Skip to content

[Snyk] Fix for 3 vulnerabilities - #153

Open
snyk-bot wants to merge 1 commit into
masterfrom
snyk-fix-0dd5b0ed4533653dbc7b9bdc41237080
Open

snyk-bot wants to merge 1 commit into
masterfrom
snyk-fix-0dd5b0ed4533653dbc7b9bdc41237080

Conversation

@snyk-bot

Copy link
Copy Markdown

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • package.json
    • package-lock.json

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
high severity 768/1000
Why? Proof of Concept exploit, Recently disclosed, Has a fix available, CVSS 7.5
Regular Expression Denial of Service (ReDoS)
SNYK-JS-AXIOS-1579269
Yes Proof of Concept
high severity 696/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
Prototype Pollution
SNYK-JS-GRPC-598671
Yes Proof of Concept
medium severity 475/1000
Why? Has a fix available, CVSS 5
Prototype Pollution
SNYK-JS-HAPIHOEK-548452
Yes No Known Exploit

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: @mojaloop/central-ledger The new version differs by 141 commits.
  • 6914dad chore(release): 13.10.0 [skip ci]
  • 2b1ecab feat(2151): helm-release-v12.1.0 (#844)
  • cecdcff chore(release): 13.9.0 [skip ci]
  • 02fa819 feat(2151): helm-release-v12.1.0 (#843)
  • 0680e4a chore(release): 13.8.0 [skip ci]
  • 459c9e0 feat(2151): helm-release-v12.1.0 (#842)
  • f9f2834 chore(release): 13.6.0 [skip ci]
  • 605177a feat(#2123): default settlement model added (#839)
  • 2a47f61 chore(release): 13.4.0 [skip ci]
  • 233785e feat: add services endpoint seeds (#838)
  • 0b6c567 chore(release): 13.3.0 [skip ci]
  • de5077a feat(db migrations): fix subid db (#836)
  • 182a591 chore(deps): bump djv from 2.1.2 to 2.1.4 (#833)
  • 32346e5 fix(security): Bump y18n from 3.2.1 to 3.2.2 (#830)
  • 16a75af fix: package.json & package-lock.json to reduce vulnerabilities (#829)
  • a3e17c4 chore(release): 13.2.6 [skip ci]
  • 6cb311a chore: add patch consentRequest and put cr error endpoints (#828)
  • e45a71b chore(release): 13.2.5 [skip ci]
  • 2bb426d fix: #1977 timeout enumeration for cron job fixed (#824)
  • eda654b chore(release): 13.2.4 [skip ci]
  • 1c692ab [Security] Bump urijs from 1.19.5 to 1.19.6 (#825)
  • 33c53fd chore(release): 13.2.3 [skip ci]
  • 9e4d017 chore: add accounts callback endpoints (#822)
  • 3a4ff95 chore(release): 13.2.2 [skip ci]

See the full diff

Package name: @mojaloop/central-services-shared The new version differs by 107 commits.

See the full diff

Package name: @now-ims/hapi-now-auth The new version differs by 2 commits.

See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant