taquito icon indicating copy to clipboard operation
taquito copied to clipboard

[Snyk] Fix for 4 vulnerabilities

Open roxaneletourneau opened this issue 1 year ago • 3 comments

This PR was automatically created by Snyk using the credentials of a real user.


![snyk-top-banner](https://github.com/andygongea/OWASP-Benchmark/assets/818805/c518c423-16fe-447e-b67f-ad5a49b5d123)

Snyk has created this PR to fix 4 vulnerabilities in the npm dependencies of this project.

Snyk changed the following file(s):

  • website/package.json
  • website/package-lock.json

Vulnerabilities that will be fixed with an upgrade:

Issue
high severity Cross-site Request Forgery (CSRF)
SNYK-JS-AXIOS-6032459
medium severity Open Redirect
SNYK-JS-GOT-2932019
medium severity Uncontrolled Resource Consumption ('Resource Exhaustion')
SNYK-JS-TAR-6476909
high severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-TRIM-1017038

[!IMPORTANT]

  • Check the changes in this PR to ensure they won't cause issues with your project.
  • Max score is 1000. Note that the real score may have changed since the PR was raised.
  • This PR was automatically created by Snyk using the credentials of a real user.

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information: 🧐 View latest project report 📜 Customise PR templates 🛠 Adjust project settings 📚 Read about Snyk's upgrade logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Cross-site Request Forgery (CSRF) 🦉 Open Redirect 🦉 Uncontrolled Resource Consumption ('Resource Exhaustion')

[//]: # 'snyk:metadata:{"customTemplate":{"variablesUsed":[],"fieldsUsed":[]},"dependencies":[{"name":"@docusaurus/core","from":"2.4.3","to":"3.0.0"},{"name":"@docusaurus/preset-classic","from":"2.4.3","to":"3.0.0"},{"name":"@docusaurus/theme-mermaid","from":"2.4.3","to":"3.0.0"},{"name":"lerna","from":"7.4.2","to":"8.1.3"}],"env":"prod","issuesToFix":[{"exploit_maturity":"Proof of Concept","id":"SNYK-JS-AXIOS-6032459","severity":"high","title":"Cross-site Request Forgery (CSRF)"},{"exploit_maturity":"Proof of Concept","id":"SNYK-JS-AXIOS-6032459","severity":"high","title":"Cross-site Request Forgery (CSRF)"},{"exploit_maturity":"Proof of Concept","id":"SNYK-JS-AXIOS-6032459","severity":"high","title":"Cross-site Request Forgery (CSRF)"},{"exploit_maturity":"Proof of Concept","id":"SNYK-JS-AXIOS-6032459","severity":"high","title":"Cross-site Request Forgery (CSRF)"},{"exploit_maturity":"Proof of Concept","id":"SNYK-JS-AXIOS-6032459","severity":"high","title":"Cross-site Request Forgery (CSRF)"},{"exploit_maturity":"No Known Exploit","id":"SNYK-JS-GOT-2932019","severity":"medium","title":"Open Redirect"},{"exploit_maturity":"No Known Exploit","id":"SNYK-JS-GOT-2932019","severity":"medium","title":"Open Redirect"},{"exploit_maturity":"No Known Exploit","id":"SNYK-JS-GOT-2932019","severity":"medium","title":"Open Redirect"},{"exploit_maturity":"No Known Exploit","id":"SNYK-JS-GOT-2932019","severity":"medium","title":"Open Redirect"},{"exploit_maturity":"No Known Exploit","id":"SNYK-JS-GOT-2932019","severity":"medium","title":"Open Redirect"},{"exploit_maturity":"Proof of Concept","id":"SNYK-JS-TAR-6476909","severity":"medium","title":"Uncontrolled Resource Consumption ('Resource Exhaustion')"},{"exploit_maturity":"Proof of Concept","id":"SNYK-JS-TAR-6476909","severity":"medium","title":"Uncontrolled Resource Consumption ('Resource Exhaustion')"},{"exploit_maturity":"Proof of Concept","id":"SNYK-JS-TRIM-1017038","severity":"high","title":"Regular Expression Denial of Service (ReDoS)"},{"exploit_maturity":"Proof of Concept","id":"SNYK-JS-TRIM-1017038","severity":"high","title":"Regular Expression Denial of Service (ReDoS)"},{"exploit_maturity":"Proof of Concept","id":"SNYK-JS-TRIM-1017038","severity":"high","title":"Regular Expression Denial of Service (ReDoS)"},{"exploit_maturity":"Proof of Concept","id":"SNYK-JS-TRIM-1017038","severity":"high","title":"Regular Expression Denial of Service (ReDoS)"},{"exploit_maturity":"Proof of Concept","id":"SNYK-JS-TRIM-1017038","severity":"high","title":"Regular Expression Denial of Service (ReDoS)"},{"exploit_maturity":"Proof of Concept","id":"SNYK-JS-TRIM-1017038","severity":"high","title":"Regular Expression Denial of Service (ReDoS)"},{"exploit_maturity":"Proof of Concept","id":"SNYK-JS-TRIM-1017038","severity":"high","title":"Regular Expression Denial of Service (ReDoS)"},{"exploit_maturity":"Proof of Concept","id":"SNYK-JS-TRIM-1017038","severity":"high","title":"Regular Expression Denial of Service (ReDoS)"},{"exploit_maturity":"Proof of Concept","id":"SNYK-JS-TRIM-1017038","severity":"high","title":"Regular Expression Denial of Service (ReDoS)"},{"exploit_maturity":"Proof of Concept","id":"SNYK-JS-TRIM-1017038","severity":"high","title":"Regular Expression Denial of Service (ReDoS)"}],"prId":"88281b81-96d6-46da-a7c6-1f41453f229b","prPublicId":"88281b81-96d6-46da-a7c6-1f41453f229b","packageManager":"npm","priorityScoreList":[null,null,null,null],"projectPublicId":"ad4c74dc-f97a-4a6b-8c68-4c305b03e490","projectUrl":"https://app.snyk.io/org/roxane/project/ad4c74dc-f97a-4a6b-8c68-4c305b03e490?utm_source=github&utm_medium=referral&page=fix-pr","prType":"fix","templateFieldSources":{"branchName":"default","commitMessage":"default","description":"default","title":"default"},"templateVariants":[],"type":"auto","upgrade":["SNYK-JS-AXIOS-6032459","SNYK-JS-GOT-2932019","SNYK-JS-TAR-6476909","SNYK-JS-TRIM-1017038"],"vulns":["SNYK-JS-AXIOS-6032459","SNYK-JS-GOT-2932019","SNYK-JS-TAR-6476909","SNYK-JS-TRIM-1017038"],"patch":[],"isBreakingChange":true,"remediationStrategy":"vuln"}'

roxaneletourneau avatar Jul 16 '24 23:07 roxaneletourneau

Deploying taquito with  Cloudflare Pages  Cloudflare Pages

Latest commit: 44e9b5b
Status: ✅  Deploy successful!
Preview URL: https://1ce25640.taquito.pages.dev
Branch Preview URL: https://snyk-fix-67f34473deca1fd9dba.taquito.pages.dev

View logs

A new deploy preview is available on Cloudflare Pages at https://83ffff8f.taquito-test-dapp.pages.dev

github-actions[bot] avatar Jul 16 '24 23:07 github-actions[bot]

New packages have been deployed to the preview repository at https://npm.preview.tezostaquito.io/.

Published packages:

npm i @taquito/[email protected] --registry https://npm.preview.tezostaquito.io/
npm i @taquito/[email protected] --registry https://npm.preview.tezostaquito.io/
npm i @taquito/[email protected] --registry https://npm.preview.tezostaquito.io/
npm i @taquito/[email protected] --registry https://npm.preview.tezostaquito.io/
npm i @taquito/[email protected] --registry https://npm.preview.tezostaquito.io/
npm i @taquito/[email protected] --registry https://npm.preview.tezostaquito.io/
npm i @taquito/[email protected] --registry https://npm.preview.tezostaquito.io/
npm i @taquito/[email protected] --registry https://npm.preview.tezostaquito.io/
npm i @taquito/[email protected] --registry https://npm.preview.tezostaquito.io/
npm i @taquito/[email protected] --registry https://npm.preview.tezostaquito.io/
npm i @taquito/[email protected] --registry https://npm.preview.tezostaquito.io/
npm i @taquito/[email protected] --registry https://npm.preview.tezostaquito.io/
npm i @taquito/[email protected] --registry https://npm.preview.tezostaquito.io/
npm i @taquito/[email protected] --registry https://npm.preview.tezostaquito.io/
npm i @taquito/[email protected] --registry https://npm.preview.tezostaquito.io/
npm i @taquito/[email protected] --registry https://npm.preview.tezostaquito.io/
npm i @taquito/[email protected] --registry https://npm.preview.tezostaquito.io/

github-actions[bot] avatar Jul 16 '24 23:07 github-actions[bot]

duplicate from pr #3042 #3039

hui-an-yang avatar Sep 06 '24 20:09 hui-an-yang