-
Notifications
You must be signed in to change notification settings - Fork 0
[Snyk] Fix for 1 vulnerabilities#43
[Snyk] Fix for 1 vulnerabilities#43snyk-bot wants to merge 1 commit intomasterturkdevops/setup-node:masterfrom snyk-fix-28d2cf63b18cb4a590ae70672ddb497bturkdevops/setup-node:snyk-fix-28d2cf63b18cb4a590ae70672ddb497bCopy head branch name to clipboard
Conversation
The following vulnerabilities are fixed with a Snyk patch: - https://snyk.io/vuln/SNYK-JS-LODASH-567746
|
Hard-Coded Secrets (1)Line 12860 in 9d2db77
More info on how to fix Hard-Coded Secrets in General. Insecure File Management (62)Line 97 in 9d2db77
Line 106 in 9d2db77
Line 109 in 9d2db77
Line 137 in 9d2db77
Line 142 in 9d2db77
Line 154 in 9d2db77
Line 184 in 9d2db77
Line 209 in 9d2db77
Line 316 in 9d2db77
Line 320 in 9d2db77
Line 330 in 9d2db77
Line 336 in 9d2db77
Line 339 in 9d2db77
Line 340 in 9d2db77
Line 345 in 9d2db77
Line 346 in 9d2db77
Line 351 in 9d2db77
Line 352 in 9d2db77
Line 354 in 9d2db77
Line 1421 in 9d2db77
Line 1422 in 9d2db77
Line 4569 in 9d2db77
Line 4575 in 9d2db77
Line 4716 in 9d2db77
Line 4717 in 9d2db77
Line 4732 in 9d2db77
Line 4948 in 9d2db77
Line 4949 in 9d2db77
Line 7690 in 9d2db77
Line 10953 in 9d2db77
Line 10979 in 9d2db77
Line 11198 in 9d2db77
Line 11205 in 9d2db77
Line 11231 in 9d2db77
Line 11274 in 9d2db77
Line 11295 in 9d2db77
Line 11296 in 9d2db77
Line 11300 in 9d2db77
Line 11378 in 9d2db77
Line 12559 in 9d2db77
Line 12573 in 9d2db77
Line 12609 in 9d2db77
Line 12611 in 9d2db77
Line 12618 in 9d2db77
Line 12624 in 9d2db77
Line 12648 in 9d2db77
Line 12676 in 9d2db77
Line 12690 in 9d2db77
Line 13078 in 9d2db77
Line 13823 in 9d2db77
Line 13829 in 9d2db77
setup-node/__tests__/authutil.test.ts Line 67 in 9d2db77
setup-node/__tests__/authutil.test.ts Line 80 in 9d2db77 setup-node/__tests__/authutil.test.ts Line 81 in 9d2db77
setup-node/__tests__/authutil.test.ts Line 90 in 9d2db77 setup-node/__tests__/authutil.test.ts Line 100 in 9d2db77 setup-node/__tests__/authutil.test.ts Line 109 in 9d2db77 setup-node/__tests__/authutil.test.ts Line 117 in 9d2db77
Line 36 in 9d2db77
Line 37 in 9d2db77
Line 53 in 9d2db77
Line 124 in 9d2db77
More info on how to fix Insecure File Management in Javascript and Typescript. Insecure Use of Regular Expressions (13)Line 1669 in 9d2db77
Line 1684 in 9d2db77
Line 1705 in 9d2db77
Line 1733 in 9d2db77
Line 5208 in 9d2db77
Line 5223 in 9d2db77
Line 5244 in 9d2db77
Line 5272 in 9d2db77
Line 7069 in 9d2db77
Line 7526 in 9d2db77
Line 7572 in 9d2db77
Line 13927 in 9d2db77
Line 15059 in 9d2db77
More info on how to fix Insecure Use of Regular Expressions in Javascript. Insecure Use of Dangerous Function (9)Line 4033 in 9d2db77
Line 7526 in 9d2db77
Line 9016 in 9d2db77
Line 9024 in 9d2db77
Line 9029 in 9d2db77
Line 9032 in 9d2db77
Line 9038 in 9d2db77
Line 13991 in 9d2db77
Line 15126 in 9d2db77
More info on how to fix Insecure Use of Dangerous Function in Javascript. Insecure Use of Language/Framework API (3)Line 4177 in 9d2db77
Line 7683 in 9d2db77
Line 12800 in 9d2db77
More info on how to fix Insecure Use of Language/Framework API in Javascript. Insecure Network Communication (1)Line 10 in 9d2db77
More info on how to fix Insecure Network Communication in Javascript. 👉 Go to the dashboard for detailed results. 📥 Happy? Share your feedback with us. |
Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.
Changes included in this PR
Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
Adding or updating a Snyk policy (.snyk) file; this file is required in order to apply Snyk vulnerability patches.
Find out more.
Vulnerabilities that will be fixed
With a Snyk patch:
Why? Proof of Concept exploit, Has a fix available, CVSS 6.3
SNYK-JS-LODASH-567746
(*) Note that the real score may have changed since the PR was raised.
Check the changes in this PR to ensure they won't cause issues with your project.
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.
For more information:
🧐 View latest project report
🛠 Adjust project settings
📚 Read more about Snyk's upgrade and patch logic