Skip to content

[Snyk] Fix for 7 vulnerabilities#1

Open
gfargo wants to merge 1 commit intomainfrom
snyk-fix-424d308a2b2a246c20af0785bf19b08b
Open

[Snyk] Fix for 7 vulnerabilities#1
gfargo wants to merge 1 commit intomainfrom
snyk-fix-424d308a2b2a246c20af0785bf19b08b

Conversation

@gfargo
Copy link
Copy Markdown
Owner

@gfargo gfargo commented Oct 16, 2024

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • package.json
    • package-lock.json

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
medium severity 586/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 5.3
Resource Exhaustion
SNYK-JS-NEXT-6032387
No Proof of Concept
high severity 589/1000
Why? Has a fix available, CVSS 7.5
HTTP Request Smuggling
SNYK-JS-NEXT-6828456
No No Known Exploit
medium severity 616/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 5.9
Server-Side Request Forgery (SSRF)
SNYK-JS-NEXT-6828457
Yes Proof of Concept
high severity 649/1000
Why? Has a fix available, CVSS 8.7
Denial of Service (DoS)
SNYK-JS-NEXT-7442548
No No Known Exploit
high severity 696/1000
Why? Recently disclosed, Has a fix available, CVSS 8.2
Uncontrolled Recursion
SNYK-JS-NEXT-8186172
Yes No Known Exploit
medium severity 479/1000
Why? Has a fix available, CVSS 5.3
Improper Input Validation
SNYK-JS-POSTCSS-5926692
No No Known Exploit
high severity 696/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
Regular Expression Denial of Service (ReDoS)
SNYK-JS-ZOD-5925617
No Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: next The new version differs by 250 commits.
  • a1c3a03 v14.2.7
  • d46ab2c Fix hmr assetPrefix escaping and reuse logic from other files (#67983)
  • d11cbc9 Reject next image urls in image optimizer (#68628)
  • 575385e Fix bad modRequest in flight entry manifest (#68888)
  • 9ecf2e8 update turbopack build manifest
  • 325dc4b pages router: ensure x-middleware-cache is respected (#67734)
  • d3021b6 update playwright interface
  • 5e6f511 fix i18n data pathname resolving (#68947)
  • dd32e0f Update font data (#68639)
  • 2f7fa98 Add deployment id header for rsc payload if present (#67255)
  • 545746e fix: properly patch lockfile against swc bindings (#66515)
  • 26c80ee GTM dataLayer parameter should take an object, not an array of strings (#66339)
  • bce2ec0 build: upgrade edge-runtime (#67565)
  • 96d6ada fix(next): add cross origin in react dom preload (#67423)
  • c572030 fix: Narrow down from `string | undefined` to `string` (#65248)
  • b5db704 Refactor internal routing headers to use request meta (#66987)
  • deeeb5f Revert "chore: externalize undici for bundling" (#65727)
  • 43f24d0 Switch from automatically requesting reviews to manually requesting them (#67024)
  • 42f0129 fix formatting from #69164
  • 427c01d v14.2.6
  • d4ca0b9 Ensure fetch cache TTL is updated properly (#69164)
  • eee87cb remove invalid line in disabling webpack cache example
  • dc40cc9 Fix typo in memory usage docs
  • 28110b6 [docs] Backport Multi-Zones docs to 14.x branch (#68460)

See the full diff

Package name: zod The new version differs by 71 commits.
  • 1e61d76 3.22.3
  • 2ba00fe [2609] fix ReDoS vulnerability in email regex (#2824)
  • ae0f7a2 docs: update ref to discriminated-unions docs (#2485)
  • ad2ee9c 2718 Updated Custom Schemas documentation example to use type narrowing (#2778)
  • 28c1927 Update sponsors
  • 18115a8 Formatting
  • 64dcc8e Update sponsors
  • f59be09 clarify datetime ISO 8601 (#2673)
  • 9bd3879 docs: remove obsolete text about readonly types (#2676)
  • 1e23990 Commit
  • 792b3ef Fix superrefine types
  • 8e4af7b X to Zod: add app.quicktype.io (#2668)
  • 0d49f10 docs: add typeschema to ecosystem (#2626)
  • 13d9e6b Fix lint
  • 0a055e7 3.22.1
  • 932cc47 Initial prototype fix for issue #2651 (#2652)
  • fba438c 3.22.0
  • 981d4b5 Add ZodReadonly (#2634)
  • 1ecd624 Fix prettier
  • 78a4090 docs: update comparison with `runtypes` (#2536)
  • 81a89f5 Update nullish documentation to correct chaining order (#2457)
  • 6aab901 fix typo test name (#2542)
  • 8b8ab3e Update README.md (#2562)
  • 5adae24 docs: add conform form integration (#2577)

See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Resource Exhaustion
🦉 Server-Side Request Forgery (SSRF)
🦉 Improper Input Validation

@vercel
Copy link
Copy Markdown
Contributor

vercel Bot commented Oct 16, 2024

The latest updates on your projects. Learn more about Vercel for Git ↗︎

Name Status Preview Comments Updated (UTC)
tune-observer ❌ Failed (Inspect) Oct 16, 2024 11:00pm

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants