Skip to content

[Snyk] Fix for 1 vulnerabilities#41

Open
MaxMood96 wants to merge 1 commit intomasterfrom
snyk-fix-a68227a54a78201335ef794454cfe9a7
Open

[Snyk] Fix for 1 vulnerabilities#41
MaxMood96 wants to merge 1 commit intomasterfrom
snyk-fix-a68227a54a78201335ef794454cfe9a7

Conversation

@MaxMood96
Copy link
Copy Markdown

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • package.json
⚠️ Warning
Failed to update the package-lock.json, please update manually before merging.

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
critical severity 858/1000
Why? Proof of Concept exploit, Recently disclosed, Has a fix available, CVSS 9.3
Authentication Bypass
SNYK-JS-HAWK-6969142
Yes Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: less The new version differs by 127 commits.
  • b873737 Merge pull request #3177 from Kartoffelsalat/master
  • bd2a93f chore(package): update request to 2.83.0
  • 3699921 Merge pull request #3170 from thorn0/patch-1
  • 6985541 Having `inline` and `less` imports of the same name lead to a race condition
  • 2f1386f Merge pull request #3168 from matthew-dean/master
  • 4272871 Fixes #3116 - lessc not loading plugins in 3.0
  • ba5ad9c Point badges at master branch
  • 4962988 Update CHANGELOG.md
  • 12fe0c6 Update README.md
  • 45d06b9 Merge pull request #3163 from matthew-dean/master
  • 9590b7b Add dist files
  • 0b6536b Merge branch '3.x'
  • a48c24c calc() fix - fixes #974 (partially #1880)
  • 367b46a Merge pull request #3161 from matthew-dean/3.x
  • 4508495 Remove legacy upgrade
  • 2a4a63a Update CHANGELOG.md with 3.x list
  • bb6da28 Update README.md
  • f80a021 Merge pull request #3159 from matthew-dean/3.x
  • 8b4524f Bump to 3.0.0-RC.1
  • d30e3a6 Merge pull request #3150 from anthony-redFox/3.x
  • 0b7c81c Removed install npm 2 version for appveyor. It was hotfix for old node version.
  • 5d230dd Drop node 0.10 and 0.12 and added node 9 matrix testing
  • 385da8f Update stale.yml
  • d384779 Create stale.yml

See the full diff

Package name: npm The new version differs by 250 commits.
  • c62d0ea 5.10.0
  • 9edd48e docs: update changelog for npm@5.10.0
  • e33bc08 audit: Timeout audit requests eventually
  • 9cb9102 5.10.0-next.1
  • dab8d6d update AUTHORS
  • ba6f620 doc: update changelog for npm@5.10.0-next.1
  • be01b7d test: Change bad url in test in anticipation of aliasing
  • 74bcdb8 update: Add parens to clarify order of operations when defaulting where
  • 3232699 deps: Fix regexp used to cleanup from fields
  • fb99f75 travis: Add node v10
  • d6187a9 mailmap: Update with real names
  • 1822379 audit: Only report audit as being unsupported on 404 and >= 500
  • 35de046 docs: describe what colors in outdated mean
  • e0235eb docs: add from field back into git dependencies
  • fb7efac makefile: call cache clean with --force
  • cf09066 audit: Refuse to run in global mode
  • bc3fc55 audit: Verify lockfile integrity before running
  • 7d43ddf audit: Exit with non-zero when vulnerabilities are found
  • 113e1a3 inflate-shrinkwrap: Infer versions from tarballs to self heal
  • 36f9984 shrinkwrap: Prefer computed resolved from dep tree
  • aadbf3f audit: Include session and scope in requests
  • f9804b1 cmd-list: How else am I supposed to deploy my urns?
  • dac6f9b cmd-list: sit booboo, cit
  • a6e2f12 audit: Make sure we hide stream errors on background audit submissions

See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic


Note: This is a default PR template raised by Snyk. Find out more about how you can customise Snyk PRs in our documentation.

Learn how to fix vulnerabilities with free interactive lessons:

🦉 Authentication Bypass

The following vulnerabilities are fixed with an upgrade:
- https://snyk.io/vuln/SNYK-JS-HAWK-6969142
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants