Skip to content

Update yarn.lock#17

Open
try-panwiac wants to merge 1 commit intomasterfrom
try-panwiac-patch-4
Open

Update yarn.lock#17
try-panwiac wants to merge 1 commit intomasterfrom
try-panwiac-patch-4

Conversation

@try-panwiac
Copy link
Owner

No description provided.

Copy link

@prisma-cloud-devsecops prisma-cloud-devsecops bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Prisma Cloud has found errors in this PR ⬇️

resolved "https://registry.yarnpkg.com/argparse/-/argparse-1.0.9.tgz#73d83bc263f86e97f8cc4f6bae1b0e90a7d22c86"
dependencies:
sprintf-js "~1.0.2"
sprintf-js "~1.0.2"

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

express 4.14.0 / yarn.lock

Total vulnerabilities: 1

Critical: 0High: 1Medium: 0Low: 0
Vulnerability ID Severity CVSSFixed in Status
CVE-2022-24999 HIGH HIGH74.17.3Open

resolved "https://registry.yarnpkg.com/argparse/-/argparse-1.0.9.tgz#73d83bc263f86e97f8cc4f6bae1b0e90a7d22c86"
dependencies:
sprintf-js "~1.0.2"
sprintf-js "~1.0.2"

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

brace-expansion 1.1.6 / yarn.lock

Total vulnerabilities: 1

Critical: 0High: 1Medium: 0Low: 0
Vulnerability ID Severity CVSSFixed in Status
CVE-2017-18077 HIGH HIGH71.1.7Open

resolved "https://registry.yarnpkg.com/argparse/-/argparse-1.0.9.tgz#73d83bc263f86e97f8cc4f6bae1b0e90a7d22c86"
dependencies:
sprintf-js "~1.0.2"
sprintf-js "~1.0.2"

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

fresh 0.3.0 / yarn.lock

Total vulnerabilities: 1

Critical: 0High: 1Medium: 0Low: 0
Vulnerability ID Severity CVSSFixed in Status
CVE-2017-16119 HIGH HIGH7.50.5.2Open

resolved "https://registry.yarnpkg.com/argparse/-/argparse-1.0.9.tgz#73d83bc263f86e97f8cc4f6bae1b0e90a7d22c86"
dependencies:
sprintf-js "~1.0.2"
sprintf-js "~1.0.2"

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

hawk 3.1.3 / yarn.lock

Total vulnerabilities: 1

Critical: 0High: 1Medium: 0Low: 0
Vulnerability ID Severity CVSSFixed in Status
CVE-2022-29167 HIGH HIGH7.59.0.1Open

resolved "https://registry.yarnpkg.com/argparse/-/argparse-1.0.9.tgz#73d83bc263f86e97f8cc4f6bae1b0e90a7d22c86"
dependencies:
sprintf-js "~1.0.2"
sprintf-js "~1.0.2"

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

base64-url 1.3.3 / yarn.lock

Total vulnerabilities: 1

Critical: 0High: 1Medium: 0Low: 0
Vulnerability ID Severity CVSSFixed in Status
GHSA-j4mr-9xw3-c9jx HIGH HIGH72.0.0Open

resolved "https://registry.yarnpkg.com/argparse/-/argparse-1.0.9.tgz#73d83bc263f86e97f8cc4f6bae1b0e90a7d22c86"
dependencies:
sprintf-js "~1.0.2"
sprintf-js "~1.0.2"

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

json-schema 0.2.3 / yarn.lock

Total vulnerabilities: 1

Critical: 1High: 0Medium: 0Low: 0
Vulnerability ID Severity CVSSFixed in Status
CVE-2021-3918 CRITICAL CRITICAL90.4.0Open

resolved "https://registry.yarnpkg.com/argparse/-/argparse-1.0.9.tgz#73d83bc263f86e97f8cc4f6bae1b0e90a7d22c86"
dependencies:
sprintf-js "~1.0.2"
sprintf-js "~1.0.2"

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

ajv 4.11.8 / yarn.lock

Total vulnerabilities: 1

Critical: 0High: 0Medium: 0Low: 1
Vulnerability ID Severity CVSSFixed in Status
CVE-2020-15366 LOW LOW46.12.3Open

resolved "https://registry.yarnpkg.com/argparse/-/argparse-1.0.9.tgz#73d83bc263f86e97f8cc4f6bae1b0e90a7d22c86"
dependencies:
sprintf-js "~1.0.2"
sprintf-js "~1.0.2"

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

debug 2.2.0 / yarn.lock

Total vulnerabilities: 2

Critical: 0High: 1Medium: 1Low: 0
Vulnerability ID Severity CVSSFixed in Status
CVE-2017-20165 HIGH HIGH7.53.1.0Open
CVE-2017-16137 MEDIUM MEDIUM5.32.6.9Open

resolved "https://registry.yarnpkg.com/argparse/-/argparse-1.0.9.tgz#73d83bc263f86e97f8cc4f6bae1b0e90a7d22c86"
dependencies:
sprintf-js "~1.0.2"
sprintf-js "~1.0.2"
Copy link

@prisma-cloud-devsecops prisma-cloud-devsecops bot Jan 16, 2023

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

handlebars 4.5.1 / yarn.lock

Total vulnerabilities: 6

Critical: 2High: 4Medium: 0Low: 0
Vulnerability ID Severity CVSSFixed in Status
CVE-2021-23369 CRITICAL CRITICAL9.84.7.7Open
CVE-2021-23383 CRITICAL CRITICAL9.84.7.7Open
CVE-2019-20920 HIGH HIGH8.14.5.3Open
GHSA-2cf5-4w76-r9qv HIGH HIGH74.5.2Open
GHSA-g9r4-xpmj-mj65 HIGH HIGH74.5.3Open
GHSA-q2c6-c6pm-g3gh HIGH HIGH74.5.3Open

resolved "https://registry.yarnpkg.com/argparse/-/argparse-1.0.9.tgz#73d83bc263f86e97f8cc4f6bae1b0e90a7d22c86"
dependencies:
sprintf-js "~1.0.2"
sprintf-js "~1.0.2"

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

diff 1.4.0 / yarn.lock

Total vulnerabilities: 1

Critical: 0High: 1Medium: 0Low: 0
Vulnerability ID Severity CVSSFixed in Status
GHSA-h6ch-v84p-w6p9 HIGH HIGH73.5.0Open

resolved "https://registry.yarnpkg.com/argparse/-/argparse-1.0.9.tgz#73d83bc263f86e97f8cc4f6bae1b0e90a7d22c86"
dependencies:
sprintf-js "~1.0.2"
sprintf-js "~1.0.2"

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

bintrees 1.0.1 / yarn.lock

LOW  Unknown License (NOT_FOUND)

This package use a non-SPDX, unrecognized, or private open-source license. Ensure this package is compliant.

resolved "https://registry.yarnpkg.com/argparse/-/argparse-1.0.9.tgz#73d83bc263f86e97f8cc4f6bae1b0e90a7d22c86"
dependencies:
sprintf-js "~1.0.2"
sprintf-js "~1.0.2"

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

bytes 0.2.1 / yarn.lock

LOW  Unknown License (NOT_FOUND)

This package use a non-SPDX, unrecognized, or private open-source license. Ensure this package is compliant.

resolved "https://registry.yarnpkg.com/argparse/-/argparse-1.0.9.tgz#73d83bc263f86e97f8cc4f6bae1b0e90a7d22c86"
dependencies:
sprintf-js "~1.0.2"
sprintf-js "~1.0.2"

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

chai-http 3.0.0 / yarn.lock

LOW  Unknown License (NOT_FOUND)

This package use a non-SPDX, unrecognized, or private open-source license. Ensure this package is compliant.

resolved "https://registry.yarnpkg.com/argparse/-/argparse-1.0.9.tgz#73d83bc263f86e97f8cc4f6bae1b0e90a7d22c86"
dependencies:
sprintf-js "~1.0.2"
sprintf-js "~1.0.2"

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

extsprintf 1.0.2 / yarn.lock

LOW  Unknown License (NOT_FOUND)

This package use a non-SPDX, unrecognized, or private open-source license. Ensure this package is compliant.

resolved "https://registry.yarnpkg.com/argparse/-/argparse-1.0.9.tgz#73d83bc263f86e97f8cc4f6bae1b0e90a7d22c86"
dependencies:
sprintf-js "~1.0.2"
sprintf-js "~1.0.2"

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

formatio 1.1.1 / yarn.lock

LOW  Unknown License (NOT_FOUND)

This package use a non-SPDX, unrecognized, or private open-source license. Ensure this package is compliant.

resolved "https://registry.yarnpkg.com/argparse/-/argparse-1.0.9.tgz#73d83bc263f86e97f8cc4f6bae1b0e90a7d22c86"
dependencies:
sprintf-js "~1.0.2"
sprintf-js "~1.0.2"

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

formidable 1.0.17 / yarn.lock

LOW  Unknown License (NOT_FOUND)

This package use a non-SPDX, unrecognized, or private open-source license. Ensure this package is compliant.

resolved "https://registry.yarnpkg.com/argparse/-/argparse-1.0.9.tgz#73d83bc263f86e97f8cc4f6bae1b0e90a7d22c86"
dependencies:
sprintf-js "~1.0.2"
sprintf-js "~1.0.2"

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

jsonify 0.0.1 / yarn.lock

LOW  Unknown License (Public Domain)

This package use a non-SPDX, unrecognized, or private open-source license. Ensure this package is compliant.

resolved "https://registry.yarnpkg.com/argparse/-/argparse-1.0.9.tgz#73d83bc263f86e97f8cc4f6bae1b0e90a7d22c86"
dependencies:
sprintf-js "~1.0.2"
sprintf-js "~1.0.2"

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

ms 0.7.1 / yarn.lock

LOW  Unknown License (NOT_FOUND)

This package use a non-SPDX, unrecognized, or private open-source license. Ensure this package is compliant.

resolved "https://registry.yarnpkg.com/argparse/-/argparse-1.0.9.tgz#73d83bc263f86e97f8cc4f6bae1b0e90a7d22c86"
dependencies:
sprintf-js "~1.0.2"
sprintf-js "~1.0.2"

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

optimist 0.6.1 / yarn.lock

MEDIUM  Noncompliant License (X11)

This package contains a license that is not OSI-approved.

resolved "https://registry.yarnpkg.com/argparse/-/argparse-1.0.9.tgz#73d83bc263f86e97f8cc4f6bae1b0e90a7d22c86"
dependencies:
sprintf-js "~1.0.2"
sprintf-js "~1.0.2"

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

samsam 1.1.2 / yarn.lock

LOW  Unknown License (NOT_FOUND)

This package use a non-SPDX, unrecognized, or private open-source license. Ensure this package is compliant.

resolved "https://registry.yarnpkg.com/argparse/-/argparse-1.0.9.tgz#73d83bc263f86e97f8cc4f6bae1b0e90a7d22c86"
dependencies:
sprintf-js "~1.0.2"
sprintf-js "~1.0.2"

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

verror 1.3.6 / yarn.lock

LOW  Unknown License (NOT_FOUND)

This package use a non-SPDX, unrecognized, or private open-source license. Ensure this package is compliant.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant