---|---|
| npm/@sanity/[email protected] | environment, filesystem Transitive: eval, network, shell, unsafe | +319 |
283 MB | ash |
| npm/@types/[email protected] | None | +2 |
1.69 MB | types |
| npm/[email protected] | environment, filesystem | +3 |
372 kB | ai |
| npm/[email protected] | environment | 0 |
24 kB | react-bot |
| npm/[email protected] | environment | +2 |
339 kB | react-bot |
| npm/[email protected] | Transitive: environment, eval, filesystem, network, shell, unsafe | +617 |
448 MB | armandocerna, ash, atombender, ...62 more |
🚮 Removed packages: npm/@sanity/[email protected], npm/@types/[email protected], npm/[email protected], npm/[email protected], npm/[email protected], npm/[email protected]
Closing automated Snyk PR