Skip to content

add morgan package#4

Open
nedave wants to merge 1 commit intomainfrom
ccs-feature-branch
Open

add morgan package#4
nedave wants to merge 1 commit intomainfrom
ccs-feature-branch

Conversation

@nedave
Copy link
Owner

@nedave nedave commented Jun 22, 2023

No description provided.

Copy link

@prisma-cloud-devsecops prisma-cloud-devsecops bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Prisma Cloud has found errors in this PR ⬇️

version "2.4.0"
resolved "https://registry.yarnpkg.com/bytes/-/bytes-2.4.0.tgz#7d97196f9d5baf7f6935e25985549edd2a6c2339"

bytes@~0.2.0:

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

morgan 1.0.0 / yarn.lock

Total vulnerabilities: 1

Critical: 1 High: 0 Medium: 0 Low: 0
Vulnerability IDSeverityCVSSFixed inStatus
CVE-2019-5413 CRITICAL CRITICAL 9.8 1.9.1 Open

version "2.4.0"
resolved "https://registry.yarnpkg.com/bytes/-/bytes-2.4.0.tgz#7d97196f9d5baf7f6935e25985549edd2a6c2339"

bytes@~0.2.0:

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

tough-cookie 2.3.2 / yarn.lock

Total vulnerabilities: 1

Critical: 0 High: 1 Medium: 0 Low: 0
Vulnerability IDSeverityCVSSFixed inStatus
CVE-2017-15010 HIGH HIGH 7.5 2.3.3 Open

version "2.4.0"
resolved "https://registry.yarnpkg.com/bytes/-/bytes-2.4.0.tgz#7d97196f9d5baf7f6935e25985549edd2a6c2339"

bytes@~0.2.0:

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

qs 6.3.0 / yarn.lock

Total vulnerabilities: 2

Critical: 0 High: 2 Medium: 0 Low: 0
Vulnerability IDSeverityCVSSFixed inStatus
CVE-2017-1000048 HIGH HIGH 7 6.3.2 Open
CVE-2022-24999 HIGH HIGH 7.5 6.10.3 Open

version "2.4.0"
resolved "https://registry.yarnpkg.com/bytes/-/bytes-2.4.0.tgz#7d97196f9d5baf7f6935e25985549edd2a6c2339"

bytes@~0.2.0:

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

superagent 2.3.0 / yarn.lock

Total vulnerabilities: 1

Critical: 0 High: 0 Medium: 1 Low: 0
Vulnerability IDSeverityCVSSFixed inStatus
CVE-2017-16129 MEDIUM MEDIUM 5.9 3.7.0 Open

version "2.4.0"
resolved "https://registry.yarnpkg.com/bytes/-/bytes-2.4.0.tgz#7d97196f9d5baf7f6935e25985549edd2a6c2339"

bytes@~0.2.0:

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

jsonpointer 4.0.1 / yarn.lock

Total vulnerabilities: 1

Critical: 1 High: 0 Medium: 0 Low: 0
Vulnerability IDSeverityCVSSFixed inStatus
CVE-2021-23807 CRITICAL CRITICAL 9.8 5.0.0 Open

version "2.4.0"
resolved "https://registry.yarnpkg.com/bytes/-/bytes-2.4.0.tgz#7d97196f9d5baf7f6935e25985549edd2a6c2339"

bytes@~0.2.0:

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

growl 1.9.2 / yarn.lock

Total vulnerabilities: 1

Critical: 1 High: 0 Medium: 0 Low: 0
Vulnerability IDSeverityCVSSFixed inStatus
CVE-2017-16042 CRITICAL CRITICAL 9.8 1.10.2 Open

version "2.4.0"
resolved "https://registry.yarnpkg.com/bytes/-/bytes-2.4.0.tgz#7d97196f9d5baf7f6935e25985549edd2a6c2339"

bytes@~0.2.0:

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

brace-expansion 1.1.6 / yarn.lock

Total vulnerabilities: 1

Critical: 0 High: 1 Medium: 0 Low: 0
Vulnerability IDSeverityCVSSFixed inStatus
CVE-2017-18077 HIGH HIGH 7 1.1.7 Open

version "2.4.0"
resolved "https://registry.yarnpkg.com/bytes/-/bytes-2.4.0.tgz#7d97196f9d5baf7f6935e25985549edd2a6c2339"

bytes@~0.2.0:

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

base64-url 1.3.3 / yarn.lock

Total vulnerabilities: 1

Critical: 0 High: 1 Medium: 0 Low: 0
Vulnerability IDSeverityCVSSFixed inStatus
GHSA-j4mr-9xw3-c9jx HIGH HIGH 7 2.0.0 Open

version "2.4.0"
resolved "https://registry.yarnpkg.com/bytes/-/bytes-2.4.0.tgz#7d97196f9d5baf7f6935e25985549edd2a6c2339"

bytes@~0.2.0:

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

fresh 0.3.0 / yarn.lock

Total vulnerabilities: 1

Critical: 0 High: 1 Medium: 0 Low: 0
Vulnerability IDSeverityCVSSFixed inStatus
CVE-2017-16119 HIGH HIGH 7.5 0.5.2 Open

version "2.4.0"
resolved "https://registry.yarnpkg.com/bytes/-/bytes-2.4.0.tgz#7d97196f9d5baf7f6935e25985549edd2a6c2339"

bytes@~0.2.0:

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

bintrees 1.0.1 / yarn.lock

LOW  Unknown License (NOT_FOUND)

This package use a non-SPDX, unrecognized, or private open-source license. Ensure this package is compliant.

Copy link

@prisma-cloud-devsecops prisma-cloud-devsecops bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Prisma Cloud has found errors in this PR ⬇️

version "2.4.0"
resolved "https://registry.yarnpkg.com/bytes/-/bytes-2.4.0.tgz#7d97196f9d5baf7f6935e25985549edd2a6c2339"

bytes@~0.2.0:

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

morgan 1.0.0 / yarn.lock

Total vulnerabilities: 1

Critical: 1 High: 0 Medium: 0 Low: 0
Vulnerability IDSeverityCVSSFixed inStatus
CVE-2019-5413 CRITICAL CRITICAL 9.8 1.9.1 Open

version "2.4.0"
resolved "https://registry.yarnpkg.com/bytes/-/bytes-2.4.0.tgz#7d97196f9d5baf7f6935e25985549edd2a6c2339"

bytes@~0.2.0:

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

qs 6.3.0 / yarn.lock

Total vulnerabilities: 2

Critical: 0 High: 2 Medium: 0 Low: 0
Vulnerability IDSeverityCVSSFixed inStatus
CVE-2017-1000048 HIGH HIGH 7 6.3.2 Open
CVE-2022-24999 HIGH HIGH 7.5 6.10.3 Open

version "2.4.0"
resolved "https://registry.yarnpkg.com/bytes/-/bytes-2.4.0.tgz#7d97196f9d5baf7f6935e25985549edd2a6c2339"

bytes@~0.2.0:

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

jsonpointer 4.0.1 / yarn.lock

Total vulnerabilities: 1

Critical: 1 High: 0 Medium: 0 Low: 0
Vulnerability IDSeverityCVSSFixed inStatus
CVE-2021-23807 CRITICAL CRITICAL 9.8 5.0.0 Open

version "2.4.0"
resolved "https://registry.yarnpkg.com/bytes/-/bytes-2.4.0.tgz#7d97196f9d5baf7f6935e25985549edd2a6c2339"

bytes@~0.2.0:

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

superagent 2.3.0 / yarn.lock

Total vulnerabilities: 1

Critical: 0 High: 0 Medium: 1 Low: 0
Vulnerability IDSeverityCVSSFixed inStatus
CVE-2017-16129 MEDIUM MEDIUM 5.9 3.7.0 Open

version "2.4.0"
resolved "https://registry.yarnpkg.com/bytes/-/bytes-2.4.0.tgz#7d97196f9d5baf7f6935e25985549edd2a6c2339"

bytes@~0.2.0:

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

tough-cookie 2.3.2 / yarn.lock

Total vulnerabilities: 1

Critical: 0 High: 1 Medium: 0 Low: 0
Vulnerability IDSeverityCVSSFixed inStatus
CVE-2017-15010 HIGH HIGH 7.5 2.3.3 Open

version "2.4.0"
resolved "https://registry.yarnpkg.com/bytes/-/bytes-2.4.0.tgz#7d97196f9d5baf7f6935e25985549edd2a6c2339"

bytes@~0.2.0:

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

hawk 3.1.3 / yarn.lock

Total vulnerabilities: 1

Critical: 0 High: 1 Medium: 0 Low: 0
Vulnerability IDSeverityCVSSFixed inStatus
CVE-2022-29167 HIGH HIGH 7.5 9.0.1 Open

version "2.4.0"
resolved "https://registry.yarnpkg.com/bytes/-/bytes-2.4.0.tgz#7d97196f9d5baf7f6935e25985549edd2a6c2339"

bytes@~0.2.0:

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

forwarded 0.1.0 / yarn.lock

Total vulnerabilities: 1

Critical: 0 High: 1 Medium: 0 Low: 0
Vulnerability IDSeverityCVSSFixed inStatus
CVE-2017-16118 HIGH HIGH 7.5 0.1.2 Open

version "2.4.0"
resolved "https://registry.yarnpkg.com/bytes/-/bytes-2.4.0.tgz#7d97196f9d5baf7f6935e25985549edd2a6c2339"

bytes@~0.2.0:

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

brace-expansion 1.1.6 / yarn.lock

Total vulnerabilities: 1

Critical: 0 High: 1 Medium: 0 Low: 0
Vulnerability IDSeverityCVSSFixed inStatus
CVE-2017-18077 HIGH HIGH 7 1.1.7 Open

version "2.4.0"
resolved "https://registry.yarnpkg.com/bytes/-/bytes-2.4.0.tgz#7d97196f9d5baf7f6935e25985549edd2a6c2339"

bytes@~0.2.0:

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

growl 1.9.2 / yarn.lock

Total vulnerabilities: 1

Critical: 1 High: 0 Medium: 0 Low: 0
Vulnerability IDSeverityCVSSFixed inStatus
CVE-2017-16042 CRITICAL CRITICAL 9.8 1.10.2 Open

version "2.4.0"
resolved "https://registry.yarnpkg.com/bytes/-/bytes-2.4.0.tgz#7d97196f9d5baf7f6935e25985549edd2a6c2339"

bytes@~0.2.0:

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

extend 3.0.0 / yarn.lock

Total vulnerabilities: 1

Critical: 1 High: 0 Medium: 0 Low: 0
Vulnerability IDSeverityCVSSFixed inStatus
CVE-2018-16492 CRITICAL CRITICAL 9.8 3.0.2 Open

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant