cloudboost icon indicating copy to clipboard operation
cloudboost copied to clipboard

[Snyk] Fix for 1 vulnerabilities

Open nawazdhandala opened this issue 1 year ago • 0 comments

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • data-service/package.json

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
high severity 768/1000
Why? Proof of Concept exploit, Recently disclosed, Has a fix available, CVSS 7.5
Prototype Pollution
SNYK-JS-LODASH-6139239
Yes Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: nodemailer-mailgun-transport The new version differs by 14 commits.
  • eebbfb3 Merge pull request #84 from framp/master
  • 87204df Small refactoring
  • 7c861c3 Merge pull request #78 from strix/es6-syntax
  • 79f5eb8 Fixed reference to
  • 5af88a4 Changed self to simply this.
  • fdc108b linting cleanup
  • 44a0a02 Moved resolveAttachments function outside of promise chain since it is synchronous
  • 4d50b02 Fixed path the handlebars template
  • d2352c1 Updated syntax to es6
  • 285e420 Merge pull request #77 from perzanko/master
  • ff5ff0b Fixed type in readme
  • c4f1a1e updated readme, es6 variables definitions, callback functions, region env info
  • 31d6cb3 added vuln badge
  • 9fe4182 Update README.md

See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information: 🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Prototype Pollution

nawazdhandala avatar Apr 15 '24 19:04 nawazdhandala