@@ -5260,12 +5260,13 @@ unsupported strategy "force" - must be one of: in-place, relax, override
52605260
52615261[TestCommand/fix_non-interactive_in-place_package-lock.json - 1]
52625262Scanning <tempdir>/package-lock.json...
5263- Found 11 vulnerabilities matching the filter
5264- Can fix 3/11 matching vulnerabilities by changing 3 dependencies
5263+ Found 12 vulnerabilities matching the filter
5264+ Can fix 4/12 matching vulnerabilities by changing 4 dependencies
5265+ UPGRADED-PACKAGE: ajv,6.12.6,6.14.0
52655266UPGRADED-PACKAGE: brace-expansion,1.1.11,1.1.12
52665267UPGRADED-PACKAGE: concat-stream,1.5.0,1.6.1
52675268UPGRADED-PACKAGE: hosted-git-info,2.1.4,2.8.9
5268- FIXED-VULN-IDS: GHSA-43f8-2h32-f4cj,GHSA-g74r-ffvr-5q9f,GHSA-v6h2-p8h4-qcjw
5269+ FIXED-VULN-IDS: GHSA-2g4f-4pwh-qvx6,GHSA- 43f8-2h32-f4cj,GHSA-g74r-ffvr-5q9f,GHSA-v6h2-p8h4-qcjw
52695270REMAINING-VULNS: 8
52705271UNFIXABLE-VULNS: 8
52715272Rewriting <tempdir>/package-lock.json...
@@ -5292,9 +5293,9 @@ Rewriting <tempdir>/package-lock.json...
52925293 }
52935294 },
52945295 "node_modules/ajv": {
5295- "version": "6.12.6 ",
5296- "resolved": "https://registry.npmjs.org/ajv/-/ajv-6.12.6 .tgz",
5297- "integrity": "sha512-j3fVLgvTo527anyYyJOGTYJbG+vnnQYvE0m5mmkc1TK+nxAppkCLMIL0aZ4dblVCNoGShhm+kzE4ZUykBoMg4g ==",
5296+ "version": "6.14.0 ",
5297+ "resolved": "https://registry.npmjs.org/ajv/-/ajv-6.14.0 .tgz",
5298+ "integrity": "sha512-IWrosm/yrn43eiKqkfkHis7QioDleaXQHdDVPKg0FSwwd/DuvyX79TZnFOnYpB7dcsFAMmtFztZuXPDvSePkFw ==",
52985299 "dependencies": {
52995300 "fast-deep-equal": "^3.1.1",
53005301 "fast-json-stable-stringify": "^2.0.0",
@@ -6230,9 +6231,9 @@ Rewriting <tempdir>/package-lock.json...
62306231 },
62316232 "dependencies": {
62326233 "ajv": {
6233- "version": "6.12.6 ",
6234- "resolved": "https://registry.npmjs.org/ajv/-/ajv-6.12.6 .tgz",
6235- "integrity": "sha512-j3fVLgvTo527anyYyJOGTYJbG+vnnQYvE0m5mmkc1TK+nxAppkCLMIL0aZ4dblVCNoGShhm+kzE4ZUykBoMg4g ==",
6234+ "version": "6.14.0 ",
6235+ "resolved": "https://registry.npmjs.org/ajv/-/ajv-6.14.0 .tgz",
6236+ "integrity": "sha512-IWrosm/yrn43eiKqkfkHis7QioDleaXQHdDVPKg0FSwwd/DuvyX79TZnFOnYpB7dcsFAMmtFztZuXPDvSePkFw ==",
62366237 "requires": {
62376238 "fast-deep-equal": "^3.1.1",
62386239 "fast-json-stable-stringify": "^2.0.0",
@@ -7015,6 +7016,15 @@ Rewriting <tempdir>/package-lock.json...
70157016 "name": "ajv",
70167017 "version": "6.12.6"
70177018 }
7019+ ]
7020+ },
7021+ {
7022+ "id": "GHSA-3ppc-4f35-3m26",
7023+ "packages": [
7024+ {
7025+ "name": "minimatch",
7026+ "version": "3.1.2"
7027+ }
70187028 ],
70197029 "unactionable": true
70207030 },
@@ -7117,6 +7127,27 @@ Rewriting <tempdir>/package-lock.json...
71177127 }
71187128 ],
71197129 "patches": [
7130+ {
7131+ "packageUpdates": [
7132+ {
7133+ "name": "ajv",
7134+ "versionFrom": "6.12.6",
7135+ "versionTo": "6.14.0",
7136+ "transitive": true
7137+ }
7138+ ],
7139+ "fixed": [
7140+ {
7141+ "id": "GHSA-2g4f-4pwh-qvx6",
7142+ "packages": [
7143+ {
7144+ "name": "ajv",
7145+ "version": "6.12.6"
7146+ }
7147+ ]
7148+ }
7149+ ]
7150+ },
71207151 {
71217152 "packageUpdates": [
71227153 {
@@ -7207,9 +7238,9 @@ Rewriting <tempdir>/package-lock.json...
72077238 }
72087239 },
72097240 "node_modules/ajv": {
7210- "version": "6.12.6 ",
7211- "resolved": "https://registry.npmjs.org/ajv/-/ajv-6.12.6 .tgz",
7212- "integrity": "sha512-j3fVLgvTo527anyYyJOGTYJbG+vnnQYvE0m5mmkc1TK+nxAppkCLMIL0aZ4dblVCNoGShhm+kzE4ZUykBoMg4g ==",
7241+ "version": "6.14.0 ",
7242+ "resolved": "https://registry.npmjs.org/ajv/-/ajv-6.14.0 .tgz",
7243+ "integrity": "sha512-IWrosm/yrn43eiKqkfkHis7QioDleaXQHdDVPKg0FSwwd/DuvyX79TZnFOnYpB7dcsFAMmtFztZuXPDvSePkFw ==",
72137244 "dependencies": {
72147245 "fast-deep-equal": "^3.1.1",
72157246 "fast-json-stable-stringify": "^2.0.0",
@@ -8145,9 +8176,9 @@ Rewriting <tempdir>/package-lock.json...
81458176 },
81468177 "dependencies": {
81478178 "ajv": {
8148- "version": "6.12.6 ",
8149- "resolved": "https://registry.npmjs.org/ajv/-/ajv-6.12.6 .tgz",
8150- "integrity": "sha512-j3fVLgvTo527anyYyJOGTYJbG+vnnQYvE0m5mmkc1TK+nxAppkCLMIL0aZ4dblVCNoGShhm+kzE4ZUykBoMg4g ==",
8179+ "version": "6.14.0 ",
8180+ "resolved": "https://registry.npmjs.org/ajv/-/ajv-6.14.0 .tgz",
8181+ "integrity": "sha512-IWrosm/yrn43eiKqkfkHis7QioDleaXQHdDVPKg0FSwwd/DuvyX79TZnFOnYpB7dcsFAMmtFztZuXPDvSePkFw ==",
81518182 "requires": {
81528183 "fast-deep-equal": "^3.1.1",
81538184 "fast-json-stable-stringify": "^2.0.0",
@@ -9255,14 +9286,13 @@ Rewriting <tempdir>/pom.xml...
92559286 "strategy": "relax",
92569287 "vulnerabilities": [
92579288 {
9258- "id": "GHSA-2g4f-4pwh-qvx6 ",
9289+ "id": "GHSA-3ppc-4f35-3m26 ",
92599290 "packages": [
92609291 {
9261- "name": "ajv ",
9262- "version": "6.12.6 "
9292+ "name": "minimatch ",
9293+ "version": "3.1.3 "
92639294 }
9264- ],
9265- "unactionable": true
9295+ ]
92669296 },
92679297 {
92689298 "id": "GHSA-43f8-2h32-f4cj",
@@ -9343,6 +9373,15 @@ Rewriting <tempdir>/pom.xml...
93439373 }
93449374 ],
93459375 "fixed": [
9376+ {
9377+ "id": "GHSA-3ppc-4f35-3m26",
9378+ "packages": [
9379+ {
9380+ "name": "minimatch",
9381+ "version": "3.1.3"
9382+ }
9383+ ]
9384+ },
93469385 {
93479386 "id": "GHSA-43f8-2h32-f4cj",
93489387 "packages": [
@@ -9471,11 +9510,11 @@ Rewriting <tempdir>/pom.xml...
94719510[TestCommand/fix_non-interactive_relax_package.json - 1]
94729511Resolving <tempdir>/package.json...
94739512Found 8 vulnerabilities matching the filter
9474- Can fix 3 /8 matching vulnerabilities by changing 1 dependencies
9513+ Can fix 4 /8 matching vulnerabilities by changing 1 dependencies
94759514UPGRADED-PACKAGE: npm-registry-client,6.2.0,^7.5.0
9476- FIXED-VULN-IDS: GHSA-43f8-2h32-f4cj,GHSA-c2qf-rxjj-qqgw,GHSA-c6rq-rjc2-86v2
9477- REMAINING-VULNS: 5
9478- UNFIXABLE-VULNS: 5
9515+ FIXED-VULN-IDS: GHSA-3ppc-4f35-3m26,GHSA- 43f8-2h32-f4cj,GHSA-c2qf-rxjj-qqgw,GHSA-c6rq-rjc2-86v2
9516+ REMAINING-VULNS: 4
9517+ UNFIXABLE-VULNS: 4
94799518Rewriting <tempdir>/package.json...
94809519
94819520---
@@ -9504,12 +9543,13 @@ Rewriting <tempdir>/package.json...
95049543
95059544[TestCommand/fix_non_interactive_in_place_package_lock_json_with_native_data_source - 1]
95069545Scanning <tempdir>/package-lock.json...
9507- Found 11 vulnerabilities matching the filter
9508- Can fix 3/11 matching vulnerabilities by changing 3 dependencies
9546+ Found 12 vulnerabilities matching the filter
9547+ Can fix 4/12 matching vulnerabilities by changing 4 dependencies
9548+ UPGRADED-PACKAGE: ajv,6.12.6,6.14.0
95099549UPGRADED-PACKAGE: brace-expansion,1.1.11,1.1.12
95109550UPGRADED-PACKAGE: concat-stream,1.5.0,1.6.1
95119551UPGRADED-PACKAGE: hosted-git-info,2.1.4,2.8.9
9512- FIXED-VULN-IDS: GHSA-43f8-2h32-f4cj,GHSA-g74r-ffvr-5q9f,GHSA-v6h2-p8h4-qcjw
9552+ FIXED-VULN-IDS: GHSA-2g4f-4pwh-qvx6,GHSA- 43f8-2h32-f4cj,GHSA-g74r-ffvr-5q9f,GHSA-v6h2-p8h4-qcjw
95139553REMAINING-VULNS: 8
95149554UNFIXABLE-VULNS: 8
95159555Rewriting <tempdir>/package-lock.json...
@@ -9536,9 +9576,9 @@ Rewriting <tempdir>/package-lock.json...
95369576 }
95379577 },
95389578 "node_modules/ajv": {
9539- "version": "6.12.6 ",
9540- "resolved": "https://registry.npmjs.org/ajv/-/ajv-6.12.6 .tgz",
9541- "integrity": "sha512-j3fVLgvTo527anyYyJOGTYJbG+vnnQYvE0m5mmkc1TK+nxAppkCLMIL0aZ4dblVCNoGShhm+kzE4ZUykBoMg4g ==",
9579+ "version": "6.14.0 ",
9580+ "resolved": "https://registry.npmjs.org/ajv/-/ajv-6.14.0 .tgz",
9581+ "integrity": "sha512-IWrosm/yrn43eiKqkfkHis7QioDleaXQHdDVPKg0FSwwd/DuvyX79TZnFOnYpB7dcsFAMmtFztZuXPDvSePkFw ==",
95429582 "dependencies": {
95439583 "fast-deep-equal": "^3.1.1",
95449584 "fast-json-stable-stringify": "^2.0.0",
@@ -10474,9 +10514,9 @@ Rewriting <tempdir>/package-lock.json...
1047410514 },
1047510515 "dependencies": {
1047610516 "ajv": {
10477- "version": "6.12.6 ",
10478- "resolved": "https://registry.npmjs.org/ajv/-/ajv-6.12.6 .tgz",
10479- "integrity": "sha512-j3fVLgvTo527anyYyJOGTYJbG+vnnQYvE0m5mmkc1TK+nxAppkCLMIL0aZ4dblVCNoGShhm+kzE4ZUykBoMg4g ==",
10517+ "version": "6.14.0 ",
10518+ "resolved": "https://registry.npmjs.org/ajv/-/ajv-6.14.0 .tgz",
10519+ "integrity": "sha512-IWrosm/yrn43eiKqkfkHis7QioDleaXQHdDVPKg0FSwwd/DuvyX79TZnFOnYpB7dcsFAMmtFztZuXPDvSePkFw ==",
1048010520 "requires": {
1048110521 "fast-deep-equal": "^3.1.1",
1048210522 "fast-json-stable-stringify": "^2.0.0",
@@ -11325,12 +11365,13 @@ manifest or lockfile is required
1132511365[TestCommand_OfflineDatabase/fix_non_interactive_in_place_package_lock_json_with_offline_vulns - 1]
1132611366Loaded npm local db from <tempdir>/osv-scanner/npm/all.zip
1132711367Scanning <tempdir>/package-lock.json...
11328- Found 11 vulnerabilities matching the filter
11329- Can fix 3/11 matching vulnerabilities by changing 3 dependencies
11368+ Found 12 vulnerabilities matching the filter
11369+ Can fix 4/12 matching vulnerabilities by changing 4 dependencies
11370+ UPGRADED-PACKAGE: ajv,6.12.6,6.14.0
1133011371UPGRADED-PACKAGE: brace-expansion,1.1.11,1.1.12
1133111372UPGRADED-PACKAGE: concat-stream,1.5.0,1.6.1
1133211373UPGRADED-PACKAGE: hosted-git-info,2.1.4,2.8.9
11333- FIXED-VULN-IDS: GHSA-43f8-2h32-f4cj,GHSA-g74r-ffvr-5q9f,GHSA-v6h2-p8h4-qcjw
11374+ FIXED-VULN-IDS: GHSA-2g4f-4pwh-qvx6,GHSA- 43f8-2h32-f4cj,GHSA-g74r-ffvr-5q9f,GHSA-v6h2-p8h4-qcjw
1133411375REMAINING-VULNS: 8
1133511376UNFIXABLE-VULNS: 8
1133611377Rewriting <tempdir>/package-lock.json...
@@ -11357,9 +11398,9 @@ Rewriting <tempdir>/package-lock.json...
1135711398 }
1135811399 },
1135911400 "node_modules/ajv": {
11360- "version": "6.12.6 ",
11361- "resolved": "https://registry.npmjs.org/ajv/-/ajv-6.12.6 .tgz",
11362- "integrity": "sha512-j3fVLgvTo527anyYyJOGTYJbG+vnnQYvE0m5mmkc1TK+nxAppkCLMIL0aZ4dblVCNoGShhm+kzE4ZUykBoMg4g ==",
11401+ "version": "6.14.0 ",
11402+ "resolved": "https://registry.npmjs.org/ajv/-/ajv-6.14.0 .tgz",
11403+ "integrity": "sha512-IWrosm/yrn43eiKqkfkHis7QioDleaXQHdDVPKg0FSwwd/DuvyX79TZnFOnYpB7dcsFAMmtFztZuXPDvSePkFw ==",
1136311404 "dependencies": {
1136411405 "fast-deep-equal": "^3.1.1",
1136511406 "fast-json-stable-stringify": "^2.0.0",
@@ -12295,9 +12336,9 @@ Rewriting <tempdir>/package-lock.json...
1229512336 },
1229612337 "dependencies": {
1229712338 "ajv": {
12298- "version": "6.12.6 ",
12299- "resolved": "https://registry.npmjs.org/ajv/-/ajv-6.12.6 .tgz",
12300- "integrity": "sha512-j3fVLgvTo527anyYyJOGTYJbG+vnnQYvE0m5mmkc1TK+nxAppkCLMIL0aZ4dblVCNoGShhm+kzE4ZUykBoMg4g ==",
12339+ "version": "6.14.0 ",
12340+ "resolved": "https://registry.npmjs.org/ajv/-/ajv-6.14.0 .tgz",
12341+ "integrity": "sha512-IWrosm/yrn43eiKqkfkHis7QioDleaXQHdDVPKg0FSwwd/DuvyX79TZnFOnYpB7dcsFAMmtFztZuXPDvSePkFw ==",
1230112342 "requires": {
1230212343 "fast-deep-equal": "^3.1.1",
1230312344 "fast-json-stable-stringify": "^2.0.0",
@@ -13071,11 +13112,11 @@ Rewriting <tempdir>/package-lock.json...
1307113112Loaded npm local db from <tempdir>/osv-scanner/npm/all.zip
1307213113Resolving <tempdir>/package.json...
1307313114Found 8 vulnerabilities matching the filter
13074- Can fix 3 /8 matching vulnerabilities by changing 1 dependencies
13115+ Can fix 4 /8 matching vulnerabilities by changing 1 dependencies
1307513116UPGRADED-PACKAGE: npm-registry-client,6.2.0,^7.5.0
13076- FIXED-VULN-IDS: GHSA-43f8-2h32-f4cj,GHSA-c2qf-rxjj-qqgw,GHSA-c6rq-rjc2-86v2
13077- REMAINING-VULNS: 5
13078- UNFIXABLE-VULNS: 5
13117+ FIXED-VULN-IDS: GHSA-3ppc-4f35-3m26,GHSA- 43f8-2h32-f4cj,GHSA-c2qf-rxjj-qqgw,GHSA-c6rq-rjc2-86v2
13118+ REMAINING-VULNS: 4
13119+ UNFIXABLE-VULNS: 4
1307913120Rewriting <tempdir>/package.json...
1308013121
1308113122---
0 commit comments