Update package.json#2019
Open
edk1kamel wants to merge 1 commit intoyui:dev-masterfrom
Open
Conversation
Please upgrade dependency to help address the following: # Run npm install request@2.88.0 to resolve 3 vulnerabilities Moderate Remote Memory Exposure Package request Dependency of request Path request More info https://npmjs.com/advisories/309 Moderate Regular Expression Denial of Service Package mime Dependency of request Path request > form-data > mime More info https://npmjs.com/advisories/535 Moderate Memory Exposure Package tunnel-agent Dependency of request Path request > tunnel-agent More info https://npmjs.com/advisories/598 Manual Review Some vulnerabilities require your attention to resolve Visit https://go.npm.me/audit-guide for additional guidance Moderate Regular Expression Denial of Service Package hawk Patched in >=3.1.3 < 4.0.0 || >=4.1.1 Dependency of request Path request > hawk More info https://npmjs.com/advisories/77 Moderate Prototype Pollution Package hoek Patched in > 4.2.0 < 5.0.0 || >= 5.0.3 Dependency of request Path request > hawk > boom > hoek More info https://npmjs.com/advisories/566 Moderate Prototype Pollution Package hoek Patched in > 4.2.0 < 5.0.0 || >= 5.0.3 Dependency of request Path request > hawk > cryptiles > boom > hoek More info https://npmjs.com/advisories/566 Moderate Prototype Pollution Package hoek Patched in > 4.2.0 < 5.0.0 || >= 5.0.3 Dependency of request Path request > hawk > hoek More info https://npmjs.com/advisories/566 Moderate Prototype Pollution Package hoek Patched in > 4.2.0 < 5.0.0 || >= 5.0.3 Dependency of request Path request > hawk > sntp > hoek More info https://npmjs.com/advisories/566 found 8 moderate severity vulnerabilities in 32 scanned packages:1
|
Thank you for submitting this pull request, however I do not see a valid CLA on file for you. Before we can merge this request please visit https://yahoocla.herokuapp.com/ and agree to the terms. Thanks! 😄 |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Please upgrade dependency to help address the following:
Run npm install request@2.88.0 to resolve 3 vulnerabilities
Moderate Remote Memory Exposure
Package request
Dependency of request
Path request
More info https://npmjs.com/advisories/309
Moderate Regular Expression Denial of Service
Package mime
Dependency of request
Path request > form-data > mime
More info https://npmjs.com/advisories/535
Moderate Memory Exposure
Package tunnel-agent
Dependency of request
Path request > tunnel-agent
More info https://npmjs.com/advisories/598
Moderate Regular Expression Denial of Service
Package hawk
Patched in >=3.1.3 < 4.0.0 || >=4.1.1
Dependency of request
Path request > hawk
More info https://npmjs.com/advisories/77
Moderate Prototype Pollution
Package hoek
Patched in > 4.2.0 < 5.0.0 || >= 5.0.3
Dependency of request
Path request > hawk > boom > hoek
More info https://npmjs.com/advisories/566
Moderate Prototype Pollution
Package hoek
Patched in > 4.2.0 < 5.0.0 || >= 5.0.3
Dependency of request
Path request > hawk > cryptiles > boom > hoek
More info https://npmjs.com/advisories/566
Moderate Prototype Pollution
Package hoek
Patched in > 4.2.0 < 5.0.0 || >= 5.0.3
Dependency of request
Path request > hawk > hoek
More info https://npmjs.com/advisories/566
Moderate Prototype Pollution
Package hoek
Patched in > 4.2.0 < 5.0.0 || >= 5.0.3
Dependency of request
Path request > hawk > sntp > hoek
More info https://npmjs.com/advisories/566
found 8 moderate severity vulnerabilities in 32 scanned packages:1