-
Notifications
You must be signed in to change notification settings - Fork 8
/
Copy pathyarn-audit-known-issues
4 lines (4 loc) · 1.15 KB
/
yarn-audit-known-issues
1
2
3
4
{"value":"@types/helmet","children":{"ID":"@types/helmet (deprecation)","Issue":"This is a stub types definition. helmet provides its own type definitions, so you do not need this installed.","Severity":"moderate","Vulnerable Versions":"4.0.0","Tree Versions":["4.0.0"],"Dependents":["rpe-expressjs-template@workspace:."]}}
{"value":"axios","children":{"ID":1103618,"Issue":"axios Requests Vulnerable To Possible SSRF and Credential Leakage via Absolute URL","URL":"https://github.com/advisories/GHSA-jr5f-v2jv-69x6","Severity":"high","Vulnerable Versions":">=1.0.0 <1.8.2","Tree Versions":["1.7.4"],"Dependents":["rpe-expressjs-template@workspace:."]}}
{"value":"cookie","children":{"ID":1103907,"Issue":"cookie accepts cookie name, path, and domain with out of bounds characters","URL":"https://github.com/advisories/GHSA-pxg6-pf52-xh8x","Severity":"low","Vulnerable Versions":"<0.7.0","Tree Versions":["0.4.0"],"Dependents":["csurf@npm:1.11.0"]}}
{"value":"csurf","children":{"ID":"csurf (deprecation)","Issue":"Please use another csrf package","Severity":"moderate","Vulnerable Versions":"1.11.0","Tree Versions":["1.11.0"],"Dependents":["rpe-expressjs-template@workspace:."]}}