Skip to content

update morgan#9

Open
try-panwiac wants to merge 1 commit intomasterfrom
pr-comment-demo2
Open

update morgan#9
try-panwiac wants to merge 1 commit intomasterfrom
pr-comment-demo2

Conversation

@try-panwiac
Copy link
Owner

No description provided.

Copy link

@prisma-cloud-devsecops prisma-cloud-devsecops bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Prisma Cloud has found errors in this PR ⬇️

"dependencies": {
"async": "^1.5.2",
"body-parser": "^1.15.1",
"connect-redis": "^3.2.0",

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

morgan 1.0.0 / package.json

Total vulnerabilities: 1

Critical: 1High: 0Medium: 0Low: 0
Vulnerability ID Severity CVSSFixed in
CVE-2019-5413 CRITICAL9.81.9.1

version "1.0.4"
resolved "https://registry.yarnpkg.com/basic-auth/-/basic-auth-1.0.4.tgz#030935b01de7c9b94a824b29f3fccb750d3a5290"

bcrypt-pbkdf@^1.0.0:

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

redis 2.8.0 / yarn.lock

Total vulnerabilities: 1

Critical: 0High: 1Medium: 0Low: 0
Vulnerability ID Severity CVSSFixed in
CVE-2021-29469 HIGH7.53.1.1

version "1.0.4"
resolved "https://registry.yarnpkg.com/basic-auth/-/basic-auth-1.0.4.tgz#030935b01de7c9b94a824b29f3fccb750d3a5290"

bcrypt-pbkdf@^1.0.0:

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

superagent 2.3.0 / yarn.lock

Total vulnerabilities: 1

Critical: 0High: 0Medium: 1Low: 0
Vulnerability ID Severity CVSSFixed in
CVE-2017-16129 MEDIUM5.93.7.0

version "1.0.4"
resolved "https://registry.yarnpkg.com/basic-auth/-/basic-auth-1.0.4.tgz#030935b01de7c9b94a824b29f3fccb750d3a5290"

bcrypt-pbkdf@^1.0.0:

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

is-my-json-valid 2.15.0 / yarn.lock

Total vulnerabilities: 2

Critical: 0High: 1Medium: 1Low: 0
Vulnerability ID Severity CVSSFixed in
CVE-2016-2537 HIGH72.17.2
CVE-2018-1107 MEDIUM5.32.17.2

version "1.0.4"
resolved "https://registry.yarnpkg.com/basic-auth/-/basic-auth-1.0.4.tgz#030935b01de7c9b94a824b29f3fccb750d3a5290"

bcrypt-pbkdf@^1.0.0:

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

mocha 3.2.0 / yarn.lock

Total vulnerabilities: 2

Critical: 0High: 1Medium: 1Low: 0
Vulnerability ID Severity CVSSFixed in
PRISMA-2022-0230 HIGH7.5-
PRISMA-2022-0335 MEDIUM5.3-

version "1.0.4"
resolved "https://registry.yarnpkg.com/basic-auth/-/basic-auth-1.0.4.tgz#030935b01de7c9b94a824b29f3fccb750d3a5290"

bcrypt-pbkdf@^1.0.0:

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

growl 1.9.2 / yarn.lock

Total vulnerabilities: 1

Critical: 1High: 0Medium: 0Low: 0
Vulnerability ID Severity CVSSFixed in
CVE-2017-16042 CRITICAL9.81.10.2

version "1.0.4"
resolved "https://registry.yarnpkg.com/basic-auth/-/basic-auth-1.0.4.tgz#030935b01de7c9b94a824b29f3fccb750d3a5290"

bcrypt-pbkdf@^1.0.0:

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

debug 2.2.0 / yarn.lock

Total vulnerabilities: 1

Critical: 0High: 0Medium: 1Low: 0
Vulnerability ID Severity CVSSFixed in
CVE-2017-16137 MEDIUM5.32.6.9

version "1.0.4"
resolved "https://registry.yarnpkg.com/basic-auth/-/basic-auth-1.0.4.tgz#030935b01de7c9b94a824b29f3fccb750d3a5290"

bcrypt-pbkdf@^1.0.0:
Copy link

@prisma-cloud-devsecops prisma-cloud-devsecops bot Oct 3, 2022

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

hoek 2.16.3 / yarn.lock

Total vulnerabilities: 2

Critical: 0High: 2Medium: 0Low: 0
Vulnerability ID Severity CVSSFixed in
CVE-2018-3728 HIGH8.84.2.0
CVE-2020-36604 HIGH8.18.5.1

version "1.0.4"
resolved "https://registry.yarnpkg.com/basic-auth/-/basic-auth-1.0.4.tgz#030935b01de7c9b94a824b29f3fccb750d3a5290"

bcrypt-pbkdf@^1.0.0:
Copy link

@prisma-cloud-devsecops prisma-cloud-devsecops bot Oct 3, 2022

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

handlebars 4.5.1 / yarn.lock

Total vulnerabilities: 6

Critical: 2High: 4Medium: 0Low: 0
Vulnerability ID Severity CVSSFixed in
CVE-2021-23369 CRITICAL9.84.7.7
CVE-2021-23383 CRITICAL9.84.7.7
CVE-2019-20920 HIGH8.14.5.3
GHSA-2cf5-4w76-r9qv HIGH74.5.2
GHSA-g9r4-xpmj-mj65 HIGH74.5.3
GHSA-q2c6-c6pm-g3gh HIGH74.5.3

version "1.0.4"
resolved "https://registry.yarnpkg.com/basic-auth/-/basic-auth-1.0.4.tgz#030935b01de7c9b94a824b29f3fccb750d3a5290"

bcrypt-pbkdf@^1.0.0:

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

diff 1.4.0 / yarn.lock

Total vulnerabilities: 1

Critical: 0High: 1Medium: 0Low: 0
Vulnerability ID Severity CVSSFixed in
GHSA-h6ch-v84p-w6p9 HIGH73.5.0

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant