lad
lad copied to clipboard
[Snyk] Fix for 7 vulnerabilities
Snyk has created this PR to fix 7 vulnerabilities in the yarn dependencies of this project.
Snyk changed the following file(s):
-
template/package.json
-
template/yarn.lock
Note for zero-installs users
If you are using the Yarn feature zero-installs that was introduced in Yarn V2, note that this PR does not update the .yarn/cache/
directory meaning this code cannot be pulled and immediately developed on as one would expect for a zero-install project - you will need to run yarn
to update the contents of the ./yarn/cache
directory.
If you are not using zero-install you can ignore this as your flow should likely be unchanged.
Vulnerabilities that will be fixed with an upgrade:
Issue | Score | |
---|---|---|
![]() |
Prototype Pollution SNYK-JS-PROTOBUFJS-5756498 |
751 |
![]() |
Prototype Pollution SNYK-JS-PROTOBUFJS-2441248 |
731 |
![]() |
Improper Control of Generation of Code ('Code Injection') SNYK-JS-PUGCODEGEN-7086056 |
696 |
![]() |
Regular Expression Denial of Service (ReDoS) SNYK-JS-SEMVER-3247795 |
696 |
![]() |
Improper Input Validation SNYK-JS-FOLLOWREDIRECTS-6141137 |
686 |
![]() |
Information Exposure SNYK-JS-FOLLOWREDIRECTS-6444610 |
646 |
![]() |
Prototype Pollution SNYK-JS-UNDERSCOREDEEP-2936792 |
624 |
[!IMPORTANT]
- Check the changes in this PR to ensure they won't cause issues with your project.
- Max score is 1000. Note that the real score may have changed since the PR was raised.
- This PR was automatically created by Snyk using the credentials of a real user.
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.
For more information:
🧐 View latest project report
📜 Customise PR templates
🛠 Adjust project settings
📚 Read about Snyk's upgrade logic
Learn how to fix vulnerabilities with free interactive lessons:
🦉 Improper Input Validation 🦉 Prototype Pollution 🦉 Improper Control of Generation of Code ('Code Injection') 🦉 More lessons are available in Snyk Learn
[//]: # 'snyk:metadata:{"customTemplate":{"variablesUsed":[],"fieldsUsed":[]},"dependencies":[{"name":"@ladjs/i18n","from":"7.2.6","to":"8.0.0"},{"name":"@slack/web-api","from":"6.7.1","to":"6.12.1"},{"name":"cabin","from":"9.1.2","to":"11.0.0"},{"name":"mandarin","from":"4.2.0","to":"5.0.2"},{"name":"pug","from":"3.0.2","to":"3.0.3"}],"env":"prod","issuesToFix":[{"exploit_maturity":"Proof of Concept","id":"SNYK-JS-FOLLOWREDIRECTS-6141137","priority_score":686,"priority_score_factors":[{"type":"exploit","label":"Proof of Concept","score":107},{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"7.3","score":365},{"type":"scoreVersion","label":"v1","score":1}],"severity":"high","title":"Improper Input Validation"},{"exploit_maturity":"Proof of Concept","id":"SNYK-JS-FOLLOWREDIRECTS-6444610","priority_score":646,"priority_score_factors":[{"type":"exploit","label":"Proof of Concept","score":107},{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"6.5","score":325},{"type":"scoreVersion","label":"v1","score":1}],"severity":"medium","title":"Information Exposure"},{"exploit_maturity":"Proof of Concept","id":"SNYK-JS-PROTOBUFJS-2441248","priority_score":731,"priority_score_factors":[{"type":"exploit","label":"Proof of Concept","score":107},{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"8.2","score":410},{"type":"scoreVersion","label":"v1","score":1}],"severity":"high","title":"Prototype Pollution"},{"exploit_maturity":"Proof of Concept","id":"SNYK-JS-PROTOBUFJS-5756498","priority_score":751,"priority_score_factors":[{"type":"exploit","label":"Proof of Concept","score":107},{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"8.6","score":430},{"type":"scoreVersion","label":"v1","score":1}],"severity":"high","title":"Prototype Pollution"},{"exploit_maturity":"Proof of Concept","id":"SNYK-JS-PUGCODEGEN-7086056","priority_score":696,"priority_score_factors":[{"type":"exploit","label":"Proof of Concept","score":107},{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"7.5","score":375},{"type":"scoreVersion","label":"v1","score":1}],"severity":"high","title":"Improper Control of Generation of Code ('Code Injection')"},{"exploit_maturity":"Proof of Concept","id":"SNYK-JS-SEMVER-3247795","priority_score":696,"priority_score_factors":[{"type":"exploit","label":"Proof of Concept","score":107},{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"7.5","score":375},{"type":"scoreVersion","label":"v1","score":1}],"severity":"high","title":"Regular Expression Denial of Service (ReDoS)"},{"exploit_maturity":"Proof of Concept","id":"SNYK-JS-SEMVER-3247795","priority_score":696,"priority_score_factors":[{"type":"exploit","label":"Proof of Concept","score":107},{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"7.5","score":375},{"type":"scoreVersion","label":"v1","score":1}],"severity":"high","title":"Regular Expression Denial of Service (ReDoS)"},{"exploit_maturity":"No Known Exploit","id":"SNYK-JS-UNDERSCOREDEEP-2936792","priority_score":624,"priority_score_factors":[{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"8.2","score":410},{"type":"scoreVersion","label":"v1","score":1}],"severity":"high","title":"Prototype Pollution"}],"prId":"00fd875c-fcad-43a1-8ae5-e73583fa843b","prPublicId":"00fd875c-fcad-43a1-8ae5-e73583fa843b","packageManager":"yarn","priorityScoreList":[686,646,731,751,696,696,624],"projectPublicId":"deecffb5-5423-445c-8826-70aff63668ac","projectUrl":"https://app.snyk.io/org/titanism/project/deecffb5-5423-445c-8826-70aff63668ac?utm_source=github&utm_medium=referral&page=fix-pr","prType":"fix","templateFieldSources":{"branchName":"default","commitMessage":"default","description":"default","title":"default"},"templateVariants":["priorityScore"],"type":"auto","upgrade":["SNYK-JS-FOLLOWREDIRECTS-6141137","SNYK-JS-FOLLOWREDIRECTS-6444610","SNYK-JS-PROTOBUFJS-2441248","SNYK-JS-PROTOBUFJS-5756498","SNYK-JS-PUGCODEGEN-7086056","SNYK-JS-SEMVER-3247795","SNYK-JS-UNDERSCOREDEEP-2936792"],"vulns":["SNYK-JS-FOLLOWREDIRECTS-6141137","SNYK-JS-FOLLOWREDIRECTS-6444610","SNYK-JS-PROTOBUFJS-2441248","SNYK-JS-PROTOBUFJS-5756498","SNYK-JS-PUGCODEGEN-7086056","SNYK-JS-SEMVER-3247795","SNYK-JS-UNDERSCOREDEEP-2936792"],"patch":[],"isBreakingChange":true,"remediationStrategy":"vuln"}'