-
Notifications
You must be signed in to change notification settings - Fork 4
[Snyk] Fix for 42 vulnerabilities #221
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: master
Are you sure you want to change the base?
Conversation
The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-JS-LIBXMLJS-10557411 - https://snyk.io/vuln/SNYK-JS-LIBXMLJS-10557412 - https://snyk.io/vuln/SNYK-JS-LIBXMLJS-10557414 - https://snyk.io/vuln/SNYK-JS-LIBXMLJS-10557422 - https://snyk.io/vuln/SNYK-JS-LIBXMLJS-10557431 - https://snyk.io/vuln/SNYK-JS-LIBXMLJS-10557390 - https://snyk.io/vuln/SNYK-JS-LIBXMLJS-10557401 - https://snyk.io/vuln/SNYK-JS-LIBXMLJS-10557402 - https://snyk.io/vuln/SNYK-JS-LIBXMLJS-10557403 - https://snyk.io/vuln/SNYK-JS-LIBXMLJS-10557432 - https://snyk.io/vuln/SNYK-JS-LIBXMLJS-10557439 - https://snyk.io/vuln/SNYK-JS-WS-7266574 - https://snyk.io/vuln/SNYK-JS-LIBXMLJS-10557434 - https://snyk.io/vuln/SNYK-JS-LIBXMLJS-10557418 - https://snyk.io/vuln/SNYK-JS-LIBXMLJS-10557419 - https://snyk.io/vuln/SNYK-JS-LIBXMLJS-10557391 - https://snyk.io/vuln/SNYK-JS-LIBXMLJS-10557404 - https://snyk.io/vuln/SNYK-JS-LIBXMLJS-10557405 - https://snyk.io/vuln/SNYK-JS-LIBXMLJS-10557408 - https://snyk.io/vuln/SNYK-JS-LIBXMLJS-10557413 - https://snyk.io/vuln/SNYK-JS-LIBXMLJS-10557421 - https://snyk.io/vuln/SNYK-JS-LIBXMLJS-10557424 - https://snyk.io/vuln/SNYK-JS-LIBXMLJS-10557425 - https://snyk.io/vuln/SNYK-JS-LIBXMLJS-10557430 - https://snyk.io/vuln/SNYK-JS-LIBXMLJS-10557433 - https://snyk.io/vuln/SNYK-JS-LIBXMLJS-10557436 - https://snyk.io/vuln/SNYK-JS-LIBXMLJS-10557437 - https://snyk.io/vuln/SNYK-JS-LIBXMLJS-10557407 - https://snyk.io/vuln/SNYK-JS-LIBXMLJS-10557389 - https://snyk.io/vuln/SNYK-JS-LIBXMLJS-10557409 - https://snyk.io/vuln/SNYK-JS-LIBXMLJS-10557415 - https://snyk.io/vuln/SNYK-JS-LIBXMLJS-10557416 - https://snyk.io/vuln/SNYK-JS-LIBXMLJS-10557417 - https://snyk.io/vuln/SNYK-JS-LIBXMLJS-10557429 - https://snyk.io/vuln/SNYK-JS-LIBXMLJS-10557435 - https://snyk.io/vuln/SNYK-JS-LIBXMLJS-10557406 - https://snyk.io/vuln/SNYK-JS-LIBXMLJS-10557410 - https://snyk.io/vuln/SNYK-JS-LIBXMLJS-10557420 - https://snyk.io/vuln/SNYK-JS-LIBXMLJS-10557423 - https://snyk.io/vuln/SNYK-JS-LIBXMLJS-10557440 - https://snyk.io/vuln/SNYK-JS-LIBXMLJS-10557441 - https://snyk.io/vuln/SNYK-JS-LIBXMLJS-10557428
🎉 Snyk checks have passed. No issues have been found so far.✅ security/snyk check is complete. No issues have been found. (View Details) ✅ license/snyk check is complete. No issues have been found. (View Details) |
"@nestjs/config": "^2.3.1", | ||
"@nestjs/core": "^9.3.9", | ||
"@nestjs/graphql": "^11.0.0", | ||
"@nestjs/graphql": "^12.2.0", |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
@nestjs/graphql 12.2.0 / package.json
Total vulnerabilities: 3
Critical: 0 | High: 2 | Medium: 1 | Low: 0 |
---|
Vulnerability ID | Severity | CVSS | Fixed in | Status |
---|---|---|---|---|
CVE-2024-4068 | 7.5 | - |
Open | |
CVE-2024-37890 | 7.5 | - |
Open | |
CVE-2024-4067 | 5.3 | - |
Open |
"jwk-to-pem": "^2.0.5", | ||
"jwt-simple": "^0.5.6", | ||
"libxmljs": "^0.19.7", | ||
"libxmljs": "^1.0.0", |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
libxmljs 1.0.0 / package.json
Total vulnerabilities: 6
Critical: 2 | High: 2 | Medium: 1 | Low: 1 |
---|
Vulnerability ID | Severity | CVSS | Fixed in | Status |
---|---|---|---|---|
CVE-2024-34391 | 8.1 | - |
Open | |
CVE-2024-34392 | 8.1 | - |
Open | |
CVE-2022-25883 | 7.5 | - |
Open | |
CVE-2022-25883 | 7.5 | - |
Open | |
CVE-2024-28863 | 6.5 | - |
Open | |
CVE-2025-5889 | 3.1 | - |
Open |
New Issues (114)Checkmarx found the following issues in this Pull Request
Fixed Issues (4)Great job! The following issues were fixed in this Pull Request
|
Snyk has created this PR to fix 42 vulnerabilities in the npm dependencies of this project.
Snyk changed the following file(s):
package.json
package-lock.json
Vulnerabilities that will be fixed with an upgrade:
SNYK-JS-LIBXMLJS-10557411
SNYK-JS-LIBXMLJS-10557412
SNYK-JS-LIBXMLJS-10557414
SNYK-JS-LIBXMLJS-10557422
SNYK-JS-LIBXMLJS-10557431
SNYK-JS-LIBXMLJS-10557390
SNYK-JS-LIBXMLJS-10557401
SNYK-JS-LIBXMLJS-10557402
SNYK-JS-LIBXMLJS-10557403
SNYK-JS-LIBXMLJS-10557432
SNYK-JS-LIBXMLJS-10557439
SNYK-JS-WS-7266574
SNYK-JS-LIBXMLJS-10557434
SNYK-JS-LIBXMLJS-10557418
SNYK-JS-LIBXMLJS-10557419
SNYK-JS-LIBXMLJS-10557391
SNYK-JS-LIBXMLJS-10557404
SNYK-JS-LIBXMLJS-10557405
SNYK-JS-LIBXMLJS-10557408
SNYK-JS-LIBXMLJS-10557413
SNYK-JS-LIBXMLJS-10557421
SNYK-JS-LIBXMLJS-10557424
SNYK-JS-LIBXMLJS-10557425
SNYK-JS-LIBXMLJS-10557430
SNYK-JS-LIBXMLJS-10557433
SNYK-JS-LIBXMLJS-10557436
SNYK-JS-LIBXMLJS-10557437
SNYK-JS-LIBXMLJS-10557407
SNYK-JS-LIBXMLJS-10557389
SNYK-JS-LIBXMLJS-10557409
SNYK-JS-LIBXMLJS-10557415
SNYK-JS-LIBXMLJS-10557416
SNYK-JS-LIBXMLJS-10557417
SNYK-JS-LIBXMLJS-10557429
SNYK-JS-LIBXMLJS-10557435
SNYK-JS-LIBXMLJS-10557406
SNYK-JS-LIBXMLJS-10557410
SNYK-JS-LIBXMLJS-10557420
SNYK-JS-LIBXMLJS-10557423
SNYK-JS-LIBXMLJS-10557440
SNYK-JS-LIBXMLJS-10557441
SNYK-JS-LIBXMLJS-10557428
Important
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.
For more information:
🧐 View latest project report
📜 Customise PR templates
🛠 Adjust project settings
📚 Read about Snyk's upgrade logic
Learn how to fix vulnerabilities with free interactive lessons:
🦉 Improper Input Validation
🦉 Use After Free
🦉 NULL Pointer Dereference
🦉 More lessons are available in Snyk Learn