Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion package.json
Original file line number Diff line number Diff line change
Expand Up @@ -25,7 +25,7 @@
"express": "^4.13.4",
"express-session": "^1.13.0",
"finalhandler": "^0.4.1",
"morgan": "1.9",
"morgan": "1.4",
"prom-client": "^6.3.0",
"request": "^2.72.0",
"serve-static": "^1.10.2"
Expand Down
3 changes: 0 additions & 3 deletions secrets/app.js

This file was deleted.

2 changes: 0 additions & 2 deletions secrets/config.js

This file was deleted.

5 changes: 0 additions & 5 deletions secrets/main.tf

This file was deleted.

4 changes: 0 additions & 4 deletions secrets/provider.tf

This file was deleted.

78 changes: 41 additions & 37 deletions yarn.lock
Original file line number Diff line number Diff line change
Expand Up @@ -77,12 +77,10 @@ base64-url@1.3.3:
version "1.3.3"
resolved "https://registry.yarnpkg.com/base64-url/-/base64-url-1.3.3.tgz#f8b6c537f09a4fc58c99cb86e0b0e9c61461a20f"

basic-auth@~2.0.0:
version "2.0.1"
resolved "https://registry.yarnpkg.com/basic-auth/-/basic-auth-2.0.1.tgz#b998279bf47ce38344b4f3cf916d4679bbf51e3a"
integrity sha512-NF+epuEdnUYVlGuhaxbbq+dvJttwLnGY+YixlXlME5KpQ5W3CnXA5cVTneY3SPbPDRkcjMbifrwmFYcClgOZeg==
dependencies:
safe-buffer "5.1.2"
basic-auth@1.0.0:

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

tunnel-agent 0.4.3 / yarn.lock

Total vulnerabilities: 1

Critical: 0 High: 0 Medium: 1 Low: 0
Vulnerability IDSeverityCVSSFixed inStatus
GHSA-xc7v-wxcw-j472 MEDIUM MEDIUM 4 0.6.0 Open

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

tough-cookie 2.3.4 / yarn.lock

Total vulnerabilities: 1

Critical: 1 High: 0 Medium: 0 Low: 0
Vulnerability IDSeverityCVSSFixed inStatus
CVE-2023-26136 CRITICAL CRITICAL 9.8 4.1.3 Open

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

morgan 1.4.1 / yarn.lock

Total vulnerabilities: 1

Critical: 1 High: 0 Medium: 0 Low: 0
Vulnerability IDSeverityCVSSFixed inStatus
CVE-2019-5413 CRITICAL CRITICAL 9.8 1.9.1 Open

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

is-my-json-valid 2.15.0 / yarn.lock

Total vulnerabilities: 2

Critical: 0 High: 1 Medium: 1 Low: 0
Vulnerability IDSeverityCVSSFixed inStatus
CVE-2016-2537 HIGH HIGH 7 2.17.2 Open
CVE-2018-1107 MEDIUM MEDIUM 5.3 2.17.2 Open

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

js-yaml 3.7.0 / yarn.lock

Total vulnerabilities: 2

Critical: 0 High: 1 Medium: 1 Low: 0
Vulnerability IDSeverityCVSSFixed inStatus
GHSA-8j8c-7jfh-h6hx HIGH HIGH 7 3.13.1 Open
GHSA-2pr6-76vf-7546 MEDIUM MEDIUM 4 3.13.0 Open

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

mime 1.3.4 / yarn.lock

Total vulnerabilities: 1

Critical: 0 High: 1 Medium: 0 Low: 0
Vulnerability IDSeverityCVSSFixed inStatus
CVE-2017-16138 HIGH HIGH 7.5 1.4.1 Open

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

minimist 0.0.10 / yarn.lock

Total vulnerabilities: 2

Critical: 1 High: 0 Medium: 1 Low: 0
Vulnerability IDSeverityCVSSFixed inStatus
CVE-2021-44906 CRITICAL CRITICAL 9.8 1.2.6 Open
CVE-2020-7598 MEDIUM MEDIUM 5.6 1.2.2 Open

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

qs 6.3.0 / yarn.lock

Total vulnerabilities: 2

Critical: 0 High: 2 Medium: 0 Low: 0
Vulnerability IDSeverityCVSSFixed inStatus
CVE-2022-24999 HIGH HIGH 7.5 6.10.3 Open
CVE-2017-1000048 HIGH HIGH 7 6.3.2 Open

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

superagent 2.3.0 / yarn.lock

Total vulnerabilities: 1

Critical: 0 High: 0 Medium: 1 Low: 0
Vulnerability IDSeverityCVSSFixed inStatus
CVE-2017-16129 MEDIUM MEDIUM 5.9 3.7.0 Open

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

jsonpointer 4.0.1 / yarn.lock

Total vulnerabilities: 1

Critical: 1 High: 0 Medium: 0 Low: 0
Vulnerability IDSeverityCVSSFixed inStatus
CVE-2021-23807 CRITICAL CRITICAL 9.8 5.0.0 Open

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

qs 6.2.0 / yarn.lock

Total vulnerabilities: 2

Critical: 0 High: 2 Medium: 0 Low: 0
Vulnerability IDSeverityCVSSFixed inStatus
CVE-2022-24999 HIGH HIGH 7.5 6.10.3 Open
CVE-2017-1000048 HIGH HIGH 7 6.2.3 Open

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

ms 0.7.1 / yarn.lock

Total vulnerabilities: 1

Critical: 0 High: 0 Medium: 1 Low: 0
Vulnerability IDSeverityCVSSFixed inStatus
CVE-2017-20162 MEDIUM MEDIUM 5.3 2.0.0 Open

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

semver 5.3.0 / yarn.lock

Total vulnerabilities: 1

Critical: 0 High: 1 Medium: 0 Low: 0
Vulnerability IDSeverityCVSSFixed inStatus
CVE-2022-25883 HIGH HIGH 7.5 7.5.2 Open

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

stringstream 0.0.5 / yarn.lock

Total vulnerabilities: 1

Critical: 0 High: 0 Medium: 1 Low: 0
Vulnerability IDSeverityCVSSFixed inStatus
CVE-2018-21270 MEDIUM MEDIUM 4 0.0.6 Open

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

json-schema 0.2.3 / yarn.lock

Total vulnerabilities: 1

Critical: 1 High: 0 Medium: 0 Low: 0
Vulnerability IDSeverityCVSSFixed inStatus
CVE-2021-3918 CRITICAL CRITICAL 9 0.4.0 Open

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

minimatch 3.0.3 / yarn.lock

Total vulnerabilities: 1

Critical: 0 High: 1 Medium: 0 Low: 0
Vulnerability IDSeverityCVSSFixed inStatus
CVE-2022-3517 HIGH HIGH 7.5 3.0.5 Open

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

request 2.79.0 / yarn.lock

Total vulnerabilities: 1

Critical: 0 High: 0 Medium: 1 Low: 0
Vulnerability IDSeverityCVSSFixed inStatus
CVE-2023-28155 MEDIUM MEDIUM 6.1 - Open

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

minimist 0.0.8 / yarn.lock

Total vulnerabilities: 2

Critical: 1 High: 0 Medium: 1 Low: 0
Vulnerability IDSeverityCVSSFixed inStatus
CVE-2021-44906 CRITICAL CRITICAL 9.8 1.2.6 Open
CVE-2020-7598 MEDIUM MEDIUM 5.6 1.2.2 Open

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

redis 2.8.0 / yarn.lock

Total vulnerabilities: 1

Critical: 0 High: 1 Medium: 0 Low: 0
Vulnerability IDSeverityCVSSFixed inStatus
CVE-2021-29469 HIGH HIGH 7.5 3.1.1 Open

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

ms 0.7.0 / yarn.lock

Total vulnerabilities: 2

Critical: 0 High: 1 Medium: 1 Low: 0
Vulnerability IDSeverityCVSSFixed inStatus
CVE-2015-8315 HIGH HIGH 7 0.7.1 Open
CVE-2017-20162 MEDIUM MEDIUM 5.3 2.0.0 Open

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

debug 2.1.3 / yarn.lock

Total vulnerabilities: 2

Critical: 0 High: 1 Medium: 1 Low: 0
Vulnerability IDSeverityCVSSFixed inStatus
CVE-2017-20165 HIGH HIGH 7.5 2.6.9 Open
CVE-2017-16137 MEDIUM MEDIUM 5.3 2.6.9 Open

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

cookiejar 2.0.6 / yarn.lock

Total vulnerabilities: 1

Critical: 0 High: 1 Medium: 0 Low: 0
Vulnerability IDSeverityCVSSFixed inStatus
CVE-2022-25901 HIGH HIGH 7.5 2.1.4 Open

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

handlebars 4.5.1 / yarn.lock

Total vulnerabilities: 6

Critical: 2 High: 4 Medium: 0 Low: 0
Vulnerability IDSeverityCVSSFixed inStatus
CVE-2021-23383 CRITICAL CRITICAL 9.8 4.7.7 Open
CVE-2021-23369 CRITICAL CRITICAL 9.8 4.7.7 Open
CVE-2019-20920 HIGH HIGH 8.1 4.5.3 Open
GHSA-2cf5-4w76-r9qv HIGH HIGH 7 4.5.2 Open
GHSA-g9r4-xpmj-mj65 HIGH HIGH 7 4.5.3 Open
GHSA-q2c6-c6pm-g3gh HIGH HIGH 7 4.5.3 Open

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

debug 2.2.0 / yarn.lock

Total vulnerabilities: 2

Critical: 0 High: 1 Medium: 1 Low: 0
Vulnerability IDSeverityCVSSFixed inStatus
CVE-2017-20165 HIGH HIGH 7.5 2.6.9 Open
CVE-2017-16137 MEDIUM MEDIUM 5.3 2.6.9 Open

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

bson 1.0.9 / yarn.lock

Total vulnerabilities: 2

Critical: 1 High: 0 Medium: 1 Low: 0
Vulnerability IDSeverityCVSSFixed inStatus
CVE-2020-7610 CRITICAL CRITICAL 9.8 1.1.4 Open
CVE-2019-2391 MEDIUM MEDIUM 4 1.1.4 Open

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

hoek 2.16.3 / yarn.lock

Total vulnerabilities: 2

Critical: 0 High: 2 Medium: 0 Low: 0
Vulnerability IDSeverityCVSSFixed inStatus
CVE-2020-36604 HIGH HIGH 8.1 8.5.1 Open
CVE-2018-3728 HIGH HIGH 8.8 4.2.0 Open

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

cryptiles 2.0.5 / yarn.lock

Total vulnerabilities: 1

Critical: 1 High: 0 Medium: 0 Low: 0
Vulnerability IDSeverityCVSSFixed inStatus
CVE-2018-1000620 CRITICAL CRITICAL 9 4.1.2 Open

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

fresh 0.3.0 / yarn.lock

Total vulnerabilities: 1

Critical: 0 High: 1 Medium: 0 Low: 0
Vulnerability IDSeverityCVSSFixed inStatus
CVE-2017-16119 HIGH HIGH 7.5 0.5.2 Open

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

base64-url 1.3.3 / yarn.lock

Total vulnerabilities: 1

Critical: 0 High: 1 Medium: 0 Low: 0
Vulnerability IDSeverityCVSSFixed inStatus
GHSA-j4mr-9xw3-c9jx HIGH HIGH 7 2.0.0 Open

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

diff 1.4.0 / yarn.lock

Total vulnerabilities: 1

Critical: 0 High: 1 Medium: 0 Low: 0
Vulnerability IDSeverityCVSSFixed inStatus
GHSA-h6ch-v84p-w6p9 HIGH HIGH 7 3.5.0 Open

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

hawk 3.1.3 / yarn.lock

Total vulnerabilities: 1

Critical: 0 High: 1 Medium: 0 Low: 0
Vulnerability IDSeverityCVSSFixed inStatus
CVE-2022-29167 HIGH HIGH 7.5 9.0.1 Open

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

brace-expansion 1.1.6 / yarn.lock

Total vulnerabilities: 1

Critical: 0 High: 1 Medium: 0 Low: 0
Vulnerability IDSeverityCVSSFixed inStatus
CVE-2017-18077 HIGH HIGH 7 1.1.7 Open

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

growl 1.9.2 / yarn.lock

Total vulnerabilities: 1

Critical: 1 High: 0 Medium: 0 Low: 0
Vulnerability IDSeverityCVSSFixed inStatus
CVE-2017-16042 CRITICAL CRITICAL 9.8 1.10.2 Open

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

ms 0.7.0 / yarn.lock

LOW  Unknown License (NOT_FOUND)

This package use a non-SPDX, unrecognized, or private open-source license. Ensure this package is compliant.

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

ms 0.7.1 / yarn.lock

LOW  Unknown License (NOT_FOUND)

This package use a non-SPDX, unrecognized, or private open-source license. Ensure this package is compliant.

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

bintrees 1.0.1 / yarn.lock

LOW  Unknown License (NOT_FOUND)

This package use a non-SPDX, unrecognized, or private open-source license. Ensure this package is compliant.

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

tunnel-agent 0.4.3 / yarn.lock

Total vulnerabilities: 1

Critical: 0 High: 0 Medium: 1 Low: 0
Vulnerability IDSeverityCVSSFixed inStatus
GHSA-xc7v-wxcw-j472 MEDIUM MEDIUM 4 0.6.0 Open

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

tough-cookie 2.3.4 / yarn.lock

Total vulnerabilities: 1

Critical: 1 High: 0 Medium: 0 Low: 0
Vulnerability IDSeverityCVSSFixed inStatus
CVE-2023-26136 CRITICAL CRITICAL 9.8 4.1.3 Open

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

morgan 1.4.1 / yarn.lock

Total vulnerabilities: 1

Critical: 1 High: 0 Medium: 0 Low: 0
Vulnerability IDSeverityCVSSFixed inStatus
CVE-2019-5413 CRITICAL CRITICAL 9.8 1.9.1 Open

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

is-my-json-valid 2.15.0 / yarn.lock

Total vulnerabilities: 2

Critical: 0 High: 1 Medium: 1 Low: 0
Vulnerability IDSeverityCVSSFixed inStatus
CVE-2016-2537 HIGH HIGH 7 2.17.2 Open
CVE-2018-1107 MEDIUM MEDIUM 5.3 2.17.2 Open

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

js-yaml 3.7.0 / yarn.lock

Total vulnerabilities: 2

Critical: 0 High: 1 Medium: 1 Low: 0
Vulnerability IDSeverityCVSSFixed inStatus
GHSA-8j8c-7jfh-h6hx HIGH HIGH 7 3.13.1 Open
GHSA-2pr6-76vf-7546 MEDIUM MEDIUM 4 3.13.0 Open

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

mime 1.3.4 / yarn.lock

Total vulnerabilities: 1

Critical: 0 High: 1 Medium: 0 Low: 0
Vulnerability IDSeverityCVSSFixed inStatus
CVE-2017-16138 HIGH HIGH 7.5 1.4.1 Open

Copy link

@prisma-cloud-devsecops prisma-cloud-devsecops bot Jul 18, 2023

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

minimist 0.0.10 / yarn.lock

Total vulnerabilities: 2

Critical: 1 High: 0 Medium: 1 Low: 0
Vulnerability IDSeverityCVSSFixed inStatus
CVE-2021-44906 CRITICAL CRITICAL 9.8 1.2.6 Open
CVE-2020-7598 MEDIUM MEDIUM 5.6 1.2.2 Open
Vulnerabilities scan results were updated by commit d1d8c49

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

qs 6.3.0 / yarn.lock

Total vulnerabilities: 2

Critical: 0 High: 2 Medium: 0 Low: 0
Vulnerability IDSeverityCVSSFixed inStatus
CVE-2022-24999 HIGH HIGH 7.5 6.10.3 Open
CVE-2017-1000048 HIGH HIGH 7 6.3.2 Open

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

superagent 2.3.0 / yarn.lock

Total vulnerabilities: 1

Critical: 0 High: 0 Medium: 1 Low: 0
Vulnerability IDSeverityCVSSFixed inStatus
CVE-2017-16129 MEDIUM MEDIUM 5.9 3.7.0 Open

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

jsonpointer 4.0.1 / yarn.lock

Total vulnerabilities: 1

Critical: 1 High: 0 Medium: 0 Low: 0
Vulnerability IDSeverityCVSSFixed inStatus
CVE-2021-23807 CRITICAL CRITICAL 9.8 5.0.0 Open

Copy link

@prisma-cloud-devsecops prisma-cloud-devsecops bot Jul 18, 2023

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

qs 6.3.0 / yarn.lock

Total vulnerabilities: 2

Critical: 0 High: 2 Medium: 0 Low: 0
Vulnerability IDSeverityCVSSFixed inStatus
CVE-2017-1000048 HIGH HIGH 7 6.2.3 Open
CVE-2022-24999 HIGH HIGH 7.5 6.10.3 Open
Vulnerabilities scan results were updated by commit d1d8c49

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

ms 0.7.1 / yarn.lock

Total vulnerabilities: 1

Critical: 0 High: 0 Medium: 1 Low: 0
Vulnerability IDSeverityCVSSFixed inStatus
CVE-2017-20162 MEDIUM MEDIUM 5.3 2.0.0 Open

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

semver 5.3.0 / yarn.lock

Total vulnerabilities: 1

Critical: 0 High: 1 Medium: 0 Low: 0
Vulnerability IDSeverityCVSSFixed inStatus
CVE-2022-25883 HIGH HIGH 7.5 7.5.2 Open

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

stringstream 0.0.5 / yarn.lock

Total vulnerabilities: 1

Critical: 0 High: 0 Medium: 1 Low: 0
Vulnerability IDSeverityCVSSFixed inStatus
CVE-2018-21270 MEDIUM MEDIUM 4 0.0.6 Open

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

json-schema 0.2.3 / yarn.lock

Total vulnerabilities: 1

Critical: 1 High: 0 Medium: 0 Low: 0
Vulnerability IDSeverityCVSSFixed inStatus
CVE-2021-3918 CRITICAL CRITICAL 9 0.4.0 Open

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

minimatch 3.0.3 / yarn.lock

Total vulnerabilities: 1

Critical: 0 High: 1 Medium: 0 Low: 0
Vulnerability IDSeverityCVSSFixed inStatus
CVE-2022-3517 HIGH HIGH 7.5 3.0.5 Open

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

request 2.79.0 / yarn.lock

Total vulnerabilities: 1

Critical: 0 High: 0 Medium: 1 Low: 0
Vulnerability IDSeverityCVSSFixed inStatus
CVE-2023-28155 MEDIUM MEDIUM 6.1 - Open

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

minimist 0.0.8 / yarn.lock

Total vulnerabilities: 2

Critical: 1 High: 0 Medium: 1 Low: 0
Vulnerability IDSeverityCVSSFixed inStatus
CVE-2021-44906 CRITICAL CRITICAL 9.8 1.2.6 Open
CVE-2020-7598 MEDIUM MEDIUM 5.6 1.2.2 Open

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

redis 2.8.0 / yarn.lock

Total vulnerabilities: 1

Critical: 0 High: 1 Medium: 0 Low: 0
Vulnerability IDSeverityCVSSFixed inStatus
CVE-2021-29469 HIGH HIGH 7.5 3.1.1 Open

Copy link

@prisma-cloud-devsecops prisma-cloud-devsecops bot Jul 18, 2023

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

ms 0.7.1 / yarn.lock

Total vulnerabilities: 2

Critical: 0 High: 1 Medium: 1 Low: 0
Vulnerability IDSeverityCVSSFixed inStatus
CVE-2015-8315 HIGH HIGH 7 0.7.1 Open
CVE-2017-20162 MEDIUM MEDIUM 5.3 2.0.0 Open
Vulnerabilities scan results were updated by commit d1d8c49

Copy link

@prisma-cloud-devsecops prisma-cloud-devsecops bot Jul 18, 2023

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

debug 2.1.3 / yarn.lock

Total vulnerabilities: 2

Critical: 0 High: 1 Medium: 1 Low: 0
Vulnerability IDSeverityCVSSFixed inStatus
CVE-2017-20165 HIGH HIGH 7.5 2.6.9 Open
CVE-2017-16137 MEDIUM MEDIUM 5.3 2.6.9 Open
Vulnerabilities scan results were updated by commit d1d8c49

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

minimist 0.0.10 / yarn.lock

Total vulnerabilities: 2

Critical: 1 High: 0 Medium: 1 Low: 0
Vulnerability IDSeverityCVSSFixed inStatus
CVE-2021-44906 CRITICAL CRITICAL 9.8 1.2.6 Open
CVE-2020-7598 MEDIUM MEDIUM 5.6 1.2.2 Open

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

minimist 0.0.8 / yarn.lock

Total vulnerabilities: 2

Critical: 1 High: 0 Medium: 1 Low: 0
Vulnerability IDSeverityCVSSFixed inStatus
CVE-2021-44906 CRITICAL CRITICAL 9.8 1.2.6 Open
CVE-2020-7598 MEDIUM MEDIUM 5.6 1.2.2 Open

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

debug 2.1.3 / yarn.lock

Total vulnerabilities: 2

Critical: 0 High: 1 Medium: 1 Low: 0
Vulnerability IDSeverityCVSSFixed inStatus
CVE-2017-20165 HIGH HIGH 7.5 2.6.9 Open
CVE-2017-16137 MEDIUM MEDIUM 5.3 2.6.9 Open

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

cookiejar 2.0.6 / yarn.lock

Total vulnerabilities: 1

Critical: 0 High: 1 Medium: 0 Low: 0
Vulnerability IDSeverityCVSSFixed inStatus
CVE-2022-25901 HIGH HIGH 7.5 2.1.4 Open

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

debug 2.2.0 / yarn.lock

Total vulnerabilities: 2

Critical: 0 High: 1 Medium: 1 Low: 0
Vulnerability IDSeverityCVSSFixed inStatus
CVE-2017-20165 HIGH HIGH 7.5 2.6.9 Open
CVE-2017-16137 MEDIUM MEDIUM 5.3 2.6.9 Open

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

bson 1.0.9 / yarn.lock

Total vulnerabilities: 2

Critical: 1 High: 0 Medium: 1 Low: 0
Vulnerability IDSeverityCVSSFixed inStatus
CVE-2020-7610 CRITICAL CRITICAL 9.8 1.1.4 Open
CVE-2019-2391 MEDIUM MEDIUM 4 1.1.4 Open

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

hoek 2.16.3 / yarn.lock

Total vulnerabilities: 2

Critical: 0 High: 2 Medium: 0 Low: 0
Vulnerability IDSeverityCVSSFixed inStatus
CVE-2020-36604 HIGH HIGH 8.1 8.5.1 Open
CVE-2018-3728 HIGH HIGH 8.8 4.2.0 Open

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

cryptiles 2.0.5 / yarn.lock

Total vulnerabilities: 1

Critical: 1 High: 0 Medium: 0 Low: 0
Vulnerability IDSeverityCVSSFixed inStatus
CVE-2018-1000620 CRITICAL CRITICAL 9 4.1.2 Open

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

handlebars 4.5.1 / yarn.lock

Total vulnerabilities: 6

Critical: 2 High: 4 Medium: 0 Low: 0
Vulnerability IDSeverityCVSSFixed inStatus
CVE-2021-23383 CRITICAL CRITICAL 9.8 4.7.7 Open
CVE-2021-23369 CRITICAL CRITICAL 9.8 4.7.7 Open
CVE-2019-20920 HIGH HIGH 8.1 4.5.3 Open
GHSA-2cf5-4w76-r9qv HIGH HIGH 7 4.5.2 Open
GHSA-g9r4-xpmj-mj65 HIGH HIGH 7 4.5.3 Open
GHSA-q2c6-c6pm-g3gh HIGH HIGH 7 4.5.3 Open

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

base64-url 1.3.3 / yarn.lock

Total vulnerabilities: 1

Critical: 0 High: 1 Medium: 0 Low: 0
Vulnerability IDSeverityCVSSFixed inStatus
GHSA-j4mr-9xw3-c9jx HIGH HIGH 7 2.0.0 Open

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

fresh 0.3.0 / yarn.lock

Total vulnerabilities: 1

Critical: 0 High: 1 Medium: 0 Low: 0
Vulnerability IDSeverityCVSSFixed inStatus
CVE-2017-16119 HIGH HIGH 7.5 0.5.2 Open

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

diff 1.4.0 / yarn.lock

Total vulnerabilities: 1

Critical: 0 High: 1 Medium: 0 Low: 0
Vulnerability IDSeverityCVSSFixed inStatus
GHSA-h6ch-v84p-w6p9 HIGH HIGH 7 3.5.0 Open

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

hawk 3.1.3 / yarn.lock

Total vulnerabilities: 1

Critical: 0 High: 1 Medium: 0 Low: 0
Vulnerability IDSeverityCVSSFixed inStatus
CVE-2022-29167 HIGH HIGH 7.5 9.0.1 Open

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

growl 1.9.2 / yarn.lock

Total vulnerabilities: 1

Critical: 1 High: 0 Medium: 0 Low: 0
Vulnerability IDSeverityCVSSFixed inStatus
CVE-2017-16042 CRITICAL CRITICAL 9.8 1.10.2 Open

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

brace-expansion 1.1.6 / yarn.lock

Total vulnerabilities: 1

Critical: 0 High: 1 Medium: 0 Low: 0
Vulnerability IDSeverityCVSSFixed inStatus
CVE-2017-18077 HIGH HIGH 7 1.1.7 Open

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

formidable 1.0.17 / yarn.lock

LOW  Unknown License (NOT_FOUND)

This package use a non-SPDX, unrecognized, or private open-source license. Ensure this package is compliant.

version "1.0.0"
resolved "https://registry.yarnpkg.com/basic-auth/-/basic-auth-1.0.0.tgz#111b2d9ff8e4e6d136b8c84ea5e096cb87351637"
integrity sha512-qzxS7/bW/LSiKZzdZw3isPjiVmzXbJLM3ImZZ62WMR3oJQAyqy094Nnb0TA2ZZm65xB7nu0acfTQ99z7wwCDCw==

bcrypt-pbkdf@^1.0.0:
version "1.0.2"
Expand Down Expand Up @@ -262,19 +260,19 @@ debug@2.2.0, debug@^2.2.0, debug@~2.2.0:
dependencies:
ms "0.7.1"

debug@2.6.9:
version "2.6.9"
resolved "https://registry.yarnpkg.com/debug/-/debug-2.6.9.tgz#5d128515df134ff327e90a4c93f4e077a536341f"
integrity sha512-bC7ElrdJaJnPbAP+1EotYvqZsb3ecl5wi6Bfi6BJTUcNowp6cvspg0jXznRTKDjm/E7AdgFBVeAPVMNcKGsHMA==
dependencies:
ms "2.0.0"

debug@^4.1.1:
version "4.1.1"
resolved "https://registry.yarnpkg.com/debug/-/debug-4.1.1.tgz#3b72260255109c6b589cee050f1d516139664791"
dependencies:
ms "^2.1.1"

debug@~2.1.0:
version "2.1.3"
resolved "https://registry.yarnpkg.com/debug/-/debug-2.1.3.tgz#ce8ab1b5ee8fbee2bfa3b633cab93d366b63418e"
integrity sha512-KWau3VQmxO3YwQCjJzMPPusOtI0hx3UGsqnY7RS+QHQjUeawpOVtJvAdeTrI2Ja5DTR8KH3xaEN8c+ADbXJWeg==
dependencies:
ms "0.7.0"
Comment on lines +269 to +274

Check warning

Code scanning / checkov

CVE-2017-16137 - debug: 2.1.3

CVE-2017-16137 - debug: 2.1.3
Comment on lines +269 to +274

Check failure

Code scanning / checkov

CVE-2017-20165 - debug: 2.1.3

CVE-2017-20165 - debug: 2.1.3

deep-eql@^0.1.3:
version "0.1.3"
resolved "https://registry.yarnpkg.com/deep-eql/-/deep-eql-0.1.3.tgz#ef558acab8de25206cd713906d74e56930eb69f2"
Expand All @@ -289,15 +287,15 @@ delayed-stream@~1.0.0:
version "1.0.0"
resolved "https://registry.yarnpkg.com/delayed-stream/-/delayed-stream-1.0.0.tgz#df3ae199acadfb7d440aaae0b29e2272b24ec619"

depd@~1.0.0:
version "1.0.1"
resolved "https://registry.yarnpkg.com/depd/-/depd-1.0.1.tgz#80aec64c9d6d97e65cc2a9caa93c0aa6abf73aaa"
integrity sha512-OEWAMbCkK9IWQ8pfTvHBhCSqHgR+sk5pbiYqq0FqfARG4Cy+cRsCbITx6wh5pcsmfBPiJAcbd98tfdz5fnBbag==

depd@~1.1.0:
version "1.1.0"
resolved "https://registry.yarnpkg.com/depd/-/depd-1.1.0.tgz#e1bd82c6aab6ced965b97b88b17ed3e528ca18c3"

depd@~1.1.2:
version "1.1.2"
resolved "https://registry.yarnpkg.com/depd/-/depd-1.1.2.tgz#9bcd52e14c097763e749b274c4346ed2e560b5a9"
integrity sha512-7emPTl6Dpo6JRXOXjLRxck+FlLRX5847cLKEn00PLAgc3g2hTZZgr+e4c2v6QpSmLeFP3n5yUo7ft6avBK/5jQ==

destroy@~1.0.4:
version "1.0.4"
resolved "https://registry.yarnpkg.com/destroy/-/destroy-1.0.4.tgz#978857442c44749e4206613e37946205826abd80"
Expand All @@ -317,6 +315,11 @@ ecc-jsbn@~0.1.1:
jsbn "~0.1.0"
safer-buffer "^2.1.0"

ee-first@1.1.0:
version "1.1.0"
resolved "https://registry.yarnpkg.com/ee-first/-/ee-first-1.1.0.tgz#6a0d7c6221e490feefd92ec3f441c9ce8cd097f4"
integrity sha512-n4X/DaHVKHyDy1Rwuzm1UPjTRIBSarj1BBZ5R5HLOFLn58yhw510qoF1zk94jjkw3mXScdsmMtYCNR1jsAJlEA==

ee-first@1.1.1:
version "1.1.1"
resolved "https://registry.yarnpkg.com/ee-first/-/ee-first-1.1.1.tgz#590c61156b0ae2f4f0255732a158b266bc56b21d"
Expand Down Expand Up @@ -857,26 +860,25 @@ mongodb@^2.2.5:
mongodb-core "2.1.2"
readable-stream "2.1.5"

morgan@1.9:
version "1.9.1"
resolved "https://registry.yarnpkg.com/morgan/-/morgan-1.9.1.tgz#0a8d16734a1d9afbc824b99df87e738e58e2da59"
integrity sha512-HQStPIV4y3afTiCYVxirakhlCfGkI161c76kKFca7Fk1JusM//Qeo1ej2XaMniiNeaZklMVrh3vTtIzpzwbpmA==
morgan@1.4:
version "1.4.1"
resolved "https://registry.yarnpkg.com/morgan/-/morgan-1.4.1.tgz#cd9600c3fa74e2fdf22ba0f1d026c20cb96f25fe"
integrity sha512-miTjw0gjk8JEP8IMGOR5YwLZVFg1GLvxbTp84tzx632PlysK91fSxKHQpTaran/lJPvSl8Hhj7LuWRt2x/h2SQ==
dependencies:
basic-auth "~2.0.0"
debug "2.6.9"
depd "~1.1.2"
on-finished "~2.3.0"
on-headers "~1.0.1"
basic-auth "1.0.0"
debug "~2.1.0"
depd "~1.0.0"
on-finished "2.1.1"
Comment on lines +863 to +871

Check failure

Code scanning / checkov

CVE-2019-5413 - morgan: 1.4.1

CVE-2019-5413 - morgan: 1.4.1

ms@0.7.0:
version "0.7.0"
resolved "https://registry.yarnpkg.com/ms/-/ms-0.7.0.tgz#865be94c2e7397ad8a57da6a633a6e2f30798b83"
integrity sha512-YmuMMkfOZzzAftlHwiQxFepJx/5rDaYi9o9QanyBCk485BRAyM/vB9XoYlZvglxE/pmAWOiQgrdoE10watiK9w==
Comment on lines +873 to +876

Check notice

Code scanning / checkov

License NOT_FOUND - ms: 0.7.0

License NOT_FOUND - ms: 0.7.0
Comment on lines +873 to +876

Check failure

Code scanning / checkov

CVE-2015-8315 - ms: 0.7.0

CVE-2015-8315 - ms: 0.7.0
Comment on lines +873 to +876

Check warning

Code scanning / checkov

CVE-2017-20162 - ms: 0.7.0

CVE-2017-20162 - ms: 0.7.0

ms@0.7.1:
version "0.7.1"
resolved "https://registry.yarnpkg.com/ms/-/ms-0.7.1.tgz#9cd13c03adbff25b65effde7ce864ee952017098"

ms@2.0.0:
version "2.0.0"
resolved "https://registry.yarnpkg.com/ms/-/ms-2.0.0.tgz#5608aeadfc00be6c2901df5f9861788de0d597c8"
integrity sha512-Tpp60P6IUJDTuOq/5Z8cdskzJujfwqfOTkrwIwj7IRISpnkJnT6SyJ4PCPnGMoFjC9ddhal5KVIYtAt97ix05A==

ms@^2.1.1:
version "2.1.2"
resolved "https://registry.yarnpkg.com/ms/-/ms-2.1.2.tgz#d09d1f357b443f493382a8eb3ccd183872ae6009"
Expand All @@ -899,6 +901,13 @@ oauth-sign@~0.8.1:
version "0.8.2"
resolved "https://registry.yarnpkg.com/oauth-sign/-/oauth-sign-0.8.2.tgz#46a6ab7f0aead8deae9ec0565780b7d4efeb9d43"

on-finished@2.1.1:
version "2.1.1"
resolved "https://registry.yarnpkg.com/on-finished/-/on-finished-2.1.1.tgz#f82ca1c9e3a4f3286b1b9938610e5b8636bd3cb2"
integrity sha512-3ljOi5Zrf46pSbY/39CaJulZQN9XRfmeWqXkeWddhhKD7B4n7nOTisLdaZmAXI1P3A57peTj4pHokMY8X7ICCA==
dependencies:
ee-first "1.1.0"

on-finished@~2.3.0:
version "2.3.0"
resolved "https://registry.yarnpkg.com/on-finished/-/on-finished-2.3.0.tgz#20f1336481b083cd75337992a16971aa2d906947"
Expand Down Expand Up @@ -1085,11 +1094,6 @@ resolve@1.1.x:
version "1.1.7"
resolved "https://registry.yarnpkg.com/resolve/-/resolve-1.1.7.tgz#203114d82ad2c5ed9e8e0411b3932875e889e97b"

safe-buffer@5.1.2:
version "5.1.2"
resolved "https://registry.yarnpkg.com/safe-buffer/-/safe-buffer-5.1.2.tgz#991ec69d296e0313747d59bdfd2b745c35f8828d"
integrity sha512-Gd2UZBJDkXlY7GbJxfsE8/nvKkUEU1G38c1siN6QP6a9PT9MmHB8GnpscSmMJSoF8LOIrt8ud/wPtojys4G6+g==

safer-buffer@^2.0.2, safer-buffer@^2.1.0, safer-buffer@~2.1.0:
version "2.1.2"
resolved "https://registry.yarnpkg.com/safer-buffer/-/safer-buffer-2.1.2.tgz#44fa161b0187b9549dd84bb91802f9bd8385cd6a"
Expand Down