Skip to content

Instantly share code, notes, and snippets.

@dlorenc
Created December 28, 2020 16:47
Show Gist options
  • Save dlorenc/f26d7a54a9a39c8d87a828bd894a4df6 to your computer and use it in GitHub Desktop.
Save dlorenc/f26d7a54a9a39c8d87a828bd894a4df6 to your computer and use it in GitHub Desktop.
$ snyk test
Testing /Users/dlorenc/go/src/github.com/grafana/grafana...
Tested 461 dependencies for known issues, found 12 issues, 22 vulnerable paths.
Issues to fix by upgrading:
Upgrade angular@1.6.9 to angular@1.8.0 to fix
✗ Cross-site Scripting (XSS) [Medium Severity][https://snyk.io/vuln/SNYK-JS-ANGULAR-570058] in angular@1.6.9
introduced by angular@1.6.9
✗ Cross-site Scripting (XSS) [High Severity][https://snyk.io/vuln/SNYK-JS-ANGULAR-572020] in angular@1.6.9
introduced by angular@1.6.9
✗ Prototype Pollution [High Severity][https://snyk.io/vuln/SNYK-JS-ANGULAR-534884] in angular@1.6.9
introduced by angular@1.6.9
Upgrade lodash@4.17.19 to lodash@4.17.20 to fix
✗ Prototype Pollution [High Severity][https://snyk.io/vuln/SNYK-JS-LODASH-590103] in lodash@4.17.19
introduced by lodash@4.17.19 and 7 other path(s)
Upgrade react-popper@1.3.3 to react-popper@1.3.4 to fix
✗ Denial of Service [Medium Severity][https://snyk.io/vuln/SNYK-JS-NODEFETCH-674311] in node-fetch@1.7.3
introduced by react-popper@1.3.3 > create-react-context@0.2.2 > fbjs@0.8.17 > isomorphic-fetch@2.2.1 > node-fetch@1.7.3
Issues with no direct upgrade or patch:
✗ Regular Expression Denial of Service (ReDoS) [High Severity][https://snyk.io/vuln/SNYK-JS-ACORN-559469] in acorn@5.7.3
introduced by rst2html@1.0.4 > restructured@0.0.11 > power-assert@1.6.1 > power-assert-formatter@1.4.1 > power-assert-context-reducer-ast@1.2.0 > acorn@5.7.3
This issue was fixed in versions: 5.7.4, 6.4.1, 7.1.1
✗ Prototype Pollution [Medium Severity][https://snyk.io/vuln/SNYK-JS-DOTPROP-543489] in dot-prop@4.2.0
introduced by nodemon@2.0.2 > update-notifier@2.5.0 > configstore@3.1.2 > dot-prop@4.2.0
This issue was fixed in versions: 4.2.1, 5.1.1
✗ Prototype Pollution [High Severity][https://snyk.io/vuln/SNYK-JS-INI-1048974] in ini@1.3.5
introduced by nodemon@2.0.2 > update-notifier@2.5.0 > is-installed-globally@0.1.0 > global-dirs@0.1.1 > ini@1.3.5 and 2 other path(s)
This issue was fixed in versions: 1.3.6
✗ Prototype Pollution [Medium Severity][https://snyk.io/vuln/SNYK-JS-MINIMIST-559764] in minimist@1.2.0
introduced by nodemon@2.0.2 > update-notifier@2.5.0 > latest-version@3.1.0 > package-json@4.0.1 > registry-auth-token@3.4.0 > rc@1.2.8 > minimist@1.2.0 and 1 other path(s)
This issue was fixed in versions: 0.2.1, 1.2.3
✗ Regular Expression Denial of Service (ReDoS) [High Severity][https://snyk.io/vuln/SNYK-JS-UAPARSERJS-1023599] in ua-parser-js@0.7.20
introduced by react-popper@1.3.3 > create-react-context@0.2.2 > fbjs@0.8.17 > ua-parser-js@0.7.20
This issue was fixed in versions: 0.7.23
✗ Regular Expression Denial of Service (ReDoS) [High Severity][https://snyk.io/vuln/SNYK-JS-UAPARSERJS-610226] in ua-parser-js@0.7.20
introduced by react-popper@1.3.3 > create-react-context@0.2.2 > fbjs@0.8.17 > ua-parser-js@0.7.20
This issue was fixed in versions: 0.7.22
✗ Prototype Pollution [Medium Severity][https://snyk.io/vuln/SNYK-JS-UNDEFSAFE-548940] in undefsafe@2.0.2
introduced by nodemon@2.0.2 > undefsafe@2.0.2
This issue was fixed in versions: 2.0.3
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment