Skip to content

Conversation

@tchopra91
Copy link
Contributor

@tchopra91 tchopra91 commented May 8, 2022

                   === npm audit security report ===                        

// Run npm install puppeteer@13.7.0 to resolve 1 vulnerability
SEMVER WARNING: Recommended action is a potentially breaking change

High node-fetch is vulnerable to Exposure of Sensitive
Information to an Unauthorized Actor

Package node-fetch

Dependency of puppeteer

Path puppeteer > node-fetch

More info GHSA-r683-j2x4-v87g

// Run npm update color-string --depth 5 to resolve 1 vulnerability

Moderate Regular Expression Denial of Service (ReDOS)

Package color-string

Dependency of winston

Path winston > diagnostics > colorspace > color > color-string

More info GHSA-257v-vj4p-3w2h

// Run npm update lodash --depth 3 to resolve 4 vulnerabilities

Critical Prototype Pollution in lodash

Package lodash

Dependency of winston

Path winston > async > lodash

More info GHSA-jf85-cpcp-j695

High Command Injection in lodash

Package lodash

Dependency of winston

Path winston > async > lodash

More info GHSA-35jh-r3h4-6jhm

Moderate Regular Expression Denial of Service (ReDoS) in lodash

Package lodash

Dependency of winston

Path winston > async > lodash

More info GHSA-29mw-wpgm-hmr9

High Prototype Pollution in lodash

Package lodash

Dependency of winston

Path winston > async > lodash

More info GHSA-p6mc-m468-83gw

// Run npm update async --depth 2 to resolve 1 vulnerability

High Prototype Pollution in async

Package async

Dependency of winston

Path winston > async

More info GHSA-fwr7-v2mv-hh25

found 7 vulnerabilities (2 moderate, 4 high, 1 critical) in 160 scanned packages

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant