locales icon indicating copy to clipboard operation
locales copied to clipboard

[Snyk] Security upgrade npminstall from 3.28.1 to 6.5.0

Open fengmk2 opened this issue 1 year ago โ€ข 1 comments

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • package.json

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
high severity 823/1000
Why? Proof of Concept exploit, Recently disclosed, Has a fix available, CVSS 8.6
Server-side Request Forgery (SSRF)
SNYK-JS-IP-6240864
Yes Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: npminstall The new version differs by 112 commits.
  • b0e785d Release 6.5.0
  • 0d880c6 ๐Ÿ“ฆ NEW: Use urllib@3 (#407)
  • 4eb3207 Release 6.4.0
  • 91ced98 feat: save dep with tag if install with tag (#408)
  • 0432f13 Release 6.3.0
  • 3787df9 ๐Ÿ‘Œ IMPROVE: Remove mz modules deps (#405)
  • dbb3b7a Release 6.2.1
  • ce04b97 ๐Ÿ› FIX: Remove disk cache when version not found (#404)
  • dbceaee deps: Security upgrade pacote from 11.3.5 to 13.0.0 (#402)
  • d8a095d Release 6.2.0
  • dad3dcf feat: add download url and size for ShasumNotMatchError (#400)
  • f692927 ๐Ÿค– TEST: CI add Node.js 18 (#397)
  • 1364e29 ๐Ÿค– TEST: Run action on 5.x
  • fee11d6 Release 6.1.0
  • c05046a ๐Ÿ“ฆ NEW: Support override custom scripts on bug-versions (#393)
  • d760c2b chore: update contributors
  • d358658 Release 6.0.0
  • 0dc0f9e feat: upgrade node-gyp@9 to support python3 (#392)
  • 74a13b7 Release 5.7.3
  • 161d297 Revert "feat: upgrade node-gyp@8 to support python3 (#385)" (#391)
  • 9381c66 Release 5.7.2
  • 9a60297 fix: use pacote@^11 for Node.js@^10 (#390)
  • d23122b Release 5.7.1
  • b220ec3 ๐Ÿ› FIX: Reduce http request retry warning message log (#389)

See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information: ๐Ÿง View latest project report

๐Ÿ›  Adjust project settings

๐Ÿ“š Read more about Snyk's upgrade and patch logic


Learn how to fix vulnerabilities with free interactive lessons:

๐Ÿฆ‰ Server-side Request Forgery (SSRF)

fengmk2 avatar Feb 12 '24 01:02 fengmk2

New and removed dependencies detected. Learn more about Socket for GitHub โ†—๏ธŽ

Package New capabilities Transitives Size Publisher
npm/[email protected] Transitive: environment, eval, filesystem, network, shell, unsafe +287 18.9 MB

๐Ÿšฎ Removed packages: npm/[email protected]

View full reportโ†—๏ธŽ

socket-security[bot] avatar Feb 12 '24 01:02 socket-security[bot]