Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Snyk] Fix for 76 vulnerabilities #178

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

Omrisnyk
Copy link
Owner

@Omrisnyk Omrisnyk commented Sep 5, 2024

snyk-top-banner

Snyk has created this PR to fix 76 vulnerabilities in the npm dependencies of this project.

Snyk changed the following file(s):

  • large-file/package.json
  • large-file/package-lock.json

Vulnerabilities that will be fixed with an upgrade:

Issue Score
high severity Prototype Poisoning
SNYK-JS-QS-3153490
  ****  
medium severity Validation Bypass
SNYK-JS-SANITIZEHTML-1070780
  ****  
medium severity Access Restriction Bypass
SNYK-JS-SANITIZEHTML-1070786
  ****  
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-SANITIZEHTML-2957526
  ****  
critical severity Arbitrary Code Execution
SNYK-JS-SANITIZEHTML-585892
  ****  
medium severity Information Exposure
SNYK-JS-SANITIZEHTML-6256334
  ****  
high severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-SEMVER-3247795
  ****  
high severity Prototype Pollution
SNYK-JS-SETVALUE-1540541
  ****  
high severity Prototype Pollution
SNYK-JS-SETVALUE-450213
  ****  
high severity Improper Privilege Management
SNYK-JS-SHELLJS-2332187
  ****  
high severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-SSRI-1246392
  ****  
high severity Arbitrary File Overwrite
SNYK-JS-TAR-1536528
  ****  
high severity Arbitrary File Overwrite
SNYK-JS-TAR-1536531
  ****  
low severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-TAR-1536758
  ****  
high severity Arbitrary File Write
SNYK-JS-TAR-1579147
  ****  
high severity Arbitrary File Write
SNYK-JS-TAR-1579152
  ****  
high severity Arbitrary File Write
SNYK-JS-TAR-1579155
  ****  
medium severity Uncontrolled Resource Consumption ('Resource Exhaustion')
SNYK-JS-TAR-6476909
  ****  
medium severity Prototype Pollution
SNYK-JS-TOUGHCOOKIE-5672873
  ****  
high severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-UAPARSERJS-1023599
  ****  
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-UAPARSERJS-1072471
  ****  
high severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-UAPARSERJS-610226
  ****  
high severity Prototype Pollution
SNYK-JS-UNSETVALUE-2400660
  ****  
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-WS-1296835
  ****  
high severity Denial of Service (DoS)
SNYK-JS-WS-7266574
  ****  
high severity Prototype Pollution
SNYK-JS-Y18N-1021887
  ****  
high severity Code Injection
SNYK-JS-LODASH-1040724
  239  
high severity Code Injection
SNYK-JS-LODASHES-2434284
  239  
critical severity Incomplete List of Disallowed Inputs
SNYK-JS-BABELTRAVERSE-5962462
  235  
critical severity Improper Verification of Cryptographic Signature
SNYK-JS-ELLIPTIC-7577916
  224  
critical severity Improper Verification of Cryptographic Signature
SNYK-JS-ELLIPTIC-7577917
  224  
critical severity Improper Verification of Cryptographic Signature
SNYK-JS-ELLIPTIC-7577918
  224  
high severity Denial of Service (DoS)
npm:ws:20171108
  220  
medium severity Prototype Pollution
SNYK-JS-PATHVAL-596926
  190  
high severity Prototype Pollution
SNYK-JS-LODASHES-2434283
  189  
high severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-GETFUNCNAME-5923417
  187  
medium severity Prototype Pollution
SNYK-JS-JSON5-3182856
  179  
high severity Uncontrolled resource consumption
SNYK-JS-BRACES-6838727
  169  
high severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-ES5EXT-6095076
  169  
high severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-ANSIREGEX-1583908
  159  
high severity Prototype Pollution
SNYK-JS-ASYNC-2441827
  159  
high severity Denial of Service (DoS)
SNYK-JS-DECODEURICOMPONENT-3149970
  159  
high severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-MOMENT-2944238
  159  
high severity Prototype Pollution
SNYK-JS-LODASHES-2434290
  152  
high severity Prototype Pollution
SNYK-JS-INI-1048974
  151  
high severity Prototype Pollution
SNYK-JS-JSONSCHEMA-1920922
  150  
high severity Prototype Pollution
SNYK-JS-LODASHES-2434285
  150  
high severity Prototype Pollution
SNYK-JS-LODASHES-2434287
  149  
medium severity Missing Release of Resource after Effective Lifetime
SNYK-JS-INFLIGHT-6095116
  141  
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-LODASHES-2434286
  133  
high severity Improper Verification of Cryptographic Signature
SNYK-JS-BROWSERIFYSIGN-6037026
  124  
high severity Inefficient Regular Expression Complexity
SNYK-JS-MICROMATCH-6838728
  124  
high severity Prototype Pollution
SNYK-JS-LOADERUTILS-3043105
  115  
high severity Directory Traversal
SNYK-JS-MOMENT-2440688
  114  
high severity Regular Expression Denial of Service (ReDoS)
npm:parsejson:20170908
  114  
medium severity Cryptographic Issues
SNYK-JS-ELLIPTIC-1064899
  112  
medium severity Information Exposure
SNYK-JS-NODEFETCH-2342118
  104  
medium severity Denial of Service
SNYK-JS-NODEFETCH-674311
  101  
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-BROWSERSLIST-1090194
  63  
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-COLORSTRING-1082939
  63  
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-CSSWHAT-3035488
  63  
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-GLOBPARENT-1016905
  63  
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-HOSTEDGITINFO-1088355
  63  
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-ISSVG-1085627
  63  
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-ISSVG-1243891
  63  
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-LODASH-1018905
  63  
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-LODASHES-2434289
  63  
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-PATHPARSE-1077067
  63  
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-POSTCSS-1090595
  63  
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-POSTCSS-1255640
  63  
low severity Prototype Pollution
SNYK-JS-MINIMIST-2429795
  59  
low severity Regular Expression Denial of Service (ReDoS)
npm:debug:20170905
  58  
medium severity Improper Input Validation
SNYK-JS-POSTCSS-5926692
  49  
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-LOADERUTILS-3042992
  45  
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-LOADERUTILS-3105943
  45  
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-MINIMATCH-3050818
  45  
Release notes
Package name: @babel/cli
  • 7.7.0 - 2019-11-05

    v7.7.0 (2019-11-05)

    👓 Spec Compliance

    🚀 New Feature

    • babel-generator, babel-helper-create-class-features-plugin, babel-parser, babel-plugin-transform-typescript, babel-preset-typescript, babel-types
    • babel-core, babel-parser, babel-preset-typescript
    • babel-core
    • babel-plugin-syntax-top-level-await, babel-preset-env
    • babel-helper-builder-react-jsx, babel-plugin-transform-react-jsx, babel-preset-react
      • #10572 [transform-react-jsx] Add useSpread option to transform JSX. (@ ivandevp)
    • babel-generator, babel-parser, babel-plugin-proposal-decorators, babel-plugin-syntax-flow, babel-types
    • babel-plugin-transform-function-name, babel-plugin-transform-modules-umd, babel-preset-env
      • #10477 Changes UMD callsite to be more likely to pass in the intended object.. (@ MicahZoltu)
    • babel-parser
    • babel-generator, babel-parser, babel-types
    • babel-cli, babel-register
    • babel-cli

    🐛 Bug Fix

    • babel-helpers, babel-plugin-proposal-async-generator-functions, babel-plugin-proposal-function-sent, babel-preset-env
    • babel-helper-module-transforms, babel-plugin-transform-modules-commonjs
    • babel-plugin-transform-modules-systemjs
      • #10638 fix: remove ExportNamedDeclaration when the specifier is empty. (@ JLHwung)
    • babel-parser
    • babel-plugin-transform-typescript
    • babel-core
      • #10623 Fix: inputSourceMap should work when it is an external file. (@ JLHwung)
      • #10539 fix: remove filename annotation in buildCodeFrameError. (@ JLHwung)
    • babel-plugin-proposal-decorators
    • babel-helpers, babel-plugin-proposal-dynamic-import, babel-plugin-transform-modules-commonjs, babel-preset-env
      • #10574 fix: _interopRequireWildcard should only cache objects. (@ samMeow)
    • babel-traverse
    • babel-preset-env
    • babel-generator
    • babel-plugin-transform-async-to-generator, babel-preset-env, babel-traverse

    💅 Polish

    • babel-plugin-transform-classes, babel-plugin-transform-regenerator, babel-preset-env
    • babel-helpers, babel-plugin-transform-modules-commonjs, babel-preset-env
      • #10585 fix(babel‑helpers/interopRequireWildcard): Avoid double nullish check. (@ ExE-Boss)
    • babel-register
      • #10557 fix: disable caching when babel could not read/write cache. (@ JLHwung)

    🏠 Internal

    • babel-cli, babel-node
    • babel-register
    • babel-helper-create-regexp-features-plugin, babel-plugin-proposal-unicode-property-regex, babel-plugin-transform-dotall-regex, babel-plugin-transform-named-capturing-groups-regex, babel-plugin-transform-unicode-regex, babel-preset-env
    • babel-preset-env
    • babel-helper-module-imports
      • #10608 Use .find instead of .filter to get targetPath in ImportInjector. (@ Andarist)
    • Other
    • babel-runtime
    • babel-helper-annotate-as-pure, babel-helper-bindify-decorators, babel-helper-builder-binary-assignment-operator-visitor, babel-helper-builder-react-jsx, babel-helper-call-delegate, babel-helper-define-map, babel-helper-explode-assignable-expression, babel-helper-explode-class, babel-helper-function-name, babel-helper-get-function-arity, babel-helper-hoist-variables, babel-helper-member-expression-to-functions, babel-helper-module-imports, babel-helper-module-transforms, babel-helper-optimise-call-expression, babel-helper-remap-async-to-generator, babel-helper-replace-supers, babel-helper-simple-access, babel-helper-split-export-declaration, babel-helper-wrap-function, babel-helpers, babel-template

    🏃‍♀️ Performance

    Committers: 28

  • 7.6.4 - 2019-10-10

    v7.6.4 (2019-10-10)

    👓 Spec Compliance

    🐛 Bug Fix

    • babel-cli, babel-core, babel-generator, babel-helper-transform-fixture-test-runner

    Committers: 2

  • 7.6.3 - 2019-10-08

    v7.6.3 (2019-10-08)

    Thanks to @ hjdivad, @ Basaingeal and @ todofixthis for their first PRs!

    👓 Spec Compliance

    🚀 New Feature

    • babel-types

    🐛 Bug Fix

    • babel-plugin-transform-block-scoping
      • #10343 Do not remove let bindings even they are wrapped in closure (@ JLHwung)
    • babel-parser
    • babel-plugin-transform-react-constant-elements, babel-traverse
    • babel-generator, babel-parser, babel-plugin-transform-block-scoping, babel-plugin-transform-flow-comments, babel-plugin-transform-flow-strip-types, babel-plugin-transform-typescript
      • #10220 Flow: interface identifier should be declared in the scope (@ JLHwung)

    💅 Polish

    🏠 Internal

    • Other
    • babel-cli, babel-core, babel-generator, babel-helper-fixtures, babel-helper-transform-fixture-test-runner, babel-node, babel-plugin-transform-react-jsx-source, babel-plugin-transform-runtime, babel-preset-env, babel-preset-react

    🏃‍♀️ Performance

    • babel-parser
    • Other
      • #10443 perf: only apply lazy cjs module transform on cli and core (@ JLHwung)

    Committers: 10

  • 7.6.2 - 2019-09-23

    v7.6.2 (2019-09-23)

    Thanks to @ FND, @ guywaldman, @ vivek12345, @ TomerAberbach, @ ivandevp and @ gonzarodriguezt for their first PRs!

    👓 Spec Compliance

    🐛 Bug Fix

    • babel-parser
    • babel-cli
    • babel-core
    • babel-plugin-transform-block-scoping, babel-plugin-transform-spread, babel-traverse
    • babel-plugin-proposal-object-rest-spread, babel-preset-env

    🏠 Internal

    🏃‍♀️ Performance

    Committers: 8

  • 7.6.0 - 2019-09-06

    v7.6.0 (2019-09-06)

    👓 Spec Compliance

    • babel-generator, babel-parser
    • babel-helpers, babel-plugin-transform-block-scoping, babel-traverse

    🚀 New Feature

    • babel-core
    • babel-helper-create-class-features-plugin, babel-helpers, babel-plugin-proposal-private-methods
    • babel-generator, babel-parser, babel-types
    • babel-preset-typescript
    • babel-parser
    • babel-types

    🐛 Bug Fix

    • babel-helpers, babel-plugin-transform-destructuring, babel-plugin-transform-modules-commonjs, babel-preset-env
    • babel-plugin-transform-runtime
    • babel-preset-env
    • babel-plugin-transform-named-capturing-groups-regex
    • babel-types
    • babel-parser
      • #10380 Refactor trailing comment adjustment (@ banga)
      • #10369 Retain trailing comments in array expressions (@ banga)
      • #10292 fix: assign trailing comment to ObjectProperty only when inside an ObjectExpression (@ JLHwung)
    • babel-parser, babel-types
    • babel-generator, babel-plugin-transform-typescript,

… vulnerabilities

The following vulnerabilities are fixed with an upgrade:
- https://snyk.io/vuln/SNYK-JS-QS-3153490
- https://snyk.io/vuln/SNYK-JS-SANITIZEHTML-1070780
- https://snyk.io/vuln/SNYK-JS-SANITIZEHTML-1070786
- https://snyk.io/vuln/SNYK-JS-SANITIZEHTML-2957526
- https://snyk.io/vuln/SNYK-JS-SANITIZEHTML-585892
- https://snyk.io/vuln/SNYK-JS-SANITIZEHTML-6256334
- https://snyk.io/vuln/SNYK-JS-SEMVER-3247795
- https://snyk.io/vuln/SNYK-JS-SETVALUE-1540541
- https://snyk.io/vuln/SNYK-JS-SETVALUE-450213
- https://snyk.io/vuln/SNYK-JS-SHELLJS-2332187
- https://snyk.io/vuln/SNYK-JS-SSRI-1246392
- https://snyk.io/vuln/SNYK-JS-TAR-1536528
- https://snyk.io/vuln/SNYK-JS-TAR-1536531
- https://snyk.io/vuln/SNYK-JS-TAR-1536758
- https://snyk.io/vuln/SNYK-JS-TAR-1579147
- https://snyk.io/vuln/SNYK-JS-TAR-1579152
- https://snyk.io/vuln/SNYK-JS-TAR-1579155
- https://snyk.io/vuln/SNYK-JS-TAR-6476909
- https://snyk.io/vuln/SNYK-JS-TOUGHCOOKIE-5672873
- https://snyk.io/vuln/SNYK-JS-UAPARSERJS-1023599
- https://snyk.io/vuln/SNYK-JS-UAPARSERJS-1072471
- https://snyk.io/vuln/SNYK-JS-UAPARSERJS-610226
- https://snyk.io/vuln/SNYK-JS-UNSETVALUE-2400660
- https://snyk.io/vuln/SNYK-JS-WS-1296835
- https://snyk.io/vuln/SNYK-JS-WS-7266574
- https://snyk.io/vuln/SNYK-JS-Y18N-1021887
- https://snyk.io/vuln/SNYK-JS-LODASH-1040724
- https://snyk.io/vuln/SNYK-JS-LODASHES-2434284
- https://snyk.io/vuln/SNYK-JS-BABELTRAVERSE-5962462
- https://snyk.io/vuln/SNYK-JS-ELLIPTIC-7577916
- https://snyk.io/vuln/SNYK-JS-ELLIPTIC-7577917
- https://snyk.io/vuln/SNYK-JS-ELLIPTIC-7577918
- https://snyk.io/vuln/npm:ws:20171108
- https://snyk.io/vuln/SNYK-JS-PATHVAL-596926
- https://snyk.io/vuln/SNYK-JS-LODASHES-2434283
- https://snyk.io/vuln/SNYK-JS-GETFUNCNAME-5923417
- https://snyk.io/vuln/SNYK-JS-JSON5-3182856
- https://snyk.io/vuln/SNYK-JS-BRACES-6838727
- https://snyk.io/vuln/SNYK-JS-ES5EXT-6095076
- https://snyk.io/vuln/SNYK-JS-ANSIREGEX-1583908
- https://snyk.io/vuln/SNYK-JS-ASYNC-2441827
- https://snyk.io/vuln/SNYK-JS-DECODEURICOMPONENT-3149970
- https://snyk.io/vuln/SNYK-JS-MOMENT-2944238
- https://snyk.io/vuln/SNYK-JS-LODASHES-2434290
- https://snyk.io/vuln/SNYK-JS-INI-1048974
- https://snyk.io/vuln/SNYK-JS-JSONSCHEMA-1920922
- https://snyk.io/vuln/SNYK-JS-LODASHES-2434285
- https://snyk.io/vuln/SNYK-JS-LODASHES-2434287
- https://snyk.io/vuln/SNYK-JS-INFLIGHT-6095116
- https://snyk.io/vuln/SNYK-JS-LODASHES-2434286
- https://snyk.io/vuln/SNYK-JS-BROWSERIFYSIGN-6037026
- https://snyk.io/vuln/SNYK-JS-MICROMATCH-6838728
- https://snyk.io/vuln/SNYK-JS-LOADERUTILS-3043105
- https://snyk.io/vuln/SNYK-JS-MOMENT-2440688
- https://snyk.io/vuln/npm:parsejson:20170908
- https://snyk.io/vuln/SNYK-JS-ELLIPTIC-1064899
- https://snyk.io/vuln/SNYK-JS-NODEFETCH-2342118
- https://snyk.io/vuln/SNYK-JS-NODEFETCH-674311
- https://snyk.io/vuln/SNYK-JS-BROWSERSLIST-1090194
- https://snyk.io/vuln/SNYK-JS-COLORSTRING-1082939
- https://snyk.io/vuln/SNYK-JS-CSSWHAT-3035488
- https://snyk.io/vuln/SNYK-JS-GLOBPARENT-1016905
- https://snyk.io/vuln/SNYK-JS-HOSTEDGITINFO-1088355
- https://snyk.io/vuln/SNYK-JS-ISSVG-1085627
- https://snyk.io/vuln/SNYK-JS-ISSVG-1243891
- https://snyk.io/vuln/SNYK-JS-LODASH-1018905
- https://snyk.io/vuln/SNYK-JS-LODASHES-2434289
- https://snyk.io/vuln/SNYK-JS-PATHPARSE-1077067
- https://snyk.io/vuln/SNYK-JS-POSTCSS-1090595
- https://snyk.io/vuln/SNYK-JS-POSTCSS-1255640
- https://snyk.io/vuln/SNYK-JS-MINIMIST-2429795
- https://snyk.io/vuln/npm:debug:20170905
- https://snyk.io/vuln/SNYK-JS-POSTCSS-5926692
- https://snyk.io/vuln/SNYK-JS-LOADERUTILS-3042992
- https://snyk.io/vuln/SNYK-JS-LOADERUTILS-3105943
- https://snyk.io/vuln/SNYK-JS-MINIMATCH-3050818
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

@babel/cli can't be quietened
2 participants