Bump the npm-dependencies group across 1 directory with 12 updates - #1025
dependabot[bot] wants to merge 1 commit into
Pull Request #1025 Alerts: Complete with warnings WARNING: Free tier size exceeded
| Report | Status | Message |
|---|---|---|
| PR #1025 Alerts | Found 5 project alerts |
Pull request alerts notify when new issues are detected between the diff of the pull request and it's target branch.
Details
Warning
Review the following alerts detected in dependencies.
According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.
| Action | Severity | Alert (click "▶" to expand/collapse) |
|---|---|---|
| Warn | High CVE: Rollup 4 has Arbitrary File Write via Path TraversalCVE: GHSA-mw96-cpmx-2vgc Rollup 4 has Arbitrary File Write via Path Traversal (HIGH) Affected versions: < 2.80.0; >= 3.0.0 < 3.30.0; >= 4.0.0 < 4.59.0 Patched version: 4.59.0 From: packages/cfsite/package-lock.json → ℹ Read more on: This package | This alert | What is a CVE?
|
|
| Warn | High CVE: Undici has Unhandled Exception in WebSocket Client Due to Invalid server_max_window_bits ValidationAffected versions: < 6.24.0; >= 7.0.0 < 7.24.0 Patched version: 7.24.0 From: packages/cfsite/package-lock.json → ℹ Read more on: This package | This alert | What is a CVE?
|
|
| Warn | High CVE: Undici has Unbounded Memory Consumption in WebSocket permessage-deflate DecompressionAffected versions: < 6.24.0; >= 7.0.0 < 7.24.0 Patched version: 7.24.0 From: packages/cfsite/package-lock.json → ℹ Read more on: This package | This alert | What is a CVE?
|
|
| Warn | High CVE: Undici: Malicious WebSocket 64-bit length overflows parser and crashes the clientAffected versions: >= 6.0.0 < 6.24.0; >= 7.0.0 < 7.24.0 Patched version: 7.24.0 From: packages/cfsite/package-lock.json → ℹ Read more on: This package | This alert | What is a CVE?
|
|
| Warn | Obfuscated code: npm
|