Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Snyk] Fix for 1 vulnerabilities #164

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

Omrisnyk
Copy link
Owner

This PR was automatically created by Snyk using the credentials of a real user.


![snyk-top-banner](https://github.com/andygongea/OWASP-Benchmark/assets/818805/c518c423-16fe-447e-b67f-ad5a49b5d123)

Snyk has created this PR to fix 1 vulnerabilities in the npm dependencies of this project.

Snyk changed the following file(s):

  • large-file/package.json
  • large-file/package-lock.json

Vulnerabilities that will be fixed with an upgrade:

Issue Score
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-MINIMATCH-3050818
  45  
Release notes
Package name: add-asset-html-webpack-plugin from add-asset-html-webpack-plugin GitHub release notes
Package name: cacache
  • 17.0.5 - 2023-03-21

    17.0.5 (2023-03-21)

    Dependencies

  • 17.0.4 - 2022-12-15

    17.0.4 (2022-12-14)

    Dependencies

  • 17.0.3 - 2022-12-07

    17.0.3 (2022-12-07)

    Dependencies

  • 17.0.2 - 2022-11-04

    17.0.2 (2022-11-04)

    Bug Fixes

  • 17.0.1 - 2022-10-17

    17.0.1 (2022-10-17)

    Dependencies

  • 17.0.0 - 2022-10-13

    17.0.0 (2022-10-13)

    ⚠️ BREAKING CHANGES

    • this module no longer attempts to change file ownership automatically
    • this package is now async only, all synchronous methods have been removed
    • cacache is now compatible with the following semver range for node: ^14.17.0 || ^16.13.0 || >=18.0.0

    Features

  • 16.1.3 - 2022-08-23

    16.1.3 (2022-08-23)

    Dependencies

    • bump unique-filename from 1.1.1 to 2.0.0 (#123) (6235554)
  • 16.1.2 - 2022-08-15

    16.1.2 (2022-08-15)

    Bug Fixes

  • 16.1.1 - 2022-06-02

    16.1.1 (2022-06-02)

    Bug Fixes

    • read: change lstat to stat to correctly evaluate file size (#114) (e3a2928)
  • 16.1.0 - 2022-05-17

    16.1.0 (2022-05-17)

    Features

    • allow external integrity/size source (#110) (61785e1)

    Bug Fixes

    • move to async functions where possible (#106) (71d4389)
  • 16.0.7 - 2022-04-27
  • 16.0.6 - 2022-04-21
  • 16.0.5 - 2022-04-20
  • 16.0.4 - 2022-04-05
  • 16.0.3 - 2022-03-22
  • 16.0.2 - 2022-03-17
  • 16.0.1 - 2022-03-15
  • 16.0.0 - 2022-03-14
  • 15.3.0 - 2021-08-26
  • 15.2.0 - 2021-05-25
  • 15.1.0 - 2021-05-19
  • 15.0.6 - 2021-03-22
  • 15.0.5 - 2020-07-11
  • 15.0.4 - 2020-06-03
  • 15.0.3 - 2020-04-28
  • 15.0.2 - 2020-04-28
  • 15.0.1 - 2020-04-28
  • 15.0.0 - 2020-02-18
  • 14.0.0 - 2020-01-28
  • 13.0.1 - 2019-09-30
  • 13.0.0 - 2019-09-25
  • 12.0.4 - 2020-03-24
  • 12.0.3 - 2019-08-19
  • 12.0.2 - 2019-07-19
  • 12.0.1 - 2019-07-19
  • 12.0.0 - 2019-07-15
  • 11.3.3 - 2019-06-17
  • 11.3.2 - 2018-12-21
  • 11.3.1 - 2018-11-05
  • 11.3.0 - 2018-11-05
  • 11.2.0 - 2018-08-08
  • 11.1.0 - 2018-08-01
  • 11.0.3 - 2018-08-01
  • 11.0.2 - 2018-05-07
  • 11.0.1 - 2018-04-10
  • 11.0.0 - 2018-04-09
  • 10.0.4 - 2018-02-16
from cacache GitHub release notes
Package name: compression-webpack-plugin
  • 7.0.0 - 2020-12-02

    7.0.0 (2020-12-02)

    ⚠ BREAKING CHANGES

    • minimum supported webpack version is ^5.1.0
    • the cache option was removed, the plugin respects caching from configurations, please read
  • 6.1.2 - 2023-12-26
  • 6.1.1 - 2020-11-12

    6.1.1 (2020-11-12)

    Bug Fixes

    • compatibility with child compilations (5e3bb95)
  • 6.1.0 - 2020-11-09

    6.1.0 (2020-11-09)

    Features

    • added the keep-source-maps value to the deleteOriginalAssets option (#216) (bd60650)
  • 6.0.5 - 2020-11-02

    6.0.5 (2020-11-02)

    Bug Fixes

    • allowed compressed assets to overwrite original assets using the deleteOriginalAssets option (62d3d0a)
  • 6.0.4 - 2020-10-26

    6.0.4 (2020-10-26)

    Bug Fixes

    • always set compression level to maximum for the custom algorithm (483f328)
  • 6.0.3 - 2020-10-09

    6.0.3 (2020-10-09)

    Chore

    • update schema-utils
  • 6.0.2 - 2020-09-19

    6.0.2 (2020-09-19)

    Bug Fixes

  • 6.0.1 - 2020-09-16

    6.0.1 (2020-09-16)

    Bug Fixes

  • 6.0.0 - 2020-09-14

    ⚠ BREAKING CHANGES

    • default value of the filename option was changed to "[path][base].gz"
    • removed the [dir] placeholder, please use the [path] placeholder
    • the Function type of the filename option should return value with placeholders, please see an example

    Features

    • added [fragment], [base] and [path] placeholders for the filename option

    Bug Fixes

    • caching (#194) (9de2a88)
    • respect immutable flag for assets
  • 5.0.2 - 2020-09-02

    5.0.2 (2020-09-02)

    Bug Fixes

    • do not crash when the algorithm option return non Buffer (#190) (81bf601)
  • 5.0.1 - 2020-08-22
  • 5.0.0 - 2020-08-17
  • 4.0.1 - 2020-08-12
  • 4.0.0 - 2020-05-12
from compression-webpack-plugin GitHub release notes
Package name: cypress
  • 5.0.0 - 2020-08-19

    Released 8/19/2020

    Summary:

    Cypress now includes support for test retries! Similar to how Cypress will retry assertions when they fail, test retries will allow you to automatically retry a failed test prior to marking it as failed. Read our new guide on Test Retries for more details.

    Breaking Changes:

    Please read our Migration Guide which explains the changes in more detail and how to change your code to migrate to Cypress 5.0.

    • The cypress-plugin-retries plugin has been deprecated in favor of test retries built into Cypress. Addresses #1313.
    • The Cypress.Cookies.defaults() whitelist option has been renamed to preserve to more closely reflect its behavior. Addressed in #7782.
    • The blacklistHosts configuration has been renamed to blockHosts to more closely reflect its behavior. Addressed in #7622.
    • The cy.server() whitelist option has been renamed to ignore to more closely reflect its behavior. Addresses #6642.
    • libgbm-dev is now a requirement to run Cypress on Linux. Addressed in #7791.
    • Values yielded by cy.setCookie(), cy.getCookie(), and cy.getCookies() will now contain the sameSite property if specified. Addresses #6892.
    • The experimentalGetCookiesSameSite configuration flag has been removed, since this behavior is now the default. Addresses #6892.
    • The return type of the Cypress.Blob methods arrayBufferToBlob, base64StringToBlob, binaryStringToBlob, and dataURLToBlob have changed from Promise<Blob> to Blob. Addresses #6001.
    • Cypress no longer supports file paths with a question mark ? in them. We now use the webpack preprocessor by default and it does not support files with question marks. Addressed in #7982.
    • For TypeScript compilation of spec, support, and plugins files, the esModuleInterop option is no longer coerced to true. If you need to utilize esModuleInterop, set it in your tsconfig.json. Addresses #7575.
    • Cypress now requires TypeScript 3.4+. Addressed in #7856.
    • Installing Cypress on your system now requires Node.js 10+. Addresses #6574.
    • In spec files, the values for the globals __dirname and __filename no longer include leading slashes. Addressed in #7982.

    Features:

    • There's a new retries configuration option to configure the number of times to retry a failing test. Addresses #1313.
    • .click(), .dblclick(), and .rightclick() now accept options altKey, ctrlKey, metaKey, and shiftKey to hold down key combinations while clicking. Addresses #486.
    • You can now chain .snapshot() off of cy.stub() and cy.spy() to disabled snapshots during those commands. For example: cy.stub().snapshot(false). Addresses #3849.

    Bugfixes:

    • The error Cannot set property 'err' of undefined will no longer incorrectly throw when rerunning tests in the Test Runner. Fixes #7874 and #8193.
    • Cypress will no longer throw a Cannot read property 'isAttached' of undefined error during cypress run on Firefox versions >= 75. Fixes #6813.
    • The error Maximum call stack size exceeded will no longer throw when calling scrollIntoView on an element in the shadow dom. Fixes #7986.
    • Cypress environment variables that accept arrays as their value will now properly evaluate as arrays. Fixes #6810.
    • Elements having display: inline will no longer be considered hidden if it has child elements within it that are visible. Fixes #6183.
    • When experimentalShadowDomSupport is enabled, .parent() and .parentsUntil() commands now work correctly in shadow dom as well as passing a selector to .parents() when the subject is in the shadow dom. Fixed in #8202.
    • Screenshots will now be correctly taken when a test fails in an afterEach or beforeEach hook after the hook has already passed. Fixes #3744.
    • Cypress will no longer report screenshots overwritten in a cy.screenshot() onAfterScreenshot option as a unique screenshot. Fixes #8079.
    • Taking screenshots will no longer fail when the screenshot names are too long for the filesystem to accept. Fixes #2403.
    • The "last used browser" will now be correctly remembered during cypress open if a non-default-channel browser was selected. Fixes #8281.
    • For TypeScript projects, tsconfig.json will now be loaded and used to configure TypeScript compilation of spec and support files. Fixes #7006 and #7503.
    • reporterStats now correctly show the number of passed and failed tests when a test passes but the afterEach fails. Fixes #7730.
    • The Developer Tools menu will now always display in Electron when switching focus from Specs to the Test Runner. Fixes #3559.

    Documentation Changes:

    • We have a new guide on Test Retries.
    • Our Migration Guide has a new section for 5.0 migration.

    Misc:

    • Cypress now uses the webpack preprocessor by default to preprocess spec files.
    • The Runs tab within the Test Runner has a new improved design when the project has not been set up or login is required. Addressed in #8141.
    • The type for the Window object returned from cy.window() is now correct. Addresses #7856.
    • The type definition for Cypress's ApplicationWindow can now be extended. Addresses #7856.
    • The type definition for reporterOptions has been added. Addresses #7877.

    Dependency Updates

    • Upgraded Chrome browser version used during cypress run and when selecting Electron browser in cypress open from 80 to 83. Addressed in #7791.
    • Upgraded bundled Node.js version from 12.8.1 to 12.14.1. Addressed in #7791.
    • Upgraded chalk from 2.4.2 to 4.1.0. Addressed in #7650.
    • Upgraded cli-table3 from 0.5.1 to 0.6.0. Addressed in #7650.
    • Upgraded electron from 8.3.1 to 9.2.0. Addressed in #7791 and #8235.
    • Upgraded execa from 1.0.0 to 4.0.2. Addressed in #7650.
    • Upgraded express from 4.16.4 to 4.17.1. Addressed in #8179.
    • Upgraded fs-extra from 8.1.0 to 9.0.1. Addressed in #7650.
    • Upgraded log-symbols from 3.0.0 to 4.0.0. Addressed in #7650.
    • Upgraded tmp from 0.1.0 to 0.2.1. Addressed in #7650.
  • 4.12.1 - 2020-08-05

    Released 8/5/2020

    Bugfixes:

    • The error Cannot set property 'err' of undefined will no longer incorrectly throw when rerunning tests in the Test Runner. Fixes #7874.
    • Skipping the last test before a nested suite with a before hook will now correctly run the tests in the suite following the skipped test. Fixes #8086.

    Dependency Updates:

    • Upgraded md5 from 2.2.1 to 2.3.0. Addressed in #8161.
    • Upgraded electron-context-menu from 0.15.1 to 2.2.0. Addressed in #8180.
  • 4.12.0 - 2020-08-03

    Released 8/3/2020

    Features:

    • Now you can control whether screenshots are automatically taken on test failure during cypress run by setting screenshotOnRunFailure in your configuration. Addresses #5029.
    • The pluginsFile now has access to a readonly version property within the config object that returns the current Cypress version being run. This will allow plugins to better target specific Cypress versions. Addresses #6352.
    • During cypress open, you can now run a subset of all specs by entering a text search filter and clicking 'Run n tests'. Addresses #6581.

    Bugfixes:

    • position: fixed elements that have a parent with pointer-events: none will now correctly evaluate as visible. Fixes #6675.
    • Applications using custom elements will no longer trigger infinite XHR request loops. Fixes #1068.
    • When snapshotting the DOM, Cypress no longer causes attributeChangedCallback to be triggered on custom elements. Fixes #7187.
    • Spec files containing + characters now properly run in Cypress. Fixes #5909.
    • When using the fx shortcut in cy.route(), an error is now thrown when the fixture file cannot be found. Fixes #7818.
    • Cypress no longer thrown Cannot read property '__error' of null error when passing a file containing null content to cy.fixture(). Fixes #8010.
    • Values containing exponential operators passed to --env via the command line are now properly read. Fixes #6891.
    • The "Open in IDE" button no longer disappears from hooks when the tests are manually rerun. Fixes #8094.
    • When experimentalSourceRewriting is enabled, AST rewriting will no longer return an output before the body is done being written. This would happen when the response body was too large and the response would be sent while the body was still being modified. Fixes #8043.
    • When using .type(), Cypress now properly types into an input within an iframe that auto focuses the input. Fixes #8111.

    Misc:

    • Dependencies for our cypress npm package are no longer pinned to a specific version. This allows the use of npm audit fix to fix security vulnerabilities without needing a patch release from Cypress. Addresses #8046.
    • We now collect environment variables for AWS CodeBuild when recording to the Dashboard. Addressed #8101.
    • Types inside Module API are now accessible via the CypressCommandLine namespace. Addresses #7309.
    • We added more type definitions for the .should() command. Addresses #5573.
    • Cookie command's expiry property type is now a Number instead of a String. Addresses #8144.
    • There are some minor visual improvements to the Test Runner's Command Log when hovering, focusing and clicking on hook titles and pending tests. Addressed in #8153.

    Dependency Updates:

    • Upgraded jimp from 0.13.0 to 0.14.0. Addressed in #8102.
    • Upgraded moment from 2.26.0 to 2.27.0. Addressed in #8122.
from cypress GitHub release notes
Package name: del from del GitHub release notes
Package name: eslint

… vulnerabilities

The following vulnerabilities are fixed with an upgrade:
- https://snyk.io/vuln/SNYK-JS-MINIMATCH-3050818
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment