[Snyk] Fix for 13 vulnerabilities by caniszczyk ยท Pull Request #441 ยท paralus/website

snyk-top-banner

Snyk has created this PR to fix 13 vulnerabilities in the npm dependencies of this project.

Snyk changed the following file(s):

  • package.json
  • package-lock.json

Vulnerabilities that will be fixed with an upgrade:

Issue Score
critical severity Incomplete List of Disallowed Inputs
SNYK-JS-BABELTRAVERSE-5962462
  786  
high severity Sandbox Bypass
SNYK-JS-WEBPACK-3358798
  736  
high severity Excessive Platform Resource Consumption within a Loop
SNYK-JS-BRACES-6838727
  696  
high severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-SEMVER-3247795
  696  
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-BABELRUNTIME-10044504
  666  
medium severity Cross-site Scripting (XSS)
SNYK-JS-WEBPACK-7840298
  616  
medium severity Prototype Pollution
SNYK-JS-JSYAML-13961110
  559  
medium severity Prototype Pollution
SNYK-JS-LODASH-15053838
  559  
medium severity Improper Input Validation
SNYK-JS-NANOID-8492085
  529  
low severity Server-side Request Forgery (SSRF)
SNYK-JS-WEBPACK-15235959
  498  
low severity Server-side Request Forgery (SSRF)
SNYK-JS-WEBPACK-15235969
  498  
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-SIDEWAYFORMULA-3317169
  489  
medium severity Inefficient Regular Expression Complexity
SNYK-JS-MICROMATCH-6838728
  479  

Important

  • Check the changes in this PR to ensure they won't cause issues with your project.
  • Max score is 1000. Note that the real score may have changed since the PR was raised.
  • This PR was automatically created by Snyk using the credentials of a real user.

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
๐Ÿง View latest project report
๐Ÿ“œ Customise PR templates
๐Ÿ›  Adjust project settings
๐Ÿ“š Read about Snyk's upgrade logic


Learn how to fix vulnerabilities with free interactive lessons:

๐Ÿฆ‰ Regular Expression Denial of Service (ReDoS)
๐Ÿฆ‰ Prototype Pollution
๐Ÿฆ‰ Improper Input Validation
๐Ÿฆ‰ More lessons are available in Snyk Learn