Skip to content

[Snyk] Security upgrade @hpcc-js/comms from 3.18.0 to 3.20.0 - #168

Open
GordonSmith wants to merge 1 commit into
masterfrom
snyk-fix-13c95e7f123658acfd179614c7b0c44e
Open

[Snyk] Security upgrade @hpcc-js/comms from 3.18.0 to 3.20.0#168
GordonSmith wants to merge 1 commit into
masterfrom
snyk-fix-13c95e7f123658acfd179614c7b0c44e

Conversation

@GordonSmith

Copy link
Copy Markdown
Owner

snyk-top-banner

Snyk has created this PR to fix 18 vulnerabilities in the npm dependencies of this project.

Snyk changed the following file(s):

  • esp/src/package.json

Vulnerabilities that will be fixed with an upgrade:

Issue
high severity Uncaught Exception
SNYK-JS-UNDICI-19635210
medium severity HTTP Request Smuggling
SNYK-JS-UNDICI-19635212
high severity Use of Persistent Cookies Containing Sensitive Information
SNYK-JS-UNDICI-19635216
critical severity Improper Certificate Validation
SNYK-JS-UNDICI-19635218
critical severity Origin Validation Error
SNYK-JS-UNDICI-19635224
high severity XML Injection
SNYK-JS-XMLDOMXMLDOM-19499070
high severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-XMLDOMXMLDOM-19498551
high severity XML Injection
SNYK-JS-XMLDOMXMLDOM-19498561
high severity Allocation of Resources Without Limits or Throttling
SNYK-JS-XMLDOMXMLDOM-19499069
high severity Inefficient Algorithmic Complexity
SNYK-JS-XMLDOMXMLDOM-19499072
high severity XML Injection
SNYK-JS-XMLDOMXMLDOM-19499073
high severity XML Injection
SNYK-JS-XMLDOMXMLDOM-19499075
high severity Allocation of Resources Without Limits or Throttling
SNYK-JS-XMLDOMXMLDOM-19499076
high severity XML Injection
SNYK-JS-XMLDOMXMLDOM-19499081
high severity Improper Handling of Case Sensitivity
SNYK-JS-XMLDOMXMLDOM-19499086
high severity XML Injection
SNYK-JS-XMLDOMXMLDOM-19498556
medium severity Improper Validation of Syntactic Correctness of Input
SNYK-JS-XMLDOMXMLDOM-19498557
medium severity Improper Encoding or Escaping of Output
SNYK-JS-XMLDOMXMLDOM-19499074

Breaking Change Risk

Merge Risk: Medium

Notice: This assessment is enhanced by AI.


Important

  • Check the changes in this PR to ensure they won't cause issues with your project.
  • Max score is 1000. Note that the real score may have changed since the PR was raised.
  • This PR was automatically created by Snyk using the credentials of a real user.

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report
📜 Customise PR templates
🛠 Adjust project settings
📚 Read about Snyk's upgrade logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Uncaught Exception
🦉 Regular Expression Denial of Service (ReDoS)
🦉 XML Injection
🦉 More lessons are available in Snyk Learn

@GordonSmith

Copy link
Copy Markdown
Owner Author

Merge Risk: Medium

This is a minor version upgrade from 3.18.0 to 3.20.0. A specific changelog or release notes for this version range could not be found within the hpcc-systems/Visualization mono-repository.

Without explicit release notes, there is a degree of uncertainty. While minor releases in well-maintained projects typically avoid breaking changes, it cannot be guaranteed without documentation.

Recommendation: Developers should test the functionality that relies on this package after the upgrade to ensure there are no unexpected behavioral changes. The risk is assessed as medium due to the lack of information.

Notice 🤖: This content was augmented using artificial intelligence. AI-generated content may contain errors and should be reviewed for accuracy before use.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants