Skip to content

fix: client/package.json & client/package-lock.json to reduce vulnera…

e26ba21
Select commit
Loading
Failed to load commit list.
Open

[Snyk] Fix for 3 vulnerabilities #44

fix: client/package.json & client/package-lock.json to reduce vulnera…
e26ba21
Select commit
Loading
Failed to load commit list.
Codacy Production / Codacy Static Code Analysis required action Nov 19, 2025 in 0s

18 new issues (0 max.) of at least severity.

Annotations

Check warning on line 2775 in client/package-lock.json

See this annotation in the file changed.

@codacy-production codacy-production / Codacy Static Code Analysis

client/package-lock.json#L2775

Insecure dependency npm/js-yaml@4.1.0 (CVE-2025-64718: js-yaml is a JavaScript YAML parser and dumper. In js-yaml 4.1.0 and b ...) (update to 4.1.1)

Check warning on line 15194 in client/package-lock.json

See this annotation in the file changed.

@codacy-production codacy-production / Codacy Static Code Analysis

client/package-lock.json#L15194

Insecure dependency npm/js-yaml@3.14.1 (CVE-2025-64718: js-yaml is a JavaScript YAML parser and dumper. In js-yaml 4.1.0 and b ...) (update to 3.14.2)

Check warning on line 15561 in client/package-lock.json

See this annotation in the file changed.

@codacy-production codacy-production / Codacy Static Code Analysis

client/package-lock.json#L15561

Insecure dependency npm/loader-utils@2.0.2 (CVE-2022-37599: loader-utils: regular expression denial of service in interpolateName.js) (update to 2.0.4)

Check failure on line 15561 in client/package-lock.json

See this annotation in the file changed.

@codacy-production codacy-production / Codacy Static Code Analysis

client/package-lock.json#L15561

Insecure dependency npm/loader-utils@2.0.2 (CVE-2022-37601: loader-utils: prototype pollution in function parseQuery in parseQuery.js) (update to 2.0.3)

Check warning on line 15561 in client/package-lock.json

See this annotation in the file changed.

@codacy-production codacy-production / Codacy Static Code Analysis

client/package-lock.json#L15561

Insecure dependency npm/loader-utils@2.0.2 (CVE-2022-37603: loader-utils: Regular expression denial of service) (update to 2.0.4)

Check warning on line 15930 in client/package-lock.json

See this annotation in the file changed.

@codacy-production codacy-production / Codacy Static Code Analysis

client/package-lock.json#L15930

Insecure dependency npm/moment@2.29.1 (CVE-2022-24785: Moment.js: Path traversal  in moment.locale) (update to 2.29.2)

Check warning on line 15930 in client/package-lock.json

See this annotation in the file changed.

@codacy-production codacy-production / Codacy Static Code Analysis

client/package-lock.json#L15930

Insecure dependency npm/moment@2.29.1 (CVE-2022-31129: moment: inefficient parsing algorithm resulting in DoS) (update to 2.29.4)

Check warning on line 16026 in client/package-lock.json

See this annotation in the file changed.

@codacy-production codacy-production / Codacy Static Code Analysis

client/package-lock.json#L16026

Insecure dependency npm/node-fetch@2.6.1 (CVE-2022-0235: node-fetch: exposure of sensitive information to an unauthorized actor) (update to 2.6.7)

Check warning on line 16097 in client/package-lock.json

See this annotation in the file changed.

@codacy-production codacy-production / Codacy Static Code Analysis

client/package-lock.json#L16097

Insecure dependency npm/nth-check@1.0.2 (CVE-2021-3803: nodejs-nth-check: inefficient regular expression complexity) (update to 2.0.1)

Check warning on line 16531 in client/package-lock.json

See this annotation in the file changed.

@codacy-production codacy-production / Codacy Static Code Analysis

client/package-lock.json#L16531

Insecure dependency npm/path-to-regexp@1.8.0 (CVE-2024-45296: path-to-regexp: Backtracking regular expressions cause ReDoS) (update to 1.9.0)

Check warning on line 18231 in client/package-lock.json

See this annotation in the file changed.

@codacy-production codacy-production / Codacy Static Code Analysis

client/package-lock.json#L18231

Insecure dependency npm/protobufjs@6.11.2 (CVE-2022-25878: protobufjs: Prototype Pollution via util.setProperty or ReflectionObject.setParsedOption methods) (update to 6.11.3)

Check failure on line 18231 in client/package-lock.json

See this annotation in the file changed.

@codacy-production codacy-production / Codacy Static Code Analysis

client/package-lock.json#L18231

Insecure dependency npm/protobufjs@6.11.2 (CVE-2023-36665: protobufjs: prototype pollution using user-controlled protobuf message) (update to 6.11.4)

Check warning on line 20073 in client/package-lock.json

See this annotation in the file changed.

@codacy-production codacy-production / Codacy Static Code Analysis

client/package-lock.json#L20073

Insecure dependency npm/postcss@7.0.39 (CVE-2023-44270: PostCSS: Improper input validation in PostCSS) (update to 8.4.31)

Check warning on line 20160 in client/package-lock.json

See this annotation in the file changed.

@codacy-production codacy-production / Codacy Static Code Analysis

client/package-lock.json#L20160

Insecure dependency npm/rollup@0.25.8 (CVE-2024-47068: rollup: DOM Clobbering Gadget found in rollup bundled scripts that leads to XSS) (update to 2.79.2)

Check warning on line 20482 in client/package-lock.json

See this annotation in the file changed.

@codacy-production codacy-production / Codacy Static Code Analysis

client/package-lock.json#L20482

Insecure dependency npm/semver@6.3.0 (CVE-2022-25883: nodejs-semver: Regular expression denial of service) (update to 6.3.1)

Check warning on line 21520 in client/package-lock.json

See this annotation in the file changed.

@codacy-production codacy-production / Codacy Static Code Analysis

client/package-lock.json#L21520

Insecure dependency npm/glob@10.4.5 (CVE-2025-64756: glob CLI: Command injection via -c/--cmd executes matches with shell:true) (update to 10.5.0)

Check warning on line 22670 in client/package-lock.json

See this annotation in the file changed.

@codacy-production codacy-production / Codacy Static Code Analysis

client/package-lock.json#L22670

Insecure dependency npm/webpack-dev-server@4.15.2 (CVE-2025-30359: webpack-dev-server: webpack-dev-server information exposure) (update to 5.2.1)

Check warning on line 22670 in client/package-lock.json

See this annotation in the file changed.

@codacy-production codacy-production / Codacy Static Code Analysis

client/package-lock.json#L22670

Insecure dependency npm/webpack-dev-server@4.15.2 (CVE-2025-30360: webpack-dev-server: webpack-dev-server information exposure) (update to 5.2.1)