Skip to content

[Snyk] Security upgrade gatsby from 2.23.20 to 2.31.0#318

Closed
snyk-bot wants to merge 1 commit into
masterfrom
snyk-fix-fa2210414231c8df59889f12416e6fda
Closed

[Snyk] Security upgrade gatsby from 2.23.20 to 2.31.0#318
snyk-bot wants to merge 1 commit into
masterfrom
snyk-fix-fa2210414231c8df59889f12416e6fda

Conversation

@snyk-bot
Copy link
Copy Markdown

@snyk-bot snyk-bot commented Sep 7, 2021

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

merge advice

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • deps/npm/docs/package.json
    • deps/npm/docs/package-lock.json

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
high severity 768/1000
Why? Proof of Concept exploit, Recently disclosed, Has a fix available, CVSS 7.5
Regular Expression Denial of Service (ReDoS)
SNYK-JS-AXIOS-1579269
No Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: gatsby The new version differs by 250 commits.

See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic

…reduce vulnerabilities

The following vulnerabilities are fixed with an upgrade:
- https://snyk.io/vuln/SNYK-JS-AXIOS-1579269
@mistaken-pull-closer
Copy link
Copy Markdown

Thanks for your submission.

It appears that you've created a pull request using one of our repository's branches. Since this is
almost always a mistake, we're going to go ahead and close this. If it was intentional, please
let us know what you were intending and we can see about reopening it.

Thanks again!

@pull-dog
Copy link
Copy Markdown

pull-dog Bot commented Sep 7, 2021

*Ruff* 🐶 I wasn't able to find any Docker Compose files in your repository at any of the given paths in the pull-dog.json configuration file, or the default docker-compose.yml file 😩 Make sure the given paths are correct.

Files checked:

  • docker-compose.yml
What is this?

Pull Dog is a GitHub app that makes test environments for your pull requests using Docker, from a docker-compose.yml file you specify. It takes 19 seconds to set up (we counted!) and there's a free plan available.

Visit our website to learn more.

Commands
  • @pull-dog up to reprovision or provision the server.
  • @pull-dog down to delete the provisioned server.
Troubleshooting

Need help? Don't hesitate to file an issue in our repository

Configuration

{
  "isLazy": false,
  "dockerComposeYmlFilePaths": [
    "docker-compose.yml"
  ],
  "expiry": "00:00:00",
  "conversationMode": "singleComment"
}

Trace ID
41548920-0f8c-11ec-85b6-1204ae0a5faa

@mistaken-pull-closer mistaken-pull-closer Bot added the invalid This doesn't seem right label Sep 7, 2021
@guardrails
Copy link
Copy Markdown

guardrails Bot commented Sep 7, 2021

⚠️ We detected 2 security issues in this pull request:

Mode: paranoid | Total findings: 2 | Considered vulnerability: 2

Vulnerable Libraries (2)
Severity Details
Medium @graphql-tools/url-loader@6.10.1 (t) upgrade to: >6.10.1
High gatsby@2.31.0 upgrade to: >=1.10.0-alpha.1460dad9

More info on how to fix Vulnerable Libraries in JavaScript.


👉 Go to the dashboard for detailed results.

📥 Happy? Share your feedback with us.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

invalid This doesn't seem right

1 participant