locales icon indicating copy to clipboard operation
locales copied to clipboard

[Snyk] Security upgrade npminstall from 3.28.1 to 6.6.2

Open fengmk2 opened this issue 1 year ago โ€ข 1 comments

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • package.json

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
medium severity 718/1000
Why? Proof of Concept exploit, Recently disclosed, Has a fix available, CVSS 6.5
Uncontrolled Resource Consumption ('Resource Exhaustion')
SNYK-JS-TAR-6476909
Yes Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: npminstall The new version differs by 121 commits.
  • 9728590 Release 6.6.2
  • 4286740 feat: update npm-related deps (#426)
  • a10e4f7 Release 6.6.1
  • 304a579 ๐Ÿ› FIX: Custom lookup on httpclient (#425)
  • 5888331 Release 6.6.0
  • f720eff feat: add dns cache (#424)
  • 20e40d7 Release 6.5.2
  • 8170ce2 fix: pick `fix parallel install from local directory (#398)` (#412) (#421)
  • 1d7fbae Release 6.5.1
  • b0e785d Release 6.5.0
  • 0d880c6 ๐Ÿ“ฆ NEW: Use urllib@3 (#407)
  • 4eb3207 Release 6.4.0
  • 91ced98 feat: save dep with tag if install with tag (#408)
  • 0432f13 Release 6.3.0
  • 3787df9 ๐Ÿ‘Œ IMPROVE: Remove mz modules deps (#405)
  • dbb3b7a Release 6.2.1
  • ce04b97 ๐Ÿ› FIX: Remove disk cache when version not found (#404)
  • dbceaee deps: Security upgrade pacote from 11.3.5 to 13.0.0 (#402)
  • d8a095d Release 6.2.0
  • dad3dcf feat: add download url and size for ShasumNotMatchError (#400)
  • f692927 ๐Ÿค– TEST: CI add Node.js 18 (#397)
  • 1364e29 ๐Ÿค– TEST: Run action on 5.x
  • fee11d6 Release 6.1.0
  • c05046a ๐Ÿ“ฆ NEW: Support override custom scripts on bug-versions (#393)

See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information: ๐Ÿง View latest project report

๐Ÿ›  Adjust project settings

๐Ÿ“š Read more about Snyk's upgrade and patch logic


Learn how to fix vulnerabilities with free interactive lessons:

๐Ÿฆ‰ Uncontrolled Resource Consumption ('Resource Exhaustion')

fengmk2 avatar Mar 24 '24 15:03 fengmk2

New and removed dependencies detected. Learn more about Socket for GitHub โ†—๏ธŽ

Package New capabilities Transitives Size Publisher
npm/[email protected] environment, filesystem, shell, unsafe Transitive: eval, network +297 19.2 MB fengmk2

๐Ÿšฎ Removed packages: npm/[email protected]

View full reportโ†—๏ธŽ

socket-security[bot] avatar Mar 24 '24 15:03 socket-security[bot]