gmcserver icon indicating copy to clipboard operation
gmcserver copied to clipboard

[Snyk] Fix for 2 vulnerabilities

Open vinceh121 opened this issue 7 months ago • 0 comments

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • gmcserver-web/package.json

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
medium severity 539/1000
Why? Has a fix available, CVSS 6.5
Information Exposure
SNYK-JS-NODEFETCH-2342118
No No Known Exploit
medium severity 520/1000
Why? Has a fix available, CVSS 5.9
Denial of Service
SNYK-JS-NODEFETCH-674311
No No Known Exploit

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: @nivo/core The new version differs by 51 commits.
  • 2675b60 v0.69.0
  • e9360be fix(build): include latest changelog when publishing
  • 93943b8 refactor(axes): rename AxisProp to SingleAxisProp
  • b5d5f0f fix(axes): update some types
  • 934a299 refactor(axes): respond to pr feedback
  • f11d034 fix(axes): create alias for axis value
  • 828656f chore(axes): exclude tsbuildinfo from package
  • 6b9af77 chore(build): update messaging in makefile
  • dfd3ef0 chore(axes): changes to support react-spring v9.1.2
  • f7fcc75 fix(axes): improve package types
  • 7d01a53 refactor(axes): convert tests to typescript
  • eb969df fix(axes): remove undefined cursor style prop from AxisTick
  • b4372cf fix(bullet): remove some ts-ignore comments
  • e706d48 feat(build): add test watch commands to makefile
  • 73f9803 feat(axes): init migration to typescript
  • 46d2ae0 feat(generators): migrate package to typescript (#1492)
  • 53b9c1c fix(deps): remove recompose
  • 97b7fc8 feat(voronoi): fix storybook
  • 9796f3f feat(voronoi): migrate package to TypeScript and remove recompose
  • c976d66 feat(d3-scale): upgrade d3-scale package
  • f69c799 feat(voronoi): remove license headers
  • 74621c0 feat(voronoi): init TypeScript setup
  • a00ef4a fix(legends): Add missing symbolBorderWidth to typings (#1431)
  • 89109d9 chore(circle-packing): fixes after rebase to master

See the full diff

Package name: @nivo/line The new version differs by 51 commits.
  • 2675b60 v0.69.0
  • e9360be fix(build): include latest changelog when publishing
  • 93943b8 refactor(axes): rename AxisProp to SingleAxisProp
  • b5d5f0f fix(axes): update some types
  • 934a299 refactor(axes): respond to pr feedback
  • f11d034 fix(axes): create alias for axis value
  • 828656f chore(axes): exclude tsbuildinfo from package
  • 6b9af77 chore(build): update messaging in makefile
  • dfd3ef0 chore(axes): changes to support react-spring v9.1.2
  • f7fcc75 fix(axes): improve package types
  • 7d01a53 refactor(axes): convert tests to typescript
  • eb969df fix(axes): remove undefined cursor style prop from AxisTick
  • b4372cf fix(bullet): remove some ts-ignore comments
  • e706d48 feat(build): add test watch commands to makefile
  • 73f9803 feat(axes): init migration to typescript
  • 46d2ae0 feat(generators): migrate package to typescript (#1492)
  • 53b9c1c fix(deps): remove recompose
  • 97b7fc8 feat(voronoi): fix storybook
  • 9796f3f feat(voronoi): migrate package to TypeScript and remove recompose
  • c976d66 feat(d3-scale): upgrade d3-scale package
  • f69c799 feat(voronoi): remove license headers
  • 74621c0 feat(voronoi): init TypeScript setup
  • a00ef4a fix(legends): Add missing symbolBorderWidth to typings (#1431)
  • 89109d9 chore(circle-packing): fixes after rebase to master

See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information: 🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Denial of Service

vinceh121 avatar Nov 27 '23 14:11 vinceh121