kibana4-backup
kibana4-backup copied to clipboard
[Snyk] Fix for 3 vulnerabilities
Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.
Changes included in this PR
- Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
- package.json
Vulnerabilities that will be fixed
With an upgrade:
Severity | Priority Score (*) | Issue | Breaking Change | Exploit Maturity |
---|---|---|---|---|
![]() |
676/1000 Why? Proof of Concept exploit, Has a fix available, CVSS 7.1 |
Information Exposure SNYK-JS-REQUESTRETRY-2411026 |
Yes | Proof of Concept |
![]() |
726/1000 Why? Proof of Concept exploit, Has a fix available, CVSS 8.1 |
Command Injection SNYK-JS-SIMPLEGIT-2421199 |
Yes | Proof of Concept |
![]() |
726/1000 Why? Proof of Concept exploit, Has a fix available, CVSS 8.1 |
Command Injection SNYK-JS-SIMPLEGIT-2434306 |
Yes | Proof of Concept |
(*) Note that the real score may have changed since the PR was raised.
Commit messages
Package name: elasticdump
The new version differs by 250 commits.- f4fd0e0 6.81.0
- 90a0652 bump dependencies
- 4710c31 Update README.md
- d2f257a 6.80.1
- 1c81cb0 :bug: fixed logic error in 6e58a94
- 4f7c7b7 6.80.0
- 6e58a94 Fix bug with double // in s3 keys
- b32ed2a Add support for --awsUrlRegex to multielasticdump
- 87baf8a 6.79.4
- c0fadbe fix(iohelper): fix a bug when detecting s3 url
- cc56e09 6.79.3
- 29d19cc :bug: fixed s3 logic
- fc8a76d lint fixes
- 2799654 6.79.2
- 3c57591 :bug: fixed s3 detection logic broken
- dd3f2dc 6.79.1
- 4d09f90 fix dump of indexes with %
- 44e27b2 6.79.0
- b227f12 added s3Configs to allow setting all s3 constructor updates
- 3de7a9c 6.78.0
- abe181f docs
- ed8a202 added s3Options to allow setting all s3 options
- 2adb703 doc update
- 8a34c82 6.77.1
Package name: simple-git
The new version differs by 250 commits.- 66c903c Merge pull request #776 from steveukx/changeset-release/main
- 4fc3747 Version Packages
- 9665dee Merge pull request #775 from steveukx/snyk/clone
- 2040de6 Prevent use of `--upload-pack` as a command in `git.clone` to avoid potential accidental command execution.
- 9bf9baa Merge pull request #772 from steveukx/changeset-release/main
- 64c41db Version Packages
- 357b4de Merge pull request #771 from steveukx/feat/status-with-nulls
- ed412ef Status Summary should use null terminators to allow files with spaces in their names
- 94c2462 Merge pull request #768 from steveukx/changeset-release/main
- 9113366 Version Packages
- 372efa0 Merge pull request #767 from steveukx/feat/fix-fetch-snyk
- d119ec4 Prevent use of `--upload-pack` as a command in `git.fetch` to avoid potential accidental command execution.
- e4ff627 Merge pull request #761 from steveukx/changeset-release/main
- fcc7618 Version Packages
- 7c24bb0 Merge pull request #760 from steveukx/fix/project-readme
- 80651d5 Remove pre-publish step of copying `readme.md`, no longer required
- 0d0c198 Merge pull request #759 from steveukx/changeset-release/main
- 6838e24 Version Packages
- d53875f Merge pull request #758 from steveukx/fix/project-readme
- ac4f38f Move workspace readme into the `simple-git` package, symlink to it from the workspace
- e9f0461 Move workspace readme into the `simple-git` package, symlink to it from the workspace
- bcfa6f8 Merge pull request #756 from steveukx/changeset-release/main
- 7a29566 Version Packages
- 50a8a6b Merge pull request #755 from steveukx/release-attempt
Check the changes in this PR to ensure they won't cause issues with your project.
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.
For more information:
🧐 View latest project report
📚 Read more about Snyk's upgrade and patch logic
Learn how to fix vulnerabilities with free interactive lessons:
🦉 Learn about vulnerability in an interactive lesson of Snyk Learn.