Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Snyk] Security upgrade ethers from 5.7.2 to 6.0.0 #47

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

karencapiiro
Copy link

snyk-top-banner

Snyk has created this PR to fix 1 vulnerabilities in the npm dependencies of this project.

Snyk changed the following file(s):

  • frontend/package.json

Vulnerabilities that will be fixed with an upgrade:

Issue Score
high severity Improper Verification of Cryptographic Signature
SNYK-JS-ELLIPTIC-8187303
  170  

Important

  • Check the changes in this PR to ensure they won't cause issues with your project.
  • Max score is 1000. Note that the real score may have changed since the PR was raised.
  • This PR was automatically created by Snyk using the credentials of a real user.

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report
📜 Customise PR templates
🛠 Adjust project settings
📚 Read about Snyk's upgrade logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Learn about vulnerability in an interactive lesson of Snyk Learn.

Copy link

New and removed dependencies detected. Learn more about Socket for GitHub ↗︎

Package New capabilities Transitives Size Publisher
npm/@angular-builders/[email protected] eval Transitive: environment, filesystem, network, unsafe +35 5.85 MB justjeb
npm/@angular-devkit/[email protected] environment, filesystem, network, shell, unsafe Transitive: eval +377 291 MB google-wombot
npm/@angular-eslint/[email protected] Transitive: eval, filesystem, network +10 1.82 MB jameshenry
npm/@angular-material-extensions/[email protected] None +10 116 MB anthonynahas
npm/@angular/[email protected] None 0 2.49 MB google-wombot
npm/@angular/[email protected] None +1 11.3 MB google-wombot
npm/@angular/[email protected] environment, filesystem, network, shell, unsafe Transitive: eval +85 22.7 MB google-wombot
npm/@angular/[email protected] None 0 12.3 MB google-wombot
npm/@angular/[email protected] Transitive: environment, filesystem, shell, unsafe +72 18.1 MB google-wombot
npm/@angular/[email protected] None 0 9.07 MB google-wombot
npm/@angular/[email protected] None 0 23 MB google-wombot
npm/@angular/[email protected] None +4 45.2 MB angular
npm/@angular/[email protected] None 0 2.67 MB google-wombot
npm/@angular/[email protected] None +3 27 MB angular
npm/@angular/[email protected] None 0 14.8 MB google-wombot
npm/@angular/[email protected] None 0 17.8 MB google-wombot
npm/@angular/[email protected] None 0 132 kB google-wombot
npm/@angular/[email protected] None 0 1.12 MB google-wombot
npm/@angular/[email protected] None 0 3.22 MB google-wombot
npm/@ctrl/[email protected] None +3 310 kB scttcper
npm/@cyclonedx/[email protected] filesystem Transitive: environment, eval, network, shell, unsafe +44 22.7 MB cyclonedx-automation
npm/@fortawesome/[email protected] None +1 321 kB robmadole
npm/@fortawesome/[email protected] None +1 2.07 MB robmadole
npm/@fortawesome/[email protected] None +1 651 kB robmadole
npm/@fortawesome/[email protected] None +1 3.24 MB robmadole
npm/@nguniversal/[email protected] filesystem Transitive: environment, eval, network +31 41.3 MB angular
npm/@ngx-translate/[email protected] None 0 591 kB ocombe
npm/@ngx-translate/[email protected] None 0 15 kB ocombe
npm/@types/[email protected] None 0 6.31 kB types
npm/@types/[email protected] None 0 6.86 kB types
npm/@types/[email protected] None 0 2.99 kB types
npm/@typescript-eslint/[email protected] Transitive: environment, eval, filesystem, shell, unsafe +59 7.24 MB jameshenry
npm/@wagmi/[email protected] environment +1 549 kB jmoxey
npm/[email protected] None +1 381 kB bkimminich
npm/[email protected] None 0 92.3 kB kirilv
npm/[email protected] filesystem Transitive: environment, eval, shell, unsafe +47 61.2 MB mgechev
npm/[email protected] None 0 506 kB alincode
npm/[email protected] None 0 2.96 MB marijn
npm/[email protected] None 0 1.24 MB zloirock
npm/[email protected] None 0 16.9 kB lydell
npm/[email protected] Transitive: environment, eval, filesystem, shell, unsafe +87 14.1 MB gajus
npm/[email protected] None 0 28.7 kB feross
npm/[email protected] None 0 36 kB endless
npm/[email protected] None 0 4.37 MB lipis
npm/[email protected] None 0 3.22 MB exaptis
npm/[email protected] filesystem 0 394 kB sgravrock
npm/[email protected] filesystem 0 220 kB bcaudan
npm/[email protected] Transitive: environment, filesystem +6 574 kB sgravrock
npm/[email protected] None 0 26.4 kB jfromaniello
npm/[email protected] environment, filesystem +2 50.1 kB karmarunnerbot
npm/[email protected] Transitive: environment, filesystem, shell, unsafe +56 12.8 MB karmarunnerbot
npm/[email protected] None 0 55.4 kB dfederm
npm/[email protected] None 0 25.8 kB karmarunnerbot
npm/[email protected] environment, filesystem, network, shell +31 4.28 MB karmarunnerbot
npm/[email protected] eval 0 636 kB bnjmnt4n
npm/[email protected] None 0 859 kB marella
npm/[email protected] None 0 119 kB tommueller
npm/[email protected] None 0 626 kB bichard
npm/[email protected] None +1 721 kB valorkin
npm/[email protected] None 0 122 kB maxisam
npm/[email protected] None 0 132 kB sa.alemdar
npm/[email protected] None 0 257 kB murhaf
npm/[email protected] None 0 444 kB geek2210
npm/[email protected] None +1 651 kB abenassi87
npm/[email protected] None 0 8.77 kB maxisam
npm/[email protected] None +1 5.16 MB blesh
npm/[email protected] filesystem, unsafe Transitive: environment +14 6.96 MB sassbot
npm/[email protected] None 0 34.6 kB developit
npm/[email protected] Transitive: environment +2 977 kB darrachequesne
npm/[email protected] network 0 6.1 kB nikola-bozin-org
npm/[email protected] None 0 26.8 kB bjankord
npm/[email protected] None +2 1.81 MB kristerkari
npm/[email protected] environment, filesystem Transitive: eval, shell, unsafe +52 8.48 MB jeddy3
npm/[email protected] environment, filesystem, unsafe 0 757 kB blakeembrey
npm/[email protected] None 0 68.8 MB typescript-bot
npm/[email protected] None 0 5.5 MB google-wombot
npm/[email protected] environment 0 304 kB daishi

🚮 Removed packages: npm/@cyclonedx/[email protected], npm/@istanbuljs/[email protected], npm/@types/[email protected], npm/@types/[email protected], npm/@types/[email protected], npm/@types/[email protected], npm/@types/[email protected], npm/@types/[email protected], npm/@types/[email protected], npm/@types/[email protected], npm/@types/[email protected], npm/@types/[email protected], npm/@types/[email protected], npm/@types/[email protected], npm/@types/[email protected], npm/@types/[email protected], npm/@types/[email protected], npm/@types/[email protected], npm/@types/[email protected], npm/@types/[email protected], npm/@types/[email protected], npm/@types/[email protected], npm/@types/[email protected], npm/@types/[email protected], npm/@types/[email protected], npm/@types/[email protected], npm/@types/[email protected], npm/@types/[email protected], npm/@types/[email protected], npm/@types/[email protected], npm/@types/[email protected], npm/@types/[email protected], npm/@types/[email protected], npm/@types/[email protected], npm/@types/[email protected], npm/@types/[email protected], npm/@types/[email protected], npm/@types/[email protected], npm/@types/[email protected], npm/@types/[email protected], npm/@types/[email protected], npm/@types/[email protected], npm/[email protected], npm/[email protected], npm/[email protected], npm/[email protected], npm/[email protected], npm/[email protected], npm/[email protected], npm/[email protected], npm/[email protected], npm/[email protected], npm/[email protected], npm/[email protected], npm/[email protected], npm/[email protected], npm/[email protected], npm/[email protected], npm/[email protected], npm/[email protected], npm/[email protected], npm/[email protected], npm/[email protected], npm/[email protected], npm/[email protected], npm/[email protected], npm/[email protected], npm/[email protected], npm/[email protected], npm/[email protected], npm/[email protected], npm/[email protected], npm/[email protected], npm/[email protected], npm/[email protected], npm/[email protected], npm/[email protected], npm/[email protected], npm/[email protected], npm/[email protected], npm/[email protected], npm/[email protected]

View full report↗︎

@rafikmojr
Copy link

Logo
Checkmarx One – Scan Summary & Details07c9d31e-43d1-4043-aa0c-8b3eb165a950

New Issues

Severity Issue Source File / Package Checkmarx Insight
CRITICAL Second_Order_SQL_Injection /routes/chatbot.ts: 24 Attack Vector
CRITICAL Second_Order_SQL_Injection /routes/chatbot.ts: 45 Attack Vector
CRITICAL Second_Order_SQL_Injection /routes/chatbot.ts: 45 Attack Vector
CRITICAL Second_Order_SQL_Injection /routes/chatbot.ts: 45 Attack Vector
CRITICAL Second_Order_SQL_Injection /routes/chatbot.ts: 24 Attack Vector
CRITICAL Second_Order_SQL_Injection /routes/chatbot.ts: 45 Attack Vector
CRITICAL Second_Order_SQL_Injection /routes/chatbot.ts: 45 Attack Vector
CRITICAL Second_Order_SQL_Injection /routes/chatbot.ts: 45 Attack Vector
CRITICAL Stored_XSS /routes/videoHandler.ts: 74 Attack Vector
CRITICAL Stored_XSS /routes/videoHandler.ts: 79 Attack Vector
CRITICAL Stored_XSS /routes/userProfile.ts: 76 Attack Vector
CRITICAL Stored_XSS /routes/userProfile.ts: 55 Attack Vector
MEDIUM CVE-2024-47764 Npm-cookie-0.4.2 Vulnerable Package
MEDIUM Client_Privacy_Violation /frontend/src/app/register/register.component.spec.ts: 150 Attack Vector
MEDIUM Client_Privacy_Violation /frontend/src/app/change-password/change-password.component.spec.ts: 115 Attack Vector
MEDIUM Client_Privacy_Violation /frontend/src/app/change-password/change-password.component.spec.ts: 102 Attack Vector
MEDIUM Client_Privacy_Violation /frontend/src/app/change-password/change-password.component.spec.ts: 116 Attack Vector
MEDIUM Client_Privacy_Violation /frontend/src/app/change-password/change-password.component.spec.ts: 103 Attack Vector
MEDIUM Client_Privacy_Violation /frontend/src/app/app.module.ts: 222 Attack Vector
MEDIUM Client_Privacy_Violation /frontend/src/app/register/register.component.ts: 31 Attack Vector
MEDIUM Client_Privacy_Violation /frontend/src/app/forgot-password/forgot-password.component.ts: 23 Attack Vector
MEDIUM Client_Privacy_Violation /frontend/src/app/forgot-password/forgot-password.component.ts: 23 Attack Vector
MEDIUM Client_Privacy_Violation /frontend/src/app/forgot-password/forgot-password.component.ts: 23 Attack Vector
MEDIUM Client_Privacy_Violation /frontend/src/app/forgot-password/forgot-password.component.ts: 23 Attack Vector
MEDIUM Client_Privacy_Violation /frontend/src/app/change-password/change-password.component.ts: 22 Attack Vector
MEDIUM Client_Privacy_Violation /frontend/src/app/change-password/change-password.component.ts: 22 Attack Vector
MEDIUM Client_Privacy_Violation /frontend/src/app/change-password/change-password.component.ts: 22 Attack Vector
MEDIUM Client_Privacy_Violation /frontend/src/app/change-password/change-password.component.ts: 22 Attack Vector
MEDIUM Client_Privacy_Violation /frontend/src/app/app.module.ts: 164 Attack Vector
MEDIUM Client_Privacy_Violation /frontend/src/app/app.module.ts: 161 Attack Vector
MEDIUM Client_Privacy_Violation /frontend/src/app/change-password/change-password.component.ts: 25 Attack Vector
MEDIUM Client_Privacy_Violation /frontend/src/app/change-password/change-password.component.ts: 24 Attack Vector
MEDIUM Client_Privacy_Violation /frontend/src/app/forgot-password/forgot-password.component.ts: 27 Attack Vector
MEDIUM Client_Privacy_Violation /frontend/src/app/forgot-password/forgot-password.component.ts: 71 Attack Vector
MEDIUM Client_Privacy_Violation /frontend/src/app/change-password/change-password.component.ts: 45 Attack Vector
LOW Use_Of_Hardcoded_Password /frontend/src/app/register/register.component.spec.ts: 136 Attack Vector
LOW Use_Of_Hardcoded_Password /test/api/deluxeApiSpec.ts: 105 Attack Vector

Fixed Issues

Severity Issue Source File / Package
CRITICAL Stored_XSS /routes/vulnCodeFixes.ts: 28
CRITICAL Stored_XSS /routes/vulnCodeFixes.ts: 80
CRITICAL Stored_XSS /routes/vulnCodeFixes.ts: 80
CRITICAL Stored_XSS /routes/vulnCodeSnippet.ts: 94
CRITICAL Stored_XSS /routes/search.ts: 24
CRITICAL Stored_XSS /data/static/codefixes/dbSchemaChallenge_3.ts: 12
CRITICAL Stored_XSS /data/static/codefixes/unionSqlInjectionChallenge_3.ts: 11
CRITICAL Stored_XSS /data/static/codefixes/dbSchemaChallenge_2_correct.ts: 8
CRITICAL Stored_XSS /data/static/codefixes/unionSqlInjectionChallenge_2_correct.ts: 8
CRITICAL Stored_XSS /data/static/codefixes/unionSqlInjectionChallenge_1.ts: 7
CRITICAL Stored_XSS /data/static/codefixes/dbSchemaChallenge_1.ts: 6
CRITICAL Stored_XSS /routes/vulnCodeFixes.ts: 28
CRITICAL Stored_XSS /routes/vulnCodeFixes.ts: 80
CRITICAL Stored_XSS /routes/vulnCodeFixes.ts: 80
CRITICAL Stored_XSS /routes/vulnCodeSnippet.ts: 94
CRITICAL Stored_XSS /routes/search.ts: 24
CRITICAL Stored_XSS /data/static/codefixes/dbSchemaChallenge_3.ts: 12
CRITICAL Stored_XSS /data/static/codefixes/unionSqlInjectionChallenge_3.ts: 11
CRITICAL Stored_XSS /data/static/codefixes/dbSchemaChallenge_2_correct.ts: 8
CRITICAL Stored_XSS /data/static/codefixes/unionSqlInjectionChallenge_2_correct.ts: 8
CRITICAL Stored_XSS /data/static/codefixes/unionSqlInjectionChallenge_1.ts: 7
CRITICAL Stored_XSS /data/static/codefixes/dbSchemaChallenge_1.ts: 6
CRITICAL Stored_XSS /data/static/codefixes/dbSchemaChallenge_3.ts: 12
CRITICAL Stored_XSS /routes/vulnCodeFixes.ts: 80
CRITICAL Stored_XSS /data/static/codefixes/unionSqlInjectionChallenge_1.ts: 7
CRITICAL Stored_XSS /routes/vulnCodeFixes.ts: 80
CRITICAL Stored_XSS /data/static/codefixes/unionSqlInjectionChallenge_2_correct.ts: 8
CRITICAL Stored_XSS /routes/vulnCodeFixes.ts: 28
CRITICAL Stored_XSS /routes/vulnCodeSnippet.ts: 94
CRITICAL Stored_XSS /data/static/codefixes/dbSchemaChallenge_2_correct.ts: 8
CRITICAL Stored_XSS /data/static/codefixes/unionSqlInjectionChallenge_3.ts: 11
CRITICAL Stored_XSS /routes/search.ts: 24
CRITICAL Stored_XSS /data/static/codefixes/dbSchemaChallenge_1.ts: 6
CRITICAL Stored_XSS /routes/vulnCodeFixes.ts: 80
CRITICAL Stored_XSS /data/static/codefixes/unionSqlInjectionChallenge_2_correct.ts: 8
CRITICAL Stored_XSS /routes/vulnCodeFixes.ts: 80
CRITICAL Stored_XSS /routes/search.ts: 24
CRITICAL Stored_XSS /routes/vulnCodeFixes.ts: 28
CRITICAL Stored_XSS /routes/vulnCodeSnippet.ts: 94
CRITICAL Stored_XSS /data/static/codefixes/dbSchemaChallenge_2_correct.ts: 8
CRITICAL Stored_XSS /data/static/codefixes/unionSqlInjectionChallenge_1.ts: 7
CRITICAL Stored_XSS /data/static/codefixes/dbSchemaChallenge_1.ts: 6
CRITICAL Stored_XSS /data/static/codefixes/dbSchemaChallenge_3.ts: 12
CRITICAL Stored_XSS /data/static/codefixes/unionSqlInjectionChallenge_3.ts: 11
CRITICAL Stored_XSS /data/static/codefixes/unionSqlInjectionChallenge_1.ts: 7
CRITICAL Stored_XSS /data/static/codefixes/unionSqlInjectionChallenge_3.ts: 11
CRITICAL Stored_XSS /data/static/codefixes/dbSchemaChallenge_3.ts: 12
CRITICAL Stored_XSS /routes/search.ts: 24
CRITICAL Stored_XSS /data/static/codefixes/loginAdminChallenge_1.ts: 21
CRITICAL Stored_XSS /data/static/codefixes/dbSchemaChallenge_2_correct.ts: 8
CRITICAL Stored_XSS /data/static/codefixes/loginBenderChallenge_1.ts: 21
CRITICAL Stored_XSS /data/static/codefixes/loginJimChallenge_4.ts: 21
CRITICAL Stored_XSS /routes/login.ts: 37
CRITICAL Stored_XSS /data/static/codefixes/unionSqlInjectionChallenge_2_correct.ts: 8
CRITICAL Stored_XSS /routes/vulnCodeSnippet.ts: 94
CRITICAL Stored_XSS /data/static/codefixes/loginAdminChallenge_1.ts: 21
CRITICAL Stored_XSS /data/static/codefixes/loginBenderChallenge_1.ts: 21
CRITICAL Stored_XSS /data/static/codefixes/loginJimChallenge_4.ts: 21
CRITICAL Stored_XSS /data/static/codefixes/dbSchemaChallenge_1.ts: 6
CRITICAL Stored_XSS /routes/login.ts: 37
CRITICAL Stored_XSS /routes/vulnCodeFixes.ts: 80
CRITICAL Stored_XSS /routes/vulnCodeFixes.ts: 80
CRITICAL Stored_XSS /routes/vulnCodeFixes.ts: 28
CRITICAL Stored_XSS /data/static/codefixes/unionSqlInjectionChallenge_2_correct.ts: 8
CRITICAL Stored_XSS /data/static/codefixes/unionSqlInjectionChallenge_3.ts: 11
CRITICAL Stored_XSS /routes/login.ts: 37
CRITICAL Stored_XSS /data/static/codefixes/loginBenderChallenge_1.ts: 21
CRITICAL Stored_XSS /data/static/codefixes/loginJimChallenge_4.ts: 21
CRITICAL Stored_XSS /data/static/codefixes/dbSchemaChallenge_2_correct.ts: 8
CRITICAL Stored_XSS /data/static/codefixes/loginBenderChallenge_1.ts: 21
CRITICAL Stored_XSS /data/static/codefixes/dbSchemaChallenge_1.ts: 6
CRITICAL Stored_XSS /routes/search.ts: 24
CRITICAL Stored_XSS /data/static/codefixes/dbSchemaChallenge_3.ts: 12
CRITICAL Stored_XSS /data/static/codefixes/loginJimChallenge_4.ts: 21
CRITICAL Stored_XSS /data/static/codefixes/loginAdminChallenge_1.ts: 21
CRITICAL Stored_XSS /data/static/codefixes/unionSqlInjectionChallenge_1.ts: 7
CRITICAL Stored_XSS /data/static/codefixes/loginAdminChallenge_1.ts: 21
MEDIUM CVE-2024-42459 Npm-elliptic-6.5.4
MEDIUM CVE-2024-42460 Npm-elliptic-6.5.4
MEDIUM CVE-2024-42461 Npm-elliptic-6.5.4
MEDIUM Client_Privacy_Violation /frontend/src/app/register/register.component.ts: 60
MEDIUM Client_Privacy_Violation /frontend/src/app/forgot-password/forgot-password.component.html: 69
MEDIUM Client_Privacy_Violation /frontend/src/app/forgot-password/forgot-password.component.html: 59
MEDIUM Client_Privacy_Violation /frontend/src/app/change-password/change-password.component.html: 53
MEDIUM Client_Privacy_Violation /frontend/src/app/change-password/change-password.component.html: 39
MEDIUM Client_Privacy_Violation /frontend/src/app/Services/user.service.ts: 55
MEDIUM Client_Privacy_Violation /frontend/src/app/register/register.component.ts: 60
MEDIUM Client_Privacy_Violation /frontend/src/app/forgot-password/forgot-password.component.html: 69
MEDIUM Client_Privacy_Violation /frontend/src/app/forgot-password/forgot-password.component.html: 59
MEDIUM Client_Privacy_Violation /frontend/src/app/change-password/change-password.component.html: 53
MEDIUM Client_Privacy_Violation /frontend/src/app/change-password/change-password.component.html: 39
MEDIUM Client_Privacy_Violation /frontend/src/app/Services/user.service.ts: 55
MEDIUM Client_Privacy_Violation /frontend/src/app/register/register.component.ts: 60
MEDIUM Client_Privacy_Violation /frontend/src/app/forgot-password/forgot-password.component.html: 69
MEDIUM Client_Privacy_Violation /frontend/src/app/forgot-password/forgot-password.component.html: 59
MEDIUM Client_Privacy_Violation /frontend/src/app/change-password/change-password.component.html: 53
MEDIUM Client_Privacy_Violation /frontend/src/app/change-password/change-password.component.html: 39
MEDIUM

More results are available on AST platform

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants