ImperialCollegeLondon / ImperialCollegeLondon/Visual2

Known security vulnerabilities detected

Open
#58 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
F#
Stars
49
Forks
7
PR merge metrics
No merged PRs in 30d

Description

Known security vulnerabilities detected

Dependency mem Version < 4.0.0 Upgrade to ~> 4.0.0
Defined in yarn.lock
Vulnerabilities
WS-2018-0236 Moderate severity

Dependency serialize-javascript Version < 2.1.1 Upgrade to ~> 2.1.1
Defined in yarn.lock
Vulnerabilities
CVE-2019-16769 Moderate severity

Dependency kind-of Version = 6.0.2 Upgrade to ~> 6.0.3
Defined in yarn.lock
Vulnerabilities
CVE-2019-20149 Moderate severity

Dependency minimist Version >= 1.0.0 < 1.2.3 Upgrade to ~> 1.2.3
Defined in yarn.lock
Vulnerabilities
CVE-2020-7598 Moderate severity

Dependency acorn Version >= 5.5.0 < 5.7.4 Upgrade to ~> 5.7.4
Defined in yarn.lock
Vulnerabilities
GHSA-6chw-6frg-f759 Moderate severity

Review all vulnerable dependencies [https://github.com/ImperialCollegeLondon/Visual2/network/alerts]

Contributor guide

No contributing guide indexed for this repository

Research direction

Start with yarn.lock and review the listed mem, serialize-javascript, kind-of, minimist, and acorn dependencies against the linked security alerts. Update the vulnerable dependency versions to the requested ranges and verify that yarn.lock no longer contains the affected versions.

Written by the indexing model from the issue text.

Assessment

Tech stack
javascript
Domain
security
Issue type
Bug
Difficulty
2/5
Estimated time
1-3 hours
Activity status
Stale
Clarity
Clearly specified
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.