Skip to content

Conversation

@titanism
Copy link

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to fix one or more vulnerable packages in the `yarn` dependencies of this project.

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • example/package.json

Note for zero-installs users

If you are using the Yarn feature zero-installs that was introduced in Yarn V2, note that this PR does not update the .yarn/cache/ directory meaning this code cannot be pulled and immediately developed on as one would expect for a zero-install project - you will need to run yarn to update the contents of the ./yarn/cache directory.
If you are not using zero-install you can ignore this as your flow should likely be unchanged.

⚠️ Warning
Failed to update the yarn.lock, please update manually before merging. 

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
critical severity 858/1000
Why? Proof of Concept exploit, Recently disclosed, Has a fix available, CVSS 9.3
Authentication Bypass
SNYK-JS-HAWK-6969142
No Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic


Note: This is a default PR template raised by Snyk. Find out more about how you can customise Snyk PRs in our documentation.

Learn how to fix vulnerabilities with free interactive lessons:

🦉 Authentication Bypass

@socket-security
Copy link

New and removed dependencies detected. Learn more about Socket for GitHub ↗︎

Package New capabilities Transitives Size Publisher
npm/accepts@1.3.8 None 0 16.8 kB dougwilson
npm/babel-preset-fbjs@3.4.0 environment Transitive: filesystem, shell, unsafe +83 10.6 MB gweterings
npm/cli-cursor@3.1.0 None +2 17.1 kB sindresorhus
npm/commander@2.20.3 filesystem, shell 0 62.4 kB abetomo
npm/compressible@2.0.18 None 0 7.36 kB dougwilson
npm/compression@1.7.4 Transitive: environment, filesystem, network +3 117 kB dougwilson
npm/connect@3.7.0 environment, network +2 105 kB dougwilson
npm/cross-spawn@6.0.5 environment, filesystem, shell +3 30.9 kB satazor
npm/error-ex@1.3.2 None +1 13.1 kB qix
npm/errorhandler@1.5.1 environment, filesystem 0 15.2 kB dougwilson
npm/event-target-shim@5.0.1 None 0 189 kB mysticatea
npm/finalhandler@1.1.2 environment +3 43.5 kB dougwilson
npm/fs-extra@8.1.0 filesystem +2 149 kB ryanzim
npm/image-size@0.6.3 filesystem 0 27.5 kB netroy
npm/joi@17.13.1 None +5 670 kB marsup
npm/mime-db@1.52.0 None 0 206 kB dougwilson
npm/mime-types@2.1.35 None 0 18.3 kB dougwilson
npm/mime@2.6.0 None 0 60.1 kB broofa
npm/negotiator@0.6.3 None 0 27.4 kB dougwilson
npm/on-headers@1.0.2 None 0 7.54 kB dougwilson
npm/parseurl@1.3.3 None 0 10.3 kB dougwilson
npm/plist@3.1.0 None +3 1.2 MB mreinstein
npm/react-native@0.69.12 environment, network Transitive: eval, filesystem, shell, unsafe +451 241 MB react-native-bot
npm/readable-stream@3.6.2 environment +2 170 kB matteo.collina
npm/regenerate@1.4.2 None 0 49.2 kB mathias
npm/serve-static@1.15.0 None +1 33.1 kB dougwilson
npm/shell-quote@1.8.1 None 0 45 kB ljharb
npm/statuses@1.5.0 None 0 11 kB dougwilson
npm/through2@2.0.5 None 0 9.65 kB rvagg
npm/vary@1.1.2 None 0 8.75 kB dougwilson
npm/walker@1.0.8 filesystem 0 5.8 kB daaku
npm/write-file-atomic@2.4.3 None +1 22.2 kB isaacs
npm/ws@6.2.2 network 0 102 kB lpinca

🚮 Removed packages: npm/accepts@1.2.13, npm/align-text@0.1.4, npm/ansi@0.3.1, npm/array-uniq@1.0.3, npm/arrify@1.0.1, npm/babel-helper-builder-binary-assignment-operator-visitor@6.22.0, npm/babel-plugin-syntax-class-constructor-call@6.18.0, npm/babel-plugin-syntax-decorators@6.13.0, npm/babel-plugin-syntax-do-expressions@6.13.0, npm/babel-plugin-syntax-exponentiation-operator@6.13.0, npm/babel-plugin-syntax-export-extensions@6.13.0, npm/babel-plugin-syntax-function-bind@6.13.0, npm/babel-plugin-transform-class-constructor-call@6.22.0, npm/babel-plugin-transform-decorators-legacy@1.3.4, npm/babel-plugin-transform-do-expressions@6.22.0, npm/babel-plugin-transform-es2015-block-scoped-functions@6.22.0, npm/babel-plugin-transform-es2015-object-super@6.22.0, npm/babel-plugin-transform-es3-member-expression-literals@6.22.0, npm/babel-plugin-transform-es3-property-literals@6.22.0, npm/babel-plugin-transform-exponentiation-operator@6.22.0, npm/babel-plugin-transform-export-extensions@6.22.0, npm/babel-plugin-transform-function-bind@6.22.0, npm/babel-preset-react-native-stage-0@1.0.1, npm/combined-stream@1.0.5, npm/mime-db@1.26.0, npm/mime-types@2.1.11, npm/mime@1.3.4, npm/on-headers@1.0.1, npm/parseurl@1.3.1, npm/plist@1.2.0, npm/react-native@0.40.0, npm/readable-stream@1.1.14, npm/string-width@1.0.2, npm/tweetnacl@0.14.5, npm/xtend@4.0.1

View full report↗︎

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

3 participants