Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Cycode] Fix for vulnerable manifest file dependency - org.mapfish.print:print-standalone updated to version 3.24 #30

Open
wants to merge 1 commit into
base: main
Choose a base branch
from

Conversation

cycode-security-staging[bot]
Copy link

@cycode-security-staging cycode-security-staging bot commented Sep 2, 2024

Vulnerable Dependencies Update

This pull request updates the following 3 manifest files:

File Path Number of Packages Updated
indirect_test/package.json 1
testing_go/go.mod 6
restore_test_2/Go/Archive/example4/go.mod 2
📄 indirect_test/package.json

1 package updated to resolve vulnerabilities:

Package Name Current Version Updated Version
tough-cookie 2.2.0 4.1.3
📄 testing_go/go.mod

6 packages updated to resolve vulnerabilities:

Package Name Current Version Updated Version
code.gitea.io/gitea 1.9.0-dev 1.22.1
golang.org/x/crypto 0.0.0-20190308221718-c2843e01d9a2 0.31.0
golang.org/x/net 0.0.0-20200324143707-d3edc9973b7e 0.33.0
github.com/gophish/gophish 0.1.2 0.12.0
github.com/go-gitea/gitea 1.2.3 1.17.3
github.com/unknown/cae 1.0.0 1.0.1
📄 restore_test_2/Go/Archive/example4/go.mod

2 packages updated to resolve vulnerabilities:

Package Name Current Version Updated Version
golang.org/x/crypto 0.0.0-20190308221718-c2843e01d9a2 0.31.0
golang.org/x/net 0.0.0-20200324143707-d3edc9973b7e 0.33.0

Important

This pull request includes major version updates for one or more packages. Please ensure all changes are thoroughly tested before merging.

…int:print-standalone updated to version 3.24
@jenia-sakirko
Copy link
Contributor

jenia-sakirko commented Dec 30, 2024

Cycode Vulnerable Dependencies Update

This pull request updates the following 3 manifest files:

File Path Number of packages to update
indirect_test/package.json 1
testing_go/go.mod 6
restore_test_2/Go/Archive/example4/go.mod 2

📂 `indirect_test/package.json`

1 package will be updated to resolve vulnerabilities:

Package Name Current Version Updated Version
tough-cookie 2.2.0 4.1.3

📂 `testing_go/go.mod`

6 packages will be updated to resolve vulnerabilities:

Package Name Current Version Updated Version
code.gitea.io/gitea 1.9.0-dev 1.22.1
golang.org/x/crypto 0.0.0-20190308221718-c2843e01d9a2 0.31.0
golang.org/x/net 0.0.0-20200324143707-d3edc9973b7e 0.33.0
github.com/gophish/gophish 0.12 0.12.0
github.com/go-gitea/gitea 1.2.3 1.17.3
github.com/unknown/cae 1.0.0 1.0.1

📂 `restore_test_2/Go/Archive/example4/go.mod`

2 packages will be updated to resolve vulnerabilities:

Package Name Current Version Updated Version
golang.org/x/crypto 0.0.0-20190308221718-c2843e01d9a2 0.31.0
golang.org/x/net 0.0.0-20200324143707-d3edc9973b7e 0.33.0

Important

This pull request updates the major version for one or more packages. Make sure changes are tested before merging.

@jenia-sakirko
Copy link
Contributor

jenia-sakirko commented Jan 6, 2025

Cycode Vulnerable Dependencies Update

This pull request updates the following 3 manifest files:

File Path Number of packages to update
path/to/first/package.json 2
path/to/third/package.json 1
path/to/forth/package.json 1

📂 path/to/first/package.json

2 packages will be updated to resolve vulnerabilities:

Package Name Current Version Updated Version
lodash ^4.17.15 4.17.21
minimist 1.2.0 1.2.5

📂 path/to/third/package.json

1 package will be updated to resolve vulnerabilities:

Package Name Current Version Updated Version
lodash 4.17.21

📂 path/to/forth/package.json

1 package will be updated to resolve vulnerabilities:

Package Name Current Version Updated Version
@angular/cli 9.1.0 10.2.1

Important

This pull request updates the major version for one or more packages. Make sure changes are tested before merging.

@jenia-sakirko
Copy link
Contributor

jenia-sakirko commented Jan 6, 2025

Cycode Vulnerable Dependencies Update

This pull request updates the following 3 manifest files:

File Path Number of packages to update
path/to/first/package.json 2
path/to/third/package.json 1
path/to/forth/package.json 1

📂 path/to/first/package.json

2 packages will be updated to resolve vulnerabilities:

Package Name Current Version Updated Version
lodash ^4.17.15 4.17.21
minimist 1.2.0 1.2.5

📂 path/to/third/package.json

1 package will be updated to resolve vulnerabilities:

Package Name Current Version Updated Version
lodash 4.17.21

📂 path/to/forth/package.json

1 package will be updated to resolve vulnerabilities:

Package Name Current Version Updated Version
@angular/cli 9.1.0 10.2.1

Important

This pull request updates the major version for one or more packages. Make sure changes are tested before merging.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant