server
server copied to clipboard
[stable30] Fix npm audit
Audit report
This audit fix resolves 12 of the total 14 vulnerabilities found in your project.
Updated dependencies
- @jimp/core
- @jimp/custom
- @testing-library/vue
- @vue/component-compiler-utils
- @vue/test-utils
- micromatch
- node-vibrant
- phin
- postcss
- select2
- vue-loader
- vue-template-compiler
Fixed vulnerabilities
@jimp/core #
- Caused by vulnerable dependency:
- phin
- Affected versions: <=0.21.4--canary.1163.d07ed6254d130e2995d24101e93427ec091016e6.0
- Package usage:
node_modules/@jimp/core
@jimp/custom #
- Caused by vulnerable dependency:
- @jimp/core
- Affected versions: <=0.21.4--canary.1163.d07ed6254d130e2995d24101e93427ec091016e6.0
- Package usage:
node_modules/@jimp/custom
@testing-library/vue #
- Caused by vulnerable dependency:
- @vue/test-utils
- vue-template-compiler
- Affected versions: <=5.9.0
- Package usage:
node_modules/@testing-library/vue
@vue/component-compiler-utils #
- Caused by vulnerable dependency:
- postcss
- Affected versions: *
- Package usage:
node_modules/@vue/component-compiler-utils
@vue/test-utils #
- Caused by vulnerable dependency:
- vue-template-compiler
- Affected versions: <=1.3.6
- Package usage:
node_modules/@vue/test-utils
micromatch #
- Regular Expression Denial of Service (ReDoS) in micromatch
- Severity: moderate
- Reference: https://github.com/advisories/GHSA-952p-6rrq-rcjv
- Affected versions: <4.0.8
- Package usage:
node_modules/micromatch
node-vibrant #
- Caused by vulnerable dependency:
- @jimp/custom
- Affected versions: 3.1.5 - 3.1.6
- Package usage:
node_modules/node-vibrant
phin #
- phin may include sensitive headers in subsequent requests after redirect
- Severity: moderate (CVSS 4.3)
- Reference: https://github.com/advisories/GHSA-x565-32qp-m3vf
- Affected versions: <3.7.1
- Package usage:
node_modules/phin
postcss #
- PostCSS line return parsing error
- Severity: moderate (CVSS 5.3)
- Reference: https://github.com/advisories/GHSA-7fh5-64p2-3v2j
- Affected versions: <8.4.31
- Package usage:
node_modules/@vue/component-compiler-utils/node_modules/postcss
select2 #
- Improper Neutralization of Input During Web Page Generation in Select2
- Severity: moderate (CVSS 6.1)
- Reference: https://github.com/advisories/GHSA-rf66-hmqf-q3fc
- Affected versions: <4.0.6
- Package usage:
node_modules/select2
vue-loader #
- Caused by vulnerable dependency:
- @vue/component-compiler-utils
- Affected versions: 15.0.0-beta.1 - 15.11.1
- Package usage:
node_modules/vue-loader
vue-template-compiler #
- vue-template-compiler vulnerable to client-side Cross-Site Scripting (XSS)
- Severity: moderate (CVSS 4.2)
- Reference: https://github.com/advisories/GHSA-g3ch-rx76-35fx
- Affected versions: >=2.0.0
- Package usage:
node_modules/vue-template-compiler