next-reason-boilerplate icon indicating copy to clipboard operation
next-reason-boilerplate copied to clipboard

[Snyk] Fix for 2 vulnerabilities

Open snyk-bot opened this issue 2 years ago • 0 comments

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • package.json
    • package-lock.json

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
low severity 471/1000
Why? Recently disclosed, Has a fix available, CVSS 3.7
Prototype Pollution
SNYK-JS-MINIMIST-2429795
Yes No Known Exploit
medium severity 586/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 5.3
Regular Expression Denial of Service (ReDoS)
SNYK-JS-WS-1296835
Yes Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: next The new version differs by 250 commits.
  • e4f96e6 v8.0.0
  • b31819f Remove build directory
  • a2bb542 Allow publishing the master branch using Lerna
  • 7d6eb38 Merge branch 'canary'
  • 8ddf9c7 v8.0.0-canary.23
  • c9f4a95 Update yarn.lock
  • 163830c Merge branch 'canary'
  • 100b733 v8.0.0-canary.22
  • 315a374 Add new circleci config
  • f8a80f1 [with-typescript] remove unnecessary `passHref` in `Link` components (#6233)
  • ac0976a Update styled-jsx (#6236)
  • b05df70 Fix first render of with-react-helmet example (#6235)
  • 63c25a9 update preset.ts to use isProduction variable (#6234)
  • c07e27f 7.0.3
  • 7c64336 Revert "should not change method to replaceState unless asPath is the same (#6033)"
  • 155423f Bring in terser-webpack-plugin (backport #6231 to master) (#6232)
  • bfd2d08 v8.0.0-canary.21
  • 377e43b Update yarn.lock
  • 2ecb248 v8.0.0-canary.20
  • 45f5663 Bring in terser-webpack-plugin (#6231)
  • 693ab43 Fix typo (#6230)
  • c0701e9 v8.0.0-canary.19
  • 6f162b9 Add Error when using publicRuntimeConfig with target serverless and add buildVars (#6212)
  • 28b61a8 Remove Unneeded _error import (#6224)

See the full diff

Package name: pm2 The new version differs by 250 commits.

See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information: 🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Prototype Pollution

snyk-bot avatar Mar 23 '22 17:03 snyk-bot