Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
12 changes: 1 addition & 11 deletions yarn-audit-known-issues
Original file line number Diff line number Diff line change
Expand Up @@ -4,18 +4,8 @@
{"value":"@opentelemetry/core","children":{"ID":1120821,"Issue":"OpenTelemetry Core: Unbounded memory allocation in W3C Baggage propagation","URL":"https://github.com/advisories/GHSA-8988-4f7v-96qf","Severity":"moderate","Vulnerable Versions":"<2.8.0","Tree Versions":["1.30.1","2.6.1","2.7.1"],"Dependents":["@azure/opentelemetry-instrumentation-azure-sdk@npm:1.0.0-beta.10","applicationinsights@npm:3.15.0","applicationinsights@virtual:5a0f6155bafcfb260ff312e0cfdce3363ab16445b55509b7a00cf1d029450c4192ff731c095c71c71a2de5d1a6c59e6501cd5511219b6aee1b73bc7df4e683c8#npm:2.9.8"]}}
{"value":"@opentelemetry/propagator-jaeger","children":{"ID":1124011,"Issue":"OpenTelemetry JavaScript: Denial of service in `JaegerPropagator` via unhandled exception on a malformed header","URL":"https://github.com/advisories/GHSA-45rx-2jwx-cxfr","Severity":"high","Vulnerable Versions":"<2.9.0","Tree Versions":["2.7.1"],"Dependents":["@opentelemetry/sdk-node@virtual:7d28986b6beca5611db0460c59742827c485e9e4ad2f65e45fb8287e62953517d20a6f66193b45448e6d2e95136688c6edcf391e563ea2038165c9fdaf765dae#npm:0.217.0"]}}
{"value":"ajv","children":{"ID":1113715,"Issue":"ajv has ReDoS when using `$data` option","URL":"https://github.com/advisories/GHSA-2g4f-4pwh-qvx6","Severity":"moderate","Vulnerable Versions":">=7.0.0-alpha.0 <8.18.0","Tree Versions":["8.17.1"],"Dependents":["schema-utils@npm:4.3.3"]}}
{"value":"axios","children":{"ID":1123882,"Issue":"Axios: Excessive recursion in formDataToJSON can cause denial of service","URL":"https://github.com/advisories/GHSA-42h9-826w-cgv3","Severity":"moderate","Vulnerable Versions":">=1.0.0 <1.18.0","Tree Versions":["1.16.1"],"Dependents":["opal-frontend@workspace:."]}}
{"value":"axios","children":{"ID":1123884,"Issue":"Axios: Prototype pollution auth subfields can inject Basic auth","URL":"https://github.com/advisories/GHSA-xj6q-8x83-jv6g","Severity":"moderate","Vulnerable Versions":">=1.15.2 <1.18.0","Tree Versions":["1.16.1"],"Dependents":["opal-frontend@workspace:."]}}
{"value":"axios","children":{"ID":1123885,"Issue":"Axios: Deep formToJSON Key Recursion Can Cause Denial of Service","URL":"https://github.com/advisories/GHSA-pmv8-rq9r-6j72","Severity":"moderate","Vulnerable Versions":">=1.0.0 <1.18.0","Tree Versions":["1.16.1"],"Dependents":["opal-frontend@workspace:."]}}
{"value":"axios","children":{"ID":1123957,"Issue":"Axios: Fetch adapter `ReadableStream` uploads bypass `maxBodyLength`","URL":"https://github.com/advisories/GHSA-jqh4-m9w3-8hp9","Severity":"moderate","Vulnerable Versions":">=1.7.0 <1.18.0","Tree Versions":["1.16.1"],"Dependents":["opal-frontend@workspace:."]}}
{"value":"axios","children":{"ID":1123959,"Issue":"Axios: Prototype pollution gadgets can alter axios request construction","URL":"https://github.com/advisories/GHSA-mmx7-hfxf-jppx","Severity":"moderate","Vulnerable Versions":">=1.0.0 <1.18.0","Tree Versions":["1.16.1"],"Dependents":["opal-frontend@workspace:."]}}
{"value":"axios","children":{"ID":1123961,"Issue":"Axios: NO_PROXY bypass for 0.0.0.0 local addresses in axios","URL":"https://github.com/advisories/GHSA-f4gw-2p7v-4548","Severity":"moderate","Vulnerable Versions":">=1.15.0 <1.18.0","Tree Versions":["1.16.1"],"Dependents":["opal-frontend@workspace:."]}}
{"value":"axios","children":{"ID":1123967,"Issue":"Axios Node HTTP adapter can use an inherited proxy after interceptor config cloning","URL":"https://github.com/advisories/GHSA-gcfj-64vw-6mp9","Severity":"high","Vulnerable Versions":">=1.15.2 <1.18.0","Tree Versions":["1.16.1"],"Dependents":["opal-frontend@workspace:."]}}
{"value":"axios","children":{"ID":1123969,"Issue":"Axios form serializer maxDepth bypass via {} metatoken","URL":"https://github.com/advisories/GHSA-hcpx-6fm6-wx23","Severity":"moderate","Vulnerable Versions":">=1.15.1 <1.18.0","Tree Versions":["1.16.1"],"Dependents":["opal-frontend@workspace:."]}}
{"value":"axios","children":{"ID":1123971,"Issue":"Axios: Nested axios option objects can consume polluted prototype values","URL":"https://github.com/advisories/GHSA-7q8q-rj6j-mhjq","Severity":"moderate","Vulnerable Versions":">=1.0.0 <1.18.0","Tree Versions":["1.16.1"],"Dependents":["opal-frontend@workspace:."]}}
{"value":"axios","children":{"ID":1123973,"Issue":"Axios: HTTP/2 streamed uploads bypass `maxBodyLength`","URL":"https://github.com/advisories/GHSA-mwf2-3pr3-8698","Severity":"moderate","Vulnerable Versions":">=1.13.0 <1.18.0","Tree Versions":["1.16.1"],"Dependents":["opal-frontend@workspace:."]}}
{"value":"body-parser","children":{"ID":1123976,"Issue":"body-parser vulnerable to denial of service when invalid limit value silently disables size enforcement","URL":"https://github.com/advisories/GHSA-v422-hmwv-36x6","Severity":"low","Vulnerable Versions":">=2.0.0 <2.3.0","Tree Versions":["2.2.2"],"Dependents":["opal-frontend@workspace:."]}}
{"value":"form-data","children":{"ID":1120743,"Issue":"form-data: CRLF injection in form-data via unescaped multipart field names and filenames","URL":"https://github.com/advisories/GHSA-hmw2-7cc7-3qxx","Severity":"high","Vulnerable Versions":">=4.0.0 <4.0.6","Tree Versions":["4.0.4","4.0.5"],"Dependents":["axios@npm:1.16.1","superagent@npm:10.2.2"]}}
{"value":"form-data","children":{"ID":1120743,"Issue":"form-data: CRLF injection in form-data via unescaped multipart field names and filenames","URL":"https://github.com/advisories/GHSA-hmw2-7cc7-3qxx","Severity":"high","Vulnerable Versions":">=4.0.0 <4.0.6","Tree Versions":["4.0.4"],"Dependents":["superagent@npm:10.2.2"]}}
{"value":"ip-address","children":{"ID":1118827,"Issue":"ip-address has XSS in Address6 HTML-emitting methods","URL":"https://github.com/advisories/GHSA-v2v4-37r5-5v8g","Severity":"moderate","Vulnerable Versions":"<=10.1.0","Tree Versions":["9.0.5"],"Dependents":["socks@npm:2.8.3"]}}
{"value":"js-yaml","children":{"ID":1123911,"Issue":"js-yaml: YAML merge-key chains can force quadratic CPU consumption","URL":"https://github.com/advisories/GHSA-52cp-r559-cp3m","Severity":"high","Vulnerable Versions":">=4.0.0 <4.3.0","Tree Versions":["4.2.0"],"Dependents":["@hmcts/info-provider@virtual:a675e69e845cebadc36cee9a38065a1960f4aab74a9924442784ad5431c94d53a7f1d4962754c45f81da4004ef26e80c7c562b8c146cee281975b943df474817#npm:1.4.0"]}}
{"value":"minimatch","children":{"ID":1113465,"Issue":"minimatch has a ReDoS via repeated wildcards with non-matching literal in pattern","URL":"https://github.com/advisories/GHSA-3ppc-4f35-3m26","Severity":"high","Vulnerable Versions":">=9.0.0 <9.0.6","Tree Versions":["9.0.5"],"Dependents":["mocha@npm:11.7.6"]}}
Expand Down
45 changes: 21 additions & 24 deletions yarn.lock
Original file line number Diff line number Diff line change
Expand Up @@ -9240,27 +9240,15 @@ __metadata:
languageName: node
linkType: hard

"axios@npm:^1.17.0":
version: 1.18.0
resolution: "axios@npm:1.18.0"
dependencies:
follow-redirects: "npm:^1.16.0"
form-data: "npm:^4.0.5"
https-proxy-agent: "npm:^5.0.1"
proxy-from-env: "npm:^2.1.0"
checksum: 10/586a1a9534531c6ec4ee8fbab07a536ecaa8d29bd16b40ab0f9fce361fcd24da1538a54aadde0562f08f30b55bf80f9b7ededf1987e6506f722e1fb338b09d5d
languageName: node
linkType: hard

"axios@npm:^1.6.2":
version: 1.16.1
resolution: "axios@npm:1.16.1"
"axios@npm:^1.17.0, axios@npm:^1.6.2":
version: 1.19.0
resolution: "axios@npm:1.19.0"
dependencies:
follow-redirects: "npm:^1.16.0"
form-data: "npm:^4.0.5"
form-data: "npm:^4.0.6"
https-proxy-agent: "npm:^5.0.1"
proxy-from-env: "npm:^2.1.0"
checksum: 10/9b6218cf96321cfbbf8f160658d695367114bcf4fb62492bdc1ccd647f184b5c71ae400e5ecaaf41079bc561de2ecbaf1fec63f398b3ec53389beff7694df64c
checksum: 10/d27e263b003f2dc1e6d0e2ab062dbc7c2b15668c25723e1e2072f139505c1fbd1f8cffef77d5ec05bb8e3cefa6fc5325c6446e747669fd95d85519529fa0db0b
languageName: node
linkType: hard

Expand Down Expand Up @@ -12704,16 +12692,16 @@ __metadata:
languageName: node
linkType: hard

"form-data@npm:^4.0.5":
version: 4.0.5
resolution: "form-data@npm:4.0.5"
"form-data@npm:^4.0.6":
version: 4.0.6
resolution: "form-data@npm:4.0.6"
dependencies:
asynckit: "npm:^0.4.0"
combined-stream: "npm:^1.0.8"
es-set-tostringtag: "npm:^2.1.0"
hasown: "npm:^2.0.2"
mime-types: "npm:^2.1.12"
checksum: 10/52ecd6e927c8c4e215e68a7ad5e0f7c1031397439672fd9741654b4a94722c4182e74cc815b225dcb5be3f4180f36428f67c6dd39eaa98af0dcfdd26c00c19cd
hasown: "npm:^2.0.4"
mime-types: "npm:^2.1.35"
checksum: 10/de6614c8537c92fa5fa3ee7e827758f98f5a9c033f348b7de81855ef36e5cb867e75d9f405d9483ab8d724a4a20d4e79926a299fa8dbba38f530eb659f0884e4
languageName: node
linkType: hard

Expand Down Expand Up @@ -13240,6 +13228,15 @@ __metadata:
languageName: node
linkType: hard

"hasown@npm:^2.0.4":
version: 2.0.4
resolution: "hasown@npm:2.0.4"
dependencies:
function-bind: "npm:^1.1.2"
checksum: 10/13823863ae48161068b4c51606a3128451c66f14545a5169d667fe9fca168dcd38c27570c7a299e32ef844b8da3d55def7fe88602f8970d4311fb543ee88001a
languageName: node
linkType: hard

"he@npm:^1.2.0":
version: 1.2.0
resolution: "he@npm:1.2.0"
Expand Down Expand Up @@ -15599,7 +15596,7 @@ __metadata:
languageName: node
linkType: hard

"mime-types@npm:^2.1.12, mime-types@npm:^2.1.27, mime-types@npm:^2.1.31, mime-types@npm:~2.1.17, mime-types@npm:~2.1.19, mime-types@npm:~2.1.24, mime-types@npm:~2.1.34":
"mime-types@npm:^2.1.12, mime-types@npm:^2.1.27, mime-types@npm:^2.1.31, mime-types@npm:^2.1.35, mime-types@npm:~2.1.17, mime-types@npm:~2.1.19, mime-types@npm:~2.1.24, mime-types@npm:~2.1.34":
version: 2.1.35
resolution: "mime-types@npm:2.1.35"
dependencies:
Expand Down