Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Snyk] Upgrade chart.js from 4.3.1 to 4.4.4 #4

Open
wants to merge 1 commit into
base: androidx-main
Choose a base branch
from

Conversation

karencapiiro
Copy link

snyk-top-banner

Snyk has created this PR to upgrade chart.js from 4.3.1 to 4.4.4.

ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


  • The recommended version is 7 versions ahead of your current version.

  • The recommended version was released on a month ago.

Release notes
Package name: chart.js from chart.js GitHub release notes

Important

  • Check the changes in this PR to ensure they won't cause issues with your project.
  • This PR was automatically created by Snyk using the credentials of a real user.

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

Snyk has created this PR to upgrade chart.js from 4.3.1 to 4.4.4.

See this package in npm:
chart.js

See this project in Snyk:
https://app.snyk.io/org/apiiro-snyk/project/632ba37d-26fa-4bfa-a23b-e7f77f6debf2?utm_source=github&utm_medium=referral&page=upgrade-pr
Copy link

New and removed dependencies detected. Learn more about Socket for GitHub ↗︎

Package New capabilities Transitives Size Publisher
npm/[email protected] None +1 5.01 MB chartjs-ci

🚮 Removed packages: npm/[email protected]

View full report↗︎

@rafikmojr
Copy link

Logo
Checkmarx One – Scan Summary & Detailse7cd6768-beb5-46b8-9ae2-38c6a9397120

New Issues

Severity Issue Source File / Package Checkmarx Insight
CRITICAL Second_Order_SQL_Injection /room/room-paging/src/main/java/androidx/room/paging/util/RoomPagingUtil.kt: 140 Attack Vector
CRITICAL Second_Order_SQL_Injection /room/room-runtime/src/main/java/androidx/room/util/DBUtil.kt: 74 Attack Vector
CRITICAL Stored_XSS /room/room-runtime/src/main/java/androidx/room/util/DBUtil.kt: 74 Attack Vector
CRITICAL Stored_XSS /room/room-runtime/src/main/java/androidx/room/util/DBUtil.kt: 74 Attack Vector
CRITICAL Stored_XSS /room/room-runtime/src/main/java/androidx/room/util/DBUtil.kt: 74 Attack Vector
CRITICAL Stored_XSS /buildSrc/private/src/main/kotlin/androidx/build/checkapi/ApiLocation.kt: 96 Attack Vector
CRITICAL Stored_XSS /buildSrc/private/src/main/kotlin/androidx/build/checkapi/ApiLocation.kt: 96 Attack Vector
CRITICAL Stored_XSS /buildSrc/private/src/main/kotlin/androidx/build/checkapi/ApiLocation.kt: 96 Attack Vector
CRITICAL Stored_XSS /buildSrc/private/src/main/kotlin/androidx/build/checkapi/ApiLocation.kt: 96 Attack Vector
CRITICAL Stored_XSS /buildSrc/private/src/main/kotlin/androidx/build/checkapi/ApiLocation.kt: 96 Attack Vector
CRITICAL Stored_XSS /buildSrc/private/src/main/kotlin/androidx/build/checkapi/ApiLocation.kt: 96 Attack Vector
CRITICAL Stored_XSS /buildSrc/private/src/main/kotlin/androidx/build/checkapi/ApiLocation.kt: 96 Attack Vector
CRITICAL Stored_XSS /room/room-paging/src/main/java/androidx/room/paging/util/RoomPagingUtil.kt: 140 Attack Vector
CRITICAL Stored_XSS /room/room-paging/src/main/java/androidx/room/paging/util/RoomPagingUtil.kt: 140 Attack Vector
CRITICAL Stored_XSS /room/room-paging/src/main/java/androidx/room/paging/util/RoomPagingUtil.kt: 140 Attack Vector
CRITICAL Stored_XSS /room/room-paging/src/main/java/androidx/room/paging/util/RoomPagingUtil.kt: 140 Attack Vector
CRITICAL Stored_XSS /room/room-runtime/src/main/java/androidx/room/util/DBUtil.kt: 74 Attack Vector
CRITICAL Stored_XSS /room/room-paging/src/main/java/androidx/room/paging/util/RoomPagingUtil.kt: 140 Attack Vector
HIGH CVE-2024-37890 Npm-ws-8.9.0 Vulnerable Package
HIGH CVE-2024-4068 Npm-braces-3.0.2 Vulnerable Package
HIGH CVE-2024-45296 Npm-path-to-regexp-0.1.7 Vulnerable Package
HIGH CVE-2024-45590 Npm-body-parser-1.20.1 Vulnerable Package
HIGH Reflected_XSS /wear/watchface/watchface-editor/src/main/java/androidx/wear/watchface/editor/WatchFaceEditorContract.kt: 168 Attack Vector
HIGH Reflected_XSS /navigation/navigation-runtime/src/main/java/androidx/navigation/NavController.kt: 1809 Attack Vector
HIGH Reflected_XSS /navigation/navigation-runtime/src/main/java/androidx/navigation/NavController.kt: 1809 Attack Vector
HIGH Reflected_XSS /navigation/navigation-runtime/src/main/java/androidx/navigation/NavController.kt: 1335 Attack Vector
HIGH Reflected_XSS /navigation/navigation-common/src/main/java/androidx/navigation/NavDeepLinkRequest.kt: 51 Attack Vector
HIGH Reflected_XSS /navigation/navigation-common/src/main/java/androidx/navigation/NavDeepLinkRequest.kt: 51 Attack Vector
HIGH Reflected_XSS /compose/foundation/foundation/src/commonMain/kotlin/androidx/compose/foundation/text/CoreTextField.kt: 243 Attack Vector
HIGH Reflected_XSS /compose/ui/ui-text/src/commonMain/kotlin/androidx/compose/ui/text/input/VisualTransformation.kt: 30 Attack Vector
HIGH Reflected_XSS /compose/foundation/foundation/integration-tests/foundation-demos/src/main/java/androidx/compose/foundation/demos/text/ComposeInputFieldMinMaxLines.kt: 140 Attack Vector
HIGH Reflected_XSS /glance/glance-template/src/main/java/androidx/glance/template/GlanceTemplate.kt: 39 Attack Vector
HIGH Reflected_XSS /glance/glance-template/src/main/java/androidx/glance/template/GlanceTemplate.kt: 39 Attack Vector
HIGH Reflected_XSS /compose/foundation/foundation/src/androidInstrumentedTest/kotlin/androidx/compose/foundation/textfield/TextFieldSelectionTest.kt: 452 Attack Vector
HIGH Reflected_XSS /window/window-demos/demo/src/main/java/androidx/window/demo/embedding/SplitDeviceStateActivityBase.kt: 100 Attack Vector
HIGH Reflected_XSS /navigation/navigation-runtime/src/main/java/androidx/navigation/NavDeepLinkBuilder.kt: 288 Attack Vector
HIGH Reflected_XSS /navigation/navigation-runtime/src/main/java/androidx/navigation/NavDeepLinkBuilder.kt: 277 Attack Vector
HIGH Reflected_XSS /navigation/navigation-runtime/src/main/java/androidx/navigation/NavDeepLinkBuilder.kt: 316 Attack Vector
HIGH Reflected_XSS /compose/ui/ui-text/benchmark/src/androidTest/java/androidx/compose/ui/text/benchmark/input/EditProcessorBenchmark.kt: 96 Attack Vector
HIGH Reflected_XSS /compose/ui/ui-text/benchmark/src/androidTest/java/androidx/compose/ui/text/benchmark/input/EditProcessorBenchmark.kt: 96 Attack Vector
HIGH Reflected_XSS /compose/ui/ui-text/benchmark/src/androidTest/java/androidx/compose/ui/text/benchmark/input/EditProcessorBenchmark.kt: 96 Attack Vector
HIGH Reflected_XSS /window/window-demos/demo/src/main/java/androidx/window/demo/embedding/SplitDeviceStateActivityBase.kt: 117 Attack Vector
HIGH Reflected_XSS /compose/ui/ui-test/src/androidInstrumentedTest/kotlin/androidx/compose/ui/test/util/TestTextField.kt: 59 Attack Vector
HIGH Reflected_XSS /paging/integration-tests/testapp/src/main/java/androidx/paging/integration/testapp/v3/Item.kt: 21 Attack Vector
HIGH Reflected_XSS /paging/integration-tests/testapp/src/main/java/androidx/paging/integration/testapp/v3/Item.kt: 21 Attack Vector
HIGH Reflected_XSS /paging/integration-tests/testapp/src/main/java/androidx/paging/integration/testapp/v3/Item.kt: 21 Attack Vector
HIGH Reflected_XSS /paging/integration-tests/testapp/src/main/java/androidx/paging/integration/testapp/v3/Item.kt: 21 Attack Vector
HIGH Reflected_XSS /compose/foundation/foundation/integration-tests/foundation-demos/src/main/java/androidx/compose/foundation/demos/text2/DecorationBoxDemos.kt: 85 Attack Vector
HIGH Reflected_XSS /compose/material3/material3/src/commonMain/kotlin/androidx/compose/material3/TimePicker.kt: 1554 Attack Vector
HIGH Reflected_XSS /navigation/navigation-runtime/src/main/java/androidx/navigation/NavController.kt: 1317 Attack Vector
HIGH Reflected_XSS /compose/ui/ui-graphics/src/commonMain/kotlin/androidx/compose/ui/graphics/colorspace/ColorSpace.kt: 458 Attack Vector
HIGH Reflected_XSS /compose/ui/ui-graphics/src/commonMain/kotlin/androidx/compose/ui/graphics/colorspace/ColorSpace.kt: 458 Attack Vector
HIGH Reflected_XSS /camera/integration-tests/extensionstestapp/src/main/java/androidx/camera/integration/extensions/validation/ImageValidationActivity.kt: 114 Attack Vector
HIGH Reflected_XSS /camera/integration-tests/extensionstestapp/src/main/java/androidx/camera/integration/extensions/validation/ImageValidationActivity.kt: 113 Attack Vector
HIGH Reflected_XSS /navigation/navigation-runtime/src/androidTest/java/androidx/navigation/NavControllerTest.kt: 3585 Attack Vector
HIGH Reflected_XSS /navigation/navigation-runtime/src/androidTest/java/androidx/navigation/NavControllerTest.kt: 3558 Attack Vector
HIGH Reflected_XSS /navigation/navigation-runtime/src/androidTest/java/androidx/navigation/NavControllerTest.kt: 3504 Attack Vector
HIGH Reflected_XSS /navigation/navigation-runtime/src/androidTest/java/androidx/navigation/NavControllerTest.kt: 3464 Attack Vector
HIGH Reflected_XSS /navigation/navigation-runtime/src/androidTest/java/androidx/navigation/NavControllerTest.kt: 3437 Attack Vector
HIGH Reflected_XSS /navigation/navigation-runtime/src/androidTest/java/androidx/navigation/NavControllerTest.kt: 3416 Attack Vector
HIGH Reflected_XSS /navigation/navigation-runtime/src/androidTest/java/androidx/navigation/NavControllerTest.kt: 3393 Attack Vector
HIGH Reflected_XSS /navigation/navigation-runtime/src/androidTest/java/androidx/navigation/NavControllerTest.kt: 3368 Attack Vector
HIGH Reflected_XSS /navigation/navigation-runtime/src/androidTest/java/androidx/navigation/NavControllerTest.kt: 3344 Attack Vector
HIGH Reflected_XSS /navigation/navigation-runtime/src/androidTest/java/androidx/navigation/NavControllerTest.kt: 3321 Attack Vector
HIGH Reflected_XSS /navigation/navigation-runtime/src/androidTest/java/androidx/navigation/NavControllerTest.kt: 3298 Attack Vector
HIGH Reflected_XSS /navigation/navigation-runtime/src/androidTest/java/androidx/navigation/NavControllerTest.kt: 3269 Attack Vector
HIGH Reflected_XSS /navigation/navigation-runtime/src/androidTest/java/androidx/navigation/NavControllerTest.kt: 3250 Attack Vector
HIGH Reflected_XSS /navigation/navigation-runtime/src/androidTest/java/androidx/navigation/NavControllerRouteTest.kt: 2359 Attack Vector
HIGH Reflected_XSS /navigation/navigation-runtime/src/androidTest/java/androidx/navigation/NavControllerRouteTest.kt: 2332 Attack Vector
HIGH Reflected_XSS /navigation/navigation-runtime/src/androidTest/java/androidx/navigation/NavControllerRouteTest.kt: 2278 Attack Vector
HIGH Reflected_XSS /navigation/navigation-runtime/src/androidTest/java/androidx/navigation/NavControllerRouteTest.kt: 2234 Attack Vector
HIGH Reflected_XSS /navigation/navigation-runtime/src/androidTest/java/androidx/navigation/NavControllerRouteTest.kt: 2207 Attack Vector
HIGH Reflected_XSS /navigation/navigation-runtime/src/androidTest/java/androidx/navigation/NavControllerRouteTest.kt: 2152 Attack Vector
HIGH Reflected_XSS /navigation/navigation-runtime/src/androidTest/java/androidx/navigation/NavControllerRouteTest.kt: 2132 Attack Vector
HIGH Reflected_XSS /activity/activity/src/main/java/androidx/activity/ComponentActivity.kt: 588 Attack Vector
MEDIUM CVE-2024-29041 Npm-express-4.18.2 Vulnerable Package
MEDIUM CVE-2024-31207 Npm-vite-4.4.7 Vulnerable Package
MEDIUM CVE-2024-4067 Npm-micromatch-4.0.5 Vulnerable Package
MEDIUM CVE-2024-43796 Npm-express-4.18.2 Vulnerable Package
MEDIUM CVE-2024-43799 Npm-send-0.18.0 Vulnerable Package
MEDIUM CVE-2024-43800 Npm-serve-static-1.15.0 Vulnerable Package
MEDIUM CVE-2024-45047 Npm-svelte-4.1.1 Vulnerable Package
MEDIUM Cx14b19a02-387a Npm-body-parser-1.20.1 Vulnerable Package
MEDIUM Parameter_Tampering /camera/integration-tests/uiwidgetstestapp/src/main/java/androidx/camera/integration/uiwidgets/foldable/FoldableCameraActivity.kt: 402 Attack Vector
MEDIUM Parameter_Tampering /camera/integration-tests/uiwidgetstestapp/src/main/java/androidx/camera/integration/uiwidgets/foldable/FoldableCameraActivity.kt: 402 Attack Vector
MEDIUM Parameter_Tampering /camera/integration-tests/uiwidgetstestapp/src/main/java/androidx/camera/integration/uiwidgets/foldable/FoldableCameraActivity.kt: 402 Attack Vector
MEDIUM Privacy_Violation /compose/runtime/runtime/samples/src/main/java/androidx/compose/runtime/samples/ModelSamples.kt: 45 Attack Vector
MEDIUM Privacy_Violation /compose/material3/material3/samples/src/main/java/androidx/compose/material3/samples/TextFieldSamples.kt: 198 Attack Vector
MEDIUM Privacy_Violation /compose/material/material/samples/src/main/java/androidx/compose/material/samples/TextFieldSamples.kt: 170 Attack Vector
MEDIUM Privacy_Violation /compose/foundation/foundation/src/commonMain/kotlin/androidx/compose/foundation/gestures/Draggable.kt: 575 Attack Vector
MEDIUM Privacy_Violation /compose/foundation/foundation/integration-tests/foundation-demos/src/main/java/androidx/compose/foundation/demos/text/TextFieldKeyboardTypeDemo.kt: 35 Attack Vector
MEDIUM Privacy_Violation /compose/foundation/foundation/integration-tests/foundation-demos/src/main/java/androidx/compose/foundation/demos/text/TextFieldKeyboardTypeDemo.kt: 34 Attack Vector
MEDIUM Privacy_Violation /compose/runtime/runtime/samples/src/main/java/androidx/compose/runtime/samples/ModelSamples.kt: 45 Attack Vector
MEDIUM Privacy_Violation /compose/material3/material3/samples/src/main/java/androidx/compose/material3/samples/TextFieldSamples.kt: 198 Attack Vector
MEDIUM Privacy_Violation /compose/material/material/samples/src/main/java/androidx/compose/material/samples/TextFieldSamples.kt: 170

More results are available on AST platform

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants