-
-
Notifications
You must be signed in to change notification settings - Fork 3.1k
Open
Labels
area: securityinvolving vulnerabilitiesinvolving vulnerabilitiesstatus: accepting prsMocha can use your help with this one!Mocha can use your help with this one!
Description
Tooling Suggestion Checklist
- I have tried restarting my IDE and the issue persists.
- I have pulled the latest
masterbranch of the repository. - I have read and agree to Mocha's Code of Conduct and Contributing Guidelines
- I have searched for related issues and issues with the
faqlabel, but none matched my issue. - I want to provide a PR to resolve this
Overview
Running npm audit reports 58 vulnerabilities (34 moderate, 23 high, 1 critical):
@babel/traverse <7.23.2axios 0.8.1 - 1.5.1browserify-sign 2.6.0 - 4.2.1debug <=2.6.8engine.io 5.1.0 - 6.4.1get-func-name <2.0.1got <=11.8.3http-cache-semantics <4.1.1liquidjs <10.0.0markdown-it <12.3.2ms <2.0.0nth-check <2.0.1nunjucks <3.2.4postcss <8.4.31request *semver <=5.7.1 || 6.0.0 - 6.3.0 || 7.0.0 - 7.5.1semver-regex <=3.1.3socket.io-parser 4.0.4 - 4.2.2taffydb *tough-cookie <4.1.3trim-newlines <3.0.1word-wrap <1.2.4
After running npm audit fix locally, npm audit reports 50 vulnerabilities (30 moderate, 20 high):
axios 0.8.1 - 1.5.1debug <=2.6.8got <=11.8.3http-cache-semantics <4.1.1liquidjs <10.0.0markdown-it <12.3.2ms <2.0.0nth-check <2.0.1postcss <8.4.31request *semver-regex <=3.1.3taffydb *tough-cookie <4.1.3trim-newlines <3.0.1
Additional Info
It's the nature of package vulnerability alerts that most or all of these are false flags. But it's good practice to stay up-to-date just in case.
Metadata
Metadata
Assignees
Labels
area: securityinvolving vulnerabilitiesinvolving vulnerabilitiesstatus: accepting prsMocha can use your help with this one!Mocha can use your help with this one!
Type
Projects
Status
No status