Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Snyk] Fix for 31 vulnerabilities #64

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

Omrisnyk
Copy link
Owner

@Omrisnyk Omrisnyk commented Sep 6, 2024

snyk-top-banner

Snyk has created this PR to fix 31 vulnerabilities in the npm dependencies of this project.

Snyk changed the following file(s):

  • admin-frontend/package.json
  • admin-frontend/package-lock.json

Vulnerabilities that will be fixed with an upgrade:

Issue Score
high severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-MOMENT-2944238
  265  
high severity Prototype Pollution
SNYK-JS-LODASH-450202
  253  
high severity Prototype Pollution
SNYK-JS-LODASH-608086
  250  
high severity Code Injection
SNYK-JS-LODASH-1040724
  239  
high severity Directory Traversal
SNYK-JS-MOMENT-2440688
  190  
high severity Prototype Pollution
SNYK-JS-LODASH-567746
  189  
high severity Prototype Pollution
SNYK-JS-Y18N-1021887
  187  
high severity Prototype Pollution
SNYK-JS-LODASH-6139239
  170  
high severity Denial of Service (DoS)
SNYK-JS-WS-7266574
  169  
high severity Arbitrary Code Execution
SNYK-JS-JSYAML-174129
  166  
high severity Prototype Pollution
SNYK-JS-AJV-584908
  165  
high severity Prototype Poisoning
SNYK-JS-QS-3153490
  162  
high severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-ANSIREGEX-1583908
  159  
high severity Denial of Service (DoS)
SNYK-JS-DECODEURICOMPONENT-3149970
  159  
high severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-SEMVER-3247795
  159  
high severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-UAPARSERJS-1023599
  159  
high severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-UAPARSERJS-610226
  159  
high severity Prototype Pollution
SNYK-JS-JSONSCHEMA-1920922
  150  
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-UAPARSERJS-1072471
  146  
medium severity Prototype Pollution
SNYK-JS-MINIMIST-559764
  137  
high severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-ACORN-559469
  115  
high severity Prototype Pollution
SNYK-JS-LOADERUTILS-3043105
  115  
high severity Arbitrary Code Execution
SNYK-JS-ESLINTUTILS-460220
  107  
medium severity Information Exposure
SNYK-JS-NODEFETCH-2342118
  104  
medium severity Denial of Service
SNYK-JS-NODEFETCH-674311
  101  
medium severity Denial of Service (DoS)
SNYK-JS-NWSAPI-2841516
  87  
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-LODASH-1018905
  63  
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-PATHPARSE-1077067
  63  
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-WS-1296835
  63  
low severity Prototype Pollution
SNYK-JS-MINIMIST-2429795
  59  
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-MINIMATCH-3050818
  45  
Release notes
Package name: eslint
  • 8.46.0 - 2023-07-28

    Features

    • 8a93438 feat: require-unicode-regexp support v flag (#17402) (SUZUKI Sosuke)
    • 1a2f966 feat: no-useless-escape support v flag (#17420) (Yosuke Ota)
    • ee68d1d feat: no-empty-character-class support v flag (#17419) (Milos Djermanovic)
    • 853d32b feat: deprecate no-return-await (#17417) (Carlos Lopez)
    • d4f02e4 feat: no-control-regex support v flag (#17405) (Yosuke Ota)
    • 2a35f3e feat: prefer-named-capture-group support v flag (#17409) (Yosuke Ota)
    • 8ca8b50 feat: Better error message for flat config plugins (#17399) (Nicholas C. Zakas)
    • 509f753 feat: no-misleading-character-class support v flag (#17406) (Yosuke Ota)
    • 3caf514 feat: no-regex-spaces support v flag (#17407) (Yosuke Ota)
    • b7fad2b feat: prefer-regex-literals support v flag (#17410) (Yosuke Ota)
    • a6a3ad4 feat: no-useless-backreference support v flag (#17408) (Yosuke Ota)
    • 94954a7 feat: no-invalid-regexp support v flag (#17404) (Yosuke Ota)
    • 1af6eac feat: adds option for allowing empty object patterns as parameter (#17365) (Tanuj Kanti)
    • cf03104 feat: Improve config error messages (#17385) (Nicholas C. Zakas)

    Bug Fixes

    • 9803c7c fix: FlatESLint#getRulesMetaForResults shouldn't throw on unknown rules (#17393) (Milos Djermanovic)
    • 42faa17 fix: Update no-loop-func to not overlap with no-undef (#17358) (Matt Wilkinson)

    Documentation

    • 4d474e3 docs: update with TypeScript info (#17423) (James)
    • 091f44e docs: File extension named processor deprecation (#17362) (Matt Wilkinson)
    • 9254a6c docs: Update README (GitHub Actions Bot)
    • 6d6dc51 docs: fix overlapping of open in playground button (#17403) (Tanuj Kanti)
    • 7fc3a2c docs: Add private class features info to no-underscore-dangle (#17386) (Matt Wilkinson)
    • da73e58 docs: Migrating eslint-env configuration comments (#17390) (Francesco Trotta)
    • 80dffed docs: fix Ignoring Files section in config migration guide (#17392) (Milos Djermanovic)
    • 8a9abb7 docs: Update README (GitHub Actions Bot)
    • 7e9be4b docs: Update README (GitHub Actions Bot)
    • 0b0bbe0 docs: Update README (GitHub Actions Bot)

    Chores

    • d1eb7e4 chore: Update ecosystem dependencies (#17427) (Nicholas C. Zakas)
    • fab9e97 chore: package.json update for eslint-config-eslint release (ESLint Jenkins)
    • 6246711 chore: package.json update for @ eslint/js release (ESLint Jenkins)
    • 0aa0bc3 chore: Add PRs to triage project (#17421) (Nicholas C. Zakas)
  • 8.45.0 - 2023-07-14

    Features

    • cdd063c feat: Expose LegacyESLint in unsupported API (#17341) (Nicholas C. Zakas)
    • d34abe5 feat: fix indent rule for else-if (#17318) (Milos Djermanovic)

    Bug Fixes

    • b79b6fb fix: Fix suggestion message in no-useless-escape (#17339) (Francesco Trotta)
    • c667055 fix: provide unique fix and fix.range objects in lint messages (#17332) (Milos Djermanovic)

    Documentation

    • 89f3225 docs: add playground links to correct and incorrect code blocks (#17306) (Josh Goldberg ✨)
    • f8892b5 docs: Expand rule option schema docs (#17198) (Matt Wilkinson)
    • 8bcbf11 docs: Config Migration Guide (#17230) (Ben Perlmutter)
    • bb30908 docs: Update README (GitHub Actions Bot)
    • 84d243b docs: Update README (GitHub Actions Bot)
    • b762632 docs: Update README (GitHub Actions Bot)
    • 138c096 docs: add more prefer-destructuring examples with array destructuring (#17330) (Milos Djermanovic)
    • 1fc50a8 docs: max-len rule code and tabWidth as positional arguments (#17331) (Jesús Leganés-Combarro)

    Chores

    • 68f63d7 chore: package.json update for @ eslint/js release (ESLint Jenkins)
    • 5ca9b4d chore: update eslint-config-eslint exports (#17336) (Milos Djermanovic)
    • 7bf2e86 chore: remove unused dependencies (#17352) (Percy Ma)
    • c6f8cd0 chore: Remove defaultIgnores from FlatESLint private members (#17349) (Francesco Trotta)
    • 0052374 chore: move jsdoc settings to eslint-config-eslint (#17338) (唯然)
  • 8.44.0 - 2023-06-30

    Features

    • 1766771 feat: add es2023 and es2024 environments (#17328) (Milos Djermanovic)
    • 4c50400 feat: add ecmaVersion: 2024, regexp v flag parsing (#17324) (Milos Djermanovic)
    • 4d411e4 feat: add ternaryOperandBinaryExpressions option to no-extra-parens rule (#17270) (Percy Ma)
    • c8b1f4d feat: Move parserServices to SourceCode (#17311) (Milos Djermanovic)
    • ef6e24e feat: treat unknown nodes as having the lowest precedence (#17302) (Brad Zacher)
    • 1866e1d feat: allow flat config files to export a Promise (#17301) (Milos Djermanovic)

    Bug Fixes

    • a36bcb6 fix: no-unused-vars false positive with logical assignment operators (#17320) (Gweesin Chan)
    • 7620b89 fix: Remove no-unused-labels autofix before potential directives (#17314) (Francesco Trotta)
    • 391ed38 fix: Remove no-extra-semi autofix before potential directives (#17297) (Francesco Trotta)

    Documentation

    • 526e911 docs: resubmit pr 17115 doc changes (#17291) (唯然)
    • e1314bf docs: Integration section and tutorial (#17132) (Ben Perlmutter)
    • 19a8c5d docs: Update README (GitHub Actions Bot)

    Chores

    • 49e46ed chore: upgrade @ eslint/js@8.44.0 (#17329) (Milos Djermanovic)
    • a1cb642 chore: package.json update for @ eslint/js release (ESLint Jenkins)
    • 840a264 test: More test cases for no-case-declarations (#17315) (Elian Cordoba)
    • e6e74f9 chore: package.json update for eslint-config-eslint release (ESLint Jenkins)
    • eb3d794 chore: upgrade semver@7.5.3 (#17323) (Ziyad El Abid)
    • cf88439 chore: upgrade optionator@0.9.3 (#17319) (Milos Djermanovic)
    • 9718a97 refactor: remove unnecessary code in flat-eslint.js (#17308) (Milos Djermanovic)
    • f82e56e perf: various performance improvements (#17135) (moonlightaria)
    • da81e66 chore: update eslint-plugin-jsdoc to 46.2.5 (#17245) (唯然)
    • b991640 chore: switch eslint-config-eslint to the flat format (#17247) (唯然)
  • 8.43.0 - 2023-06-16

    Features

    • 14581ff feat: directive prologue detection and autofix condition in quotes (#17284) (Francesco Trotta)
    • e50fac3 feat: add declaration loc to message in block-scoped-var (#17252) (Milos Djermanovic)
    • 1b7faf0 feat: add skipJSXText option to no-irregular-whitespace rule (#17182) (Azat S)

    Bug Fixes

    • 5338b56 fix: normalize cwd passed to ESLint/FlatESLint constructor (#17277) (Milos Djermanovic)
    • 54383e6 fix: Remove no-extra-parens autofix for potential directives (#17022) (Francesco Trotta)

    Documentation

    • 8b855ea docs: resubmit pr17061 doc changes (#17292) (唯然)
    • 372722e docs: resubmit pr17012 doc changes (#17293) (唯然)
    • 67e7af3 docs: resubmit custom-rules doc changes (#17294) (唯然)
    • 9e3d77c docs: Resubmit Fix formatting in Custom Rules docs (#17281) (Milos Djermanovic)
    • 503647a docs: Resubmit markVariableAsUsed docs (#17280) (Nicholas C. Zakas)
    • e0cf0d8 docs: Custom rule & plugin tutorial (#17024) (Ben Perlmutter)
    • 8e51ea9 docs: resubmit no-new rule documentation (#17264) (Nitin Kumar)
    • 1b217f8 docs: resubmit Custom Processors documentation (#17265) (Nitin Kumar)
    • 428fc76 docs: resubmit Create Plugins documentation (#17268) (Nitin Kumar)
    • bdca88c docs: resubmit Configuration Files documentation (#17267) (Nitin Kumar)
    • f5c01f2 docs: resubmit Manage Issues documentation (#17266) (Nitin Kumar)
    • b199295 docs: Resubmit custom rules update docs (#17273) (Ben Perlmutter)
    • 0e9980c docs: add new omitLastInOneLineClassBody option to the semi rule (#17263) (Nitin Kumar)
    • cb2560f docs: Resubmit getScope/getDeclaredVariables docs (#17262) (Nicholas C. Zakas)
    • 85d2b30 docs: explain how to include predefined globals (#17261) (Marcus Wyatt)
    • de4d3c1 docs: update flat config default ignore patterns (#17258) (Milos Djermanovic)
    • 3912f3a docs: Improve ignores documentation (#17239) (Francesco Trotta)
    • 35e11d3 docs: fix typos and missing info (#17257) (Ed Lucas)
    • 0bc257c docs: Clarify no-div-regex rule docs (#17051) (#17255) (Francesco Trotta)
    • 788d836 docs: add references to MIT License (#17248) (Milos Djermanovic)
    • 58aab6b docs: Update README (GitHub Actions Bot)
    • 3ef5814 docs: Revert all changes after the license change (#17227) (Milos Djermanovic)
    • 03fc4aa docs: Update README (GitHub Actions Bot)

    Chores

    • 78350f6 chore: upgrade @ eslint/js@8.43.0 (#17295) (Milos Djermanovic)
    • 62bf759 chore: package.json update for @ eslint/js release (ESLint Jenkins)
    • e0a2448 chore: docs package.license ISC => MIT (#17254) (唯然)
    • 6a0196c chore: use eslint-plugin-eslint-plugin flat configs (#17204) (Milos Djermanovic)
  • 8.42.0 - 2023-06-02

    Features

    • b8448ff feat: correct no-useless-return behaviour in try statements (#16996) (Nitin Kumar)

    Bug Fixes

    • a589636 fix: Config with ignores and without files should not always apply (#17181) (Milos Djermanovic)
    • c4fad17 fix: Correct ignore message for "node_modules" subfolders (#17217) (Francesco Trotta)

    Documentation

    • 01d7142 docs: Update README (GitHub Actions Bot)
    • e5182b7 docs: Update README (GitHub Actions Bot)

    Chores

    • 6ca5b7c chore: upgrade @ eslint/js@8.42.0 (#17236) (Milos Djermanovic)
    • 67fc5e7 chore: package.json update for @ eslint/js release (ESLint Jenkins)
    • 0892412 refactor: remove Identifier listener in no-irregular-whitespace (#17235) (Milos Djermanovic)
    • f67d298 test: Add FlatESLint tests with missing config files (#17164) (Milos Djermanovic)
    • 5b68d51 chore: Fix fixedsize attribute in code path analysis DOT debug output (#17202) (Milos Djermanovic)
    • 37432f2 chore: update descriptions in key-spacing tests (#17195) (Milos Djermanovic)
  • 8.41.0 - 2023-05-19

    Features

    • 880a431 feat: change default ignore pattern to **/node_modules/ in flat config (#17184) (Milos Djermanovic)
    • 8bf5505 feat: expose shouldUseFlatConfig (

…o reduce vulnerabilities

The following vulnerabilities are fixed with an upgrade:
- https://snyk.io/vuln/SNYK-JS-MOMENT-2944238
- https://snyk.io/vuln/SNYK-JS-LODASH-450202
- https://snyk.io/vuln/SNYK-JS-LODASH-608086
- https://snyk.io/vuln/SNYK-JS-LODASH-1040724
- https://snyk.io/vuln/SNYK-JS-MOMENT-2440688
- https://snyk.io/vuln/SNYK-JS-LODASH-567746
- https://snyk.io/vuln/SNYK-JS-Y18N-1021887
- https://snyk.io/vuln/SNYK-JS-LODASH-6139239
- https://snyk.io/vuln/SNYK-JS-WS-7266574
- https://snyk.io/vuln/SNYK-JS-JSYAML-174129
- https://snyk.io/vuln/SNYK-JS-AJV-584908
- https://snyk.io/vuln/SNYK-JS-QS-3153490
- https://snyk.io/vuln/SNYK-JS-ANSIREGEX-1583908
- https://snyk.io/vuln/SNYK-JS-DECODEURICOMPONENT-3149970
- https://snyk.io/vuln/SNYK-JS-SEMVER-3247795
- https://snyk.io/vuln/SNYK-JS-UAPARSERJS-1023599
- https://snyk.io/vuln/SNYK-JS-UAPARSERJS-610226
- https://snyk.io/vuln/SNYK-JS-JSONSCHEMA-1920922
- https://snyk.io/vuln/SNYK-JS-UAPARSERJS-1072471
- https://snyk.io/vuln/SNYK-JS-MINIMIST-559764
- https://snyk.io/vuln/SNYK-JS-ACORN-559469
- https://snyk.io/vuln/SNYK-JS-LOADERUTILS-3043105
- https://snyk.io/vuln/SNYK-JS-ESLINTUTILS-460220
- https://snyk.io/vuln/SNYK-JS-NODEFETCH-2342118
- https://snyk.io/vuln/SNYK-JS-NODEFETCH-674311
- https://snyk.io/vuln/SNYK-JS-NWSAPI-2841516
- https://snyk.io/vuln/SNYK-JS-LODASH-1018905
- https://snyk.io/vuln/SNYK-JS-PATHPARSE-1077067
- https://snyk.io/vuln/SNYK-JS-WS-1296835
- https://snyk.io/vuln/SNYK-JS-MINIMIST-2429795
- https://snyk.io/vuln/SNYK-JS-MINIMATCH-3050818
@Omrisnyk
Copy link
Owner Author

Omrisnyk commented Sep 6, 2024

🎉 Snyk hasn't found any issues so far.

security/snyk check is completed. No issues were found. (View Details)

license/snyk check is completed. No issues were found. (View Details)

code/snyk check is completed. No issues were found. (View Details)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants