Skip to content

yarn morgan#8

Open
try-panwiac wants to merge 1 commit intomasterfrom
pr-yarn
Open

yarn morgan#8
try-panwiac wants to merge 1 commit intomasterfrom
pr-yarn

Conversation

@try-panwiac
Copy link
Owner

No description provided.

Copy link

@prisma-cloud-devsecops prisma-cloud-devsecops bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Prisma Cloud has found errors in this PR ⬇️

"dependencies": {
"async": "^1.5.2",
"body-parser": "^1.15.1",
"connect-redis": "^3.2.0",

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

morgan 1.0.0 / package.json

Total vulnerabilities: 1

Critical: 1High: 0Medium: 0Low: 0
Vulnerability ID Severity CVSSFixed in
CVE-2019-5413 CRITICAL9.81.9.1

version "1.0.4"
resolved "https://registry.yarnpkg.com/basic-auth/-/basic-auth-1.0.4.tgz#030935b01de7c9b94a824b29f3fccb750d3a5290"

bcrypt-pbkdf@^1.0.0:

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

tunnel-agent 0.4.3 / yarn.lock

Total vulnerabilities: 1

Critical: 0High: 0Medium: 0Low: 1
Vulnerability ID Severity CVSSFixed in
GHSA-xc7v-wxcw-j472 LOW40.6.0

version "1.0.4"
resolved "https://registry.yarnpkg.com/basic-auth/-/basic-auth-1.0.4.tgz#030935b01de7c9b94a824b29f3fccb750d3a5290"

bcrypt-pbkdf@^1.0.0:

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

mocha 3.2.0 / yarn.lock

Total vulnerabilities: 2

Critical: 0High: 1Medium: 1Low: 0
Vulnerability ID Severity CVSSFixed in
PRISMA-2022-0230 HIGH7.5-
PRISMA-2022-0335 MEDIUM5.3-

version "1.0.4"
resolved "https://registry.yarnpkg.com/basic-auth/-/basic-auth-1.0.4.tgz#030935b01de7c9b94a824b29f3fccb750d3a5290"

bcrypt-pbkdf@^1.0.0:

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

qs 6.2.0 / yarn.lock

Total vulnerabilities: 2

Critical: 0High: 1Medium: 1Low: 0
Vulnerability ID Severity CVSSFixed in
CVE-2017-1000048 HIGH76.2.3
PRISMA-2022-0087 MEDIUM5.96.3.1

version "1.0.4"
resolved "https://registry.yarnpkg.com/basic-auth/-/basic-auth-1.0.4.tgz#030935b01de7c9b94a824b29f3fccb750d3a5290"

bcrypt-pbkdf@^1.0.0:

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

minimist 0.0.10 / yarn.lock

Total vulnerabilities: 2

Critical: 1High: 0Medium: 1Low: 0
Vulnerability ID Severity CVSSFixed in
CVE-2021-44906 CRITICAL9.81.2.6
CVE-2020-7598 MEDIUM5.61.2.2

version "1.0.4"
resolved "https://registry.yarnpkg.com/basic-auth/-/basic-auth-1.0.4.tgz#030935b01de7c9b94a824b29f3fccb750d3a5290"

bcrypt-pbkdf@^1.0.0:

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

growl 1.9.2 / yarn.lock

Total vulnerabilities: 1

Critical: 1High: 0Medium: 0Low: 0
Vulnerability ID Severity CVSSFixed in
CVE-2017-16042 CRITICAL9.81.10.2

version "1.0.4"
resolved "https://registry.yarnpkg.com/basic-auth/-/basic-auth-1.0.4.tgz#030935b01de7c9b94a824b29f3fccb750d3a5290"

bcrypt-pbkdf@^1.0.0:

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

bson 1.0.9 / yarn.lock

Total vulnerabilities: 2

Critical: 1High: 0Medium: 0Low: 1
Vulnerability ID Severity CVSSFixed in
CVE-2020-7610 CRITICAL9.81.1.4
CVE-2019-2391 LOW41.1.4

version "1.0.4"
resolved "https://registry.yarnpkg.com/basic-auth/-/basic-auth-1.0.4.tgz#030935b01de7c9b94a824b29f3fccb750d3a5290"

bcrypt-pbkdf@^1.0.0:
Copy link

@prisma-cloud-devsecops prisma-cloud-devsecops bot Oct 3, 2022

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

hoek 2.16.3 / yarn.lock

Total vulnerabilities: 2

Critical: 0High: 2Medium: 0Low: 0
Vulnerability ID Severity CVSSFixed in
CVE-2018-3728 HIGH8.84.2.0
CVE-2020-36604 HIGH8.18.5.1

version "1.0.4"
resolved "https://registry.yarnpkg.com/basic-auth/-/basic-auth-1.0.4.tgz#030935b01de7c9b94a824b29f3fccb750d3a5290"

bcrypt-pbkdf@^1.0.0:

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

debug 2.2.0 / yarn.lock

Total vulnerabilities: 1

Critical: 0High: 0Medium: 1Low: 0
Vulnerability ID Severity CVSSFixed in
CVE-2017-16137 MEDIUM5.32.6.9

version "1.0.4"
resolved "https://registry.yarnpkg.com/basic-auth/-/basic-auth-1.0.4.tgz#030935b01de7c9b94a824b29f3fccb750d3a5290"

bcrypt-pbkdf@^1.0.0:
Copy link

@prisma-cloud-devsecops prisma-cloud-devsecops bot Oct 3, 2022

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

handlebars 4.5.1 / yarn.lock

Total vulnerabilities: 6

Critical: 2High: 4Medium: 0Low: 0
Vulnerability ID Severity CVSSFixed in
CVE-2021-23369 CRITICAL9.84.7.7
CVE-2021-23383 CRITICAL9.84.7.7
CVE-2019-20920 HIGH8.14.5.3
GHSA-2cf5-4w76-r9qv HIGH74.5.2
GHSA-g9r4-xpmj-mj65 HIGH74.5.3
GHSA-q2c6-c6pm-g3gh HIGH74.5.3

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant