Skip to content

Conversation

MaryArmaly
Copy link
Owner

No description provided.

Copy link

@bridgecrew-dev bridgecrew-dev bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Bridgecrew has found errors in this PR ⬇️

"mongodb": "^2.1.18",
"forever": "^2.0.0",
"helmet": "^2.0.0",
"marked": "0.3.9",

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

marked 0.3.9 / package.json

Total vulnerabilities: 3

Critical: 0 High: 2 Medium: 1 Low: 0
Vulnerability IDSeverityCVSSFixed inStatus
CVE-2022-21681 HIGH HIGH 7.5 4.0.10 Open
CVE-2022-21680 HIGH HIGH 7.5 4.0.10 Open
PRISMA-2021-0013 MEDIUM MEDIUM - 1.1.1 Open

"forever": "^2.0.0",
"helmet": "^2.0.0",
"marked": "0.3.9",
"mongodb": "^2.1.18",

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

mongodb 2.1.18 / package.json

Total vulnerabilities: 1

Critical: 0 High: 1 Medium: 0 Low: 0
Vulnerability IDSeverityCVSSFixed inStatus
GHSA-mh5c-679w-hh4r HIGH HIGH 7 3.1.13 Open

"underscore": "^1.8.3"
"serve-favicon": "^2.3.0",
"swig": "^1.4.2",
"underscore": "^1.8.3"

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

underscore 1.8.3 / package.json

Total vulnerabilities: 1

Critical: 0 High: 1 Medium: 0 Low: 0
Vulnerability IDSeverityCVSSFixed inStatus
CVE-2021-23358 HIGH HIGH 7.2 1.12.1 Open

"swig": "^1.4.2",
"underscore": "^1.8.3"
"serve-favicon": "^2.3.0",
"swig": "^1.4.2",

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

swig 1.4.2 / package.json

Total vulnerabilities: 1

Critical: 0 High: 1 Medium: 0 Low: 0
Vulnerability IDSeverityCVSSFixed inStatus
CVE-2023-25345 HIGH HIGH 7.5 - Open

"main": "server.js",
"dependencies": {
"bcrypt-nodejs": "0.0.3",
"bcrypt-nodejs": "0.0.3",

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

bcrypt-nodejs 0.0.3 / package.json

LOW  Unknown License (NOT_FOUND)

This package use a non-SPDX, unrecognized, or private open-source license. Ensure this package is compliant.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant