Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Bug]: extension deps security vulnerabilities #878

Open
ctf0 opened this issue Oct 18, 2024 · 1 comment
Open

[Bug]: extension deps security vulnerabilities #878

ctf0 opened this issue Oct 18, 2024 · 1 comment
Assignees
Labels
bug Something isn't working Stale Stale label

Comments

@ctf0
Copy link

ctf0 commented Oct 18, 2024

Description

i ran osv scanner and i found some security vulnerabilities with the the ext deps

| https://osv.dev/GHSA-93q8-gq69-wqmw │ 7.5 │ npm │ ansi-regex │ 3.0.0 │
https://osv.dev/GHSA-93q8-gq69-wqmw │ 7.5 │ npm │ ansi-regex │ 4.1.0 │
https://osv.dev/GHSA-67hx-6x53-jw92 │ 9.3 │ npm │ babel-traverse │ 6.26.0 │
https://osv.dev/GHSA-cwfw-4gq5-mrqx │ │ npm │ braces │ 1.8.5 │
https://osv.dev/GHSA-g95f-p29q-9xw4 │ 3.7 │ npm │ braces │ 1.8.5 │
https://osv.dev/GHSA-grv7-fg5c-xmjg │ 7.5 │ npm │ braces │ 1.8.5 │
https://osv.dev/GHSA-grv7-fg5c-xmjg │ 7.5 │ npm │ braces │ 2.3.2 │
https://osv.dev/GHSA-grv7-fg5c-xmjg │ 7.5 │ npm │ braces │ 3.0.2 │
https://osv.dev/GHSA-gxpj-cx7g-858c │ 3.7 │ npm │ debug │ 4.2.0 │
https://osv.dev/GHSA-w573-4hg7-7wgq │ 7.5 │ npm │ decode-uri-component │ 0.2.0 │
https://osv.dev/GHSA-ww39-953v-wcq6 │ 7.5 │ npm │ glob-parent │ 5.1.1 │
https://osv.dev/GHSA-9c47-m6qq-7p4h │ 7.1 │ npm │ json5 │ 0.5.1 │
https://osv.dev/GHSA-29mw-wpgm-hmr9 │ 5.3 │ npm │ lodash │ 4.17.20 │
https://osv.dev/GHSA-35jh-r3h4-6jhm │ 7.2 │ npm │ lodash │ 4.17.20 │
https://osv.dev/GHSA-952p-6rrq-rcjv │ 5.3 │ npm │ micromatch │ 2.3.11 │
https://osv.dev/GHSA-952p-6rrq-rcjv │ 5.3 │ npm │ micromatch │ 3.1.10 │
https://osv.dev/GHSA-f8q6-p94x-37v3 │ 7.5 │ npm │ minimatch │ 3.0.4 │
https://osv.dev/GHSA-xvch-5gv4-984h │ 9.8 │ npm │ minimist │ 1.2.5 │
https://osv.dev/GHSA-qrpm-p2h7-hrv2 │ 5.5 │ npm │ nanoid │ 3.1.12 │
https://osv.dev/GHSA-hj48-42vr-x3v9 │ 5.3 │ npm │ path-parse │ 1.0.5 │
https://osv.dev/GHSA-gcx4-mw62-g8wm │ 8.3 │ npm │ rollup │ 0.41.6 │

Expected Behavior

...

Actual Behavior

...

Additional Context

npm

@ctf0 ctf0 added the bug Something isn't working label Oct 18, 2024
Copy link
Contributor

This issue is stale because it has been open 30 days with no activity. Remove stale label or comment or this will be closed in 5 days

@github-actions github-actions bot added the Stale Stale label label Dec 18, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Something isn't working Stale Stale label
Projects
None yet
Development

No branches or pull requests

1 participant