Skip to content

Conversation

TheKingTermux
Copy link
Owner

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • package.json
⚠️ Warning
Failed to update the package-lock.json, please update manually before merging.

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
critical severity 909/1000
Why? Mature exploit, Has a fix available, CVSS 9.6
Heap-based Buffer Overflow
SNYK-JS-SHARP-5922108
No Mature

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: sharp-cli The new version differs by 9 commits.

See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Learn about vulnerability in an interactive lesson of Snyk Learn.

The following vulnerabilities are fixed with an upgrade:
- https://snyk.io/vuln/SNYK-JS-SHARP-5922108
@TheKingTermux TheKingTermux self-assigned this Nov 29, 2023
@TheKingTermux TheKingTermux added Auto Updated Label for Auto Updated Need Update Label for Automatic Bot Update if necessary Security Label for Security Issues Auto Create Issues Label for Auto Created Issues Critical This label for Security Severity only labels Nov 29, 2023
@TheKingTermux TheKingTermux merged commit 64325ff into main Nov 29, 2023
@TheKingTermux TheKingTermux deleted the snyk-fix-9383fbce92a7162656d6b64a10de4b4e branch November 29, 2023 15:22
@TheKingTermux TheKingTermux added Bot Update Label for bot update automaticaly dependencies Pull requests that update a dependency file Solved Label for solved issues / Pr and removed Auto Create Issues Label for Auto Created Issues labels Nov 30, 2023
@github-actions github-actions bot locked as resolved and limited conversation to collaborators Dec 3, 2023
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

Auto Updated Label for Auto Updated Bot Update Label for bot update automaticaly Critical This label for Security Severity only dependencies Pull requests that update a dependency file Need Update Label for Automatic Bot Update if necessary Security Label for Security Issues Solved Label for solved issues / Pr

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Crash in HeaderParser in dicer

2 participants