[Snyk] Security upgrade tape-run from 6.0.1 to 11.0.0 #1391
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This PR was automatically created by Snyk using the credentials of a real user.
![snyk-top-banner](https://github.com/andygongea/OWASP-Benchmark/assets/818805/c518c423-16fe-447e-b67f-ad5a49b5d123)
Snyk has created this PR to fix 33 vulnerabilities in the npm dependencies of this project.
Snyk changed the following file(s):
tools/node_modules/eslint/node_modules/parse-entities/package.json
Vulnerabilities that will be fixed with an upgrade:
SNYK-JS-ELECTRON-2805803
SNYK-JS-ELECTRON-1257943
SNYK-JS-ELECTRON-1041745
SNYK-JS-ELECTRON-1085705
SNYK-JS-ELECTRON-1088600
SNYK-JS-ELECTRON-1252279
SNYK-JS-ELECTRON-1312314
SNYK-JS-ELECTRON-1313765
SNYK-JS-ELECTRON-1534883
SNYK-JS-ELECTRON-1656743
SNYK-JS-ELECTRON-1910985
SNYK-JS-ELECTRON-3014411
SNYK-JS-ELECTRON-3091122
SNYK-JS-ELECTRON-6179663
SNYK-JS-ELECTRON-5923343
SNYK-JS-ELECTRON-2946881
SNYK-JS-ELECTRON-1911949
SNYK-JS-ELECTRON-2414027
SNYK-JS-ELECTRON-1021884
SNYK-JS-ELECTRON-1047306
SNYK-JS-ELECTRON-2322001
SNYK-JS-ELECTRON-2434822
SNYK-JS-ELECTRON-6137744
SNYK-JS-ELECTRON-1296559
SNYK-JS-ELECTRON-1536581
SNYK-JS-ELECTRON-570833
SNYK-JS-ELECTRON-1912085
SNYK-JS-ELECTRON-1050882
SNYK-JS-ELECTRON-6146931
SNYK-JS-ELECTRON-1050999
SNYK-JS-ELECTRON-1070013
SNYK-JS-ELECTRON-1315668
SNYK-JS-ELECTRON-2332173
Important
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.
For more information:
🧐 View latest project report
📜 Customise PR templates
🛠 Adjust project settings
📚 Read about Snyk's upgrade logic
Learn how to fix vulnerabilities with free interactive lessons:
🦉 Type Confusion
🦉 Use After Free
🦉 Insufficient Validation
[//]: # 'snyk:metadata:{"customTemplate":{"variablesUsed":[],"fieldsUsed":[]},"dependencies":[{"name":"tape-run","from":"6.0.1","to":"11.0.0"}],"env":"prod","issuesToFix":[{"exploit_maturity":"Mature","id":"SNYK-JS-ELECTRON-2805803","priority_score":919,"priority_score_factors":[{"type":"exploit","label":"High","score":214},{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"9.8","score":490},{"type":"scoreVersion","label":"v1","score":1}],"severity":"critical","title":"Type Confusion"},{"exploit_maturity":"Mature","id":"SNYK-JS-ELECTRON-1257943","priority_score":876,"priority_score_factors":[{"type":"exploit","label":"Functional","score":171},{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"9.8","score":490},{"type":"scoreVersion","label":"v1","score":1}],"severity":"critical","title":"Out-of-bounds"},{"exploit_maturity":"Mature","id":"SNYK-JS-ELECTRON-1088600","priority_score":869,"priority_score_factors":[{"type":"exploit","label":"High","score":214},{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"8.8","score":440},{"type":"scoreVersion","label":"v1","score":1}],"severity":"high","title":"Out-of-bounds Write"},{"exploit_maturity":"Mature","id":"SNYK-JS-ELECTRON-1252279","priority_score":869,"priority_score_factors":[{"type":"exploit","label":"High","score":214},{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"8.8","score":440},{"type":"scoreVersion","label":"v1","score":1}],"severity":"high","title":"Use After Free"},{"exploit_maturity":"Mature","id":"SNYK-JS-ELECTRON-1085705","priority_score":869,"priority_score_factors":[{"type":"exploit","label":"High","score":214},{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"8.8","score":440},{"type":"scoreVersion","label":"v1","score":1}],"severity":"high","title":"Use After Free"},{"exploit_maturity":"Mature","id":"SNYK-JS-ELECTRON-1041745","priority_score":869,"priority_score_factors":[{"type":"exploit","label":"High","score":214},{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"8.8","score":440},{"type":"scoreVersion","label":"v1","score":1}],"severity":"high","title":"Use After Free"},{"exploit_maturity":"Mature","id":"SNYK-JS-ELECTRON-1312314","priority_score":869,"priority_score_factors":[{"type":"exploit","label":"High","score":214},{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"8.8","score":440},{"type":"scoreVersion","label":"v1","score":1}],"severity":"high","title":"Access of Resource Using Incompatible Type ('Type Confusion')"},{"exploit_maturity":"Mature","id":"SNYK-JS-ELECTRON-1313765","priority_score":869,"priority_score_factors":[{"type":"exploit","label":"High","score":214},{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"8.8","score":440},{"type":"scoreVersion","label":"v1","score":1}],"severity":"high","title":"Use After Free"},{"exploit_maturity":"Mature","id":"SNYK-JS-ELECTRON-1656743","priority_score":869,"priority_score_factors":[{"type":"exploit","label":"High","score":214},{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"8.8","score":440},{"type":"scoreVersion","label":"v1","score":1}],"severity":"high","title":"Use After Free"},{"exploit_maturity":"Mature","id":"SNYK-JS-ELECTRON-1910985","priority_score":869,"priority_score_factors":[{"type":"exploit","label":"High","score":214},{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"8.8","score":440},{"type":"scoreVersion","label":"v1","score":1}],"severity":"high","title":"Use After Free"},{"exploit_maturity":"Mature","id":"SNYK-JS-ELECTRON-1534883","priority_score":869,"priority_score_factors":[{"type":"exploit","label":"High","score":214},{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"8.8","score":440},{"type":"scoreVersion","label":"v1","score":1}],"severity":"high","title":"Type Confusion"},{"exploit_maturity":"Mature","id":"SNYK-JS-ELECTRON-3014411","priority_score":869,"priority_score_factors":[{"type":"exploit","label":"High","score":214},{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"8.8","score":440},{"type":"scoreVersion","label":"v1","score":1}],"severity":"high","title":"Use After Free"},{"exploit_maturity":"Mature","id":"SNYK-JS-ELECTRON-3091122","priority_score":869,"priority_score_factors":[{"type":"exploit","label":"High","score":214},{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"8.8","score":440},{"type":"scoreVersion","label":"v1","score":1}],"severity":"high","title":"Type Confusion"},{"exploit_maturity":"Mature","id":"SNYK-JS-ELECTRON-6179663","priority_score":869,"priority_score_factors":[{"type":"exploit","label":"High","score":214},{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"8.8","score":440},{"type":"scoreVersion","label":"v1","score":1}],"severity":"high","title":"Out-of-bounds Read"},{"exploit_maturity":"Mature","id":"SNYK-JS-ELECTRON-5923343","priority_score":865,"priority_score_factors":[{"type":"exploit","label":"High","score":214},{"type":"freshness","label":true,"score":71},{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"7.3","score":365},{"type":"scoreVersion","label":"v1","score":1}],"severity":"high","title":"Heap-based Buffer Overflow"},{"exploit_maturity":"Mature","id":"SNYK-JS-ELECTRON-2946881","priority_score":859,"priority_score_factors":[{"type":"exploit","label":"High","score":214},{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"8.6","score":430},{"type":"scoreVersion","label":"v1","score":1}],"severity":"high","title":"Heap-based Buffer Overflow"},{"exploit_maturity":"Proof of Concept","id":"SNYK-JS-ELECTRON-1911949","priority_score":811,"priority_score_factors":[{"type":"exploit","label":"Proof of Concept","score":107},{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"9.8","score":490},{"type":"scoreVersion","label":"v1","score":1}],"severity":"critical","title":"Type Confusion"},{"exploit_maturity":"Mature","id":"SNYK-JS-ELECTRON-2414027","priority_score":809,"priority_score_factors":[{"type":"exploit","label":"High","score":214},{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"7.6","score":380},{"type":"scoreVersion","label":"v1","score":1}],"severity":"high","title":"Use After Free"},{"exploit_maturity":"Mature","id":"SNYK-JS-ELECTRON-1021884","priority_score":804,"priority_score_factors":[{"type":"exploit","label":"High","score":214},{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"7.5","score":375},{"type":"scoreVersion","label":"v1","score":1}],"severity":"high","title":"Heap-based Buffer Overflow"},{"exploit_maturity":"Mature","id":"SNYK-JS-ELECTRON-1047306","priority_score":794,"priority_score_factors":[{"type":"exploit","label":"High","score":214},{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"7.3","score":365},{"type":"scoreVersion","label":"v1","score":1}],"severity":"high","title":"Improper Validation"},{"exploit_maturity":"Mature","id":"SNYK-JS-ELECTRON-2322001","priority_score":794,"priority_score_factors":[{"type":"exploit","label":"High","score":214},{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"7.3","score":365},{"type":"scoreVersion","label":"v1","score":1}],"severity":"high","title":"Use After Free"},{"exploit_maturity":"Mature","id":"SNYK-JS-ELECTRON-2434822","priority_score":794,"priority_score_factors":[{"type":"exploit","label":"High","score":214},{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"7.3","score":365},{"type":"scoreVersion","label":"v1","score":1}],"severity":"high","title":"Type Confusion"},{"exploit_maturity":"Mature","id":"SNYK-JS-ELECTRON-6137744","priority_score":794,"priority_score_factors":[{"type":"exploit","label":"High","score":214},{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"7.3","score":365},{"type":"scoreVersion","label":"v1","score":1}],"severity":"high","title":"Heap-based Buffer Overflow"},{"exploit_maturity":"Proof of Concept","id":"SNYK-JS-ELECTRON-1296559","priority_score":761,"priority_score_factors":[{"type":"exploit","label":"Proof of Concept","score":107},{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"8.8","score":440},{"type":"scoreVersion","label":"v1","score":1}],"severity":"high","title":"Type Confusion"},{"exploit_maturity":"Proof of Concept","id":"SNYK-JS-ELECTRON-1536581","priority_score":761,"priority_score_factors":[{"type":"exploit","label":"Proof of Concept","score":107},{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"8.8","score":440},{"type":"scoreVersion","label":"v1","score":1}],"severity":"high","title":"Use After Free"},{"exploit_maturity":"Proof of Concept","id":"SNYK-JS-ELECTRON-570833","priority_score":761,"priority_score_factors":[{"type":"exploit","label":"Proof of Concept","score":107},{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"8.8","score":440},{"type":"scoreVersion","label":"v1","score":1}],"severity":"high","title":"Type Confusion"},{"exploit_maturity":"Mature","id":"SNYK-JS-ELECTRON-1912085","priority_score":754,"priority_score_factors":[{"type":"exploit","label":"High","score":214},{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"6.5","score":325},{"type":"scoreVersion","label":"v1","score":1}],"severity":"medium","title":"Information Exposure"},{"exploit_maturity":"Mature","id":"SNYK-JS-ELECTRON-1050882","priority_score":751,"priority_score_factors":[{"type":"exploit","label":"Functional","score":171},{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"7.3","score":365},{"type":"scoreVersion","label":"v1","score":1}],"severity":"high","title":"Insufficient Validation"},{"exploit_maturity":"No Known Exploit","id":"SNYK-JS-ELECTRON-6146931","priority_score":718,"priority_score_factors":[{"type":"socialTrends","label":true,"score":111},{"type":"fixability","label":true,"score":167},{"type":"cvssScore","label":"8.8","score":440},{"type":"scoreVersion","label":"v1","score":1}],"severity":"high","title":"Heap-based Buffer Overflow"},{"exploit_maturity":"No Known Exploit","id":"SNYK-JS-ELECTRON-1050999","priority_score":704,"priority_score_factors":[{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"9.8","score":490},{"type":"scoreVersion","label":"v1","score":1}],"severity":"critical","title":"Use After Free"},{"exploit_maturity":"No Known Exploit","id":"SNYK-JS-ELECTRON-1070013","priority_score":704,"priority_score_factors":[{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"9.8","score":490},{"type":"scoreVersion","label":"v1","score":1}],"severity":"critical","title":"Use After Free"},{"exploit_maturity":"No Known Exploit","id":"SNYK-JS-ELECTRON-1315668","priority_score":704,"priority_score_factors":[{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"9.8","score":490},{"type":"scoreVersion","label":"v1","score":1}],"severity":"critical","title":"Out-of-bounds Write"},{"exploit_maturity":"No Known Exploit","id":"SNYK-JS-ELECTRON-2332173","priority_score":704,"priority_score_factors":[{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"9.8","score":490},{"type":"scoreVersion","label":"v1","score":1}],"severity":"critical","title":"Improper Input Validation"}],"prId":"77191ac9-f6c3-4d54-a46e-954b436b1d08","prPublicId":"77191ac9-f6c3-4d54-a46e-954b436b1d08","packageManager":"npm","priorityScoreList":[919,876,869,869,869,869,869,869,869,869,869,869,869,869,865,859,811,809,804,794,794,794,794,761,761,761,754,751,718,704,704,704,704],"projectPublicId":"41aec9b3-a821-46c3-bdf1-1c1da0e2d4b0","projectUrl":"https://app.snyk.io/org/leonardoadame/project/41aec9b3-a821-46c3-bdf1-1c1da0e2d4b0?utm_source=github&utm_medium=referral&page=fix-pr","prType":"backlog","templateFieldSources":{"branchName":"default","commitMessage":"default","description":"default","title":"default"},"templateVariants":["pkg-based-remediation","updated-fix-title","priorityScore"],"type":"auto","upgrade":["SNYK-JS-ELECTRON-1021884","SNYK-JS-ELECTRON-1041745","SNYK-JS-ELECTRON-1047306","SNYK-JS-ELECTRON-1050882","SNYK-JS-ELECTRON-1050999","SNYK-JS-ELECTRON-1070013","SNYK-JS-ELECTRON-1085705","SNYK-JS-ELECTRON-1088600","SNYK-JS-ELECTRON-1252279","SNYK-JS-ELECTRON-1257943","SNYK-JS-ELECTRON-1296559","SNYK-JS-ELECTRON-1312314","SNYK-JS-ELECTRON-1313765","SNYK-JS-ELECTRON-1315668","SNYK-JS-ELECTRON-1534883","SNYK-JS-ELECTRON-1536581","SNYK-JS-ELECTRON-1656743","SNYK-JS-ELECTRON-1910985","SNYK-JS-ELECTRON-1911949","SNYK-JS-ELECTRON-1912085","SNYK-JS-ELECTRON-2322001","SNYK-JS-ELECTRON-2332173","SNYK-JS-ELECTRON-2414027","SNYK-JS-ELECTRON-2434822","SNYK-JS-ELECTRON-2805803","SNYK-JS-ELECTRON-2946881","SNYK-JS-ELECTRON-3014411","SNYK-JS-ELECTRON-3091122","SNYK-JS-ELECTRON-570833","SNYK-JS-ELECTRON-5923343","SNYK-JS-ELECTRON-6137744","SNYK-JS-ELECTRON-6146931","SNYK-JS-ELECTRON-6179663"],"vulns":["SNYK-JS-ELECTRON-2805803","SNYK-JS-ELECTRON-1257943","SNYK-JS-ELECTRON-1088600","SNYK-JS-ELECTRON-1252279","SNYK-JS-ELECTRON-1085705","SNYK-JS-ELECTRON-1041745","SNYK-JS-ELECTRON-1312314","SNYK-JS-ELECTRON-1313765","SNYK-JS-ELECTRON-1656743","SNYK-JS-ELECTRON-1910985","SNYK-JS-ELECTRON-1534883","SNYK-JS-ELECTRON-3014411","SNYK-JS-ELECTRON-3091122","SNYK-JS-ELECTRON-6179663","SNYK-JS-ELECTRON-5923343","SNYK-JS-ELECTRON-2946881","SNYK-JS-ELECTRON-1911949","SNYK-JS-ELECTRON-2414027","SNYK-JS-ELECTRON-1021884","SNYK-JS-ELECTRON-1047306","SNYK-JS-ELECTRON-2322001","SNYK-JS-ELECTRON-2434822","SNYK-JS-ELECTRON-6137744","SNYK-JS-ELECTRON-1296559","SNYK-JS-ELECTRON-1536581","SNYK-JS-ELECTRON-570833","SNYK-JS-ELECTRON-1912085","SNYK-JS-ELECTRON-1050882","SNYK-JS-ELECTRON-6146931","SNYK-JS-ELECTRON-1050999","SNYK-JS-ELECTRON-1070013","SNYK-JS-ELECTRON-1315668","SNYK-JS-ELECTRON-2332173"],"patch":[],"isBreakingChange":true,"remediationStrategy":"dependency"}'