Fix vulnerabilities in various package.json and Gemfile files - #7167
Fix vulnerabilities in various package.json and Gemfile files#7167SherfeyInv wants to merge 37 commits into
Conversation
…ues-and-project-with-error/project-with-issues/package.json & test/fixtures/snyk-test-all-projects-exit-codes/project-with-issues-and-project-with-error/project-with-issues/package-lock.json to reduce vulnerabilities The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-JS-LODASH-6139239 - https://snyk.io/vuln/SNYK-JS-LODASH-608086 - https://snyk.io/vuln/SNYK-JS-LODASH-1040724
…quirements/update-dependencies/workspaces/pip-app/requirements.txt to reduce vulnerabilities The following vulnerabilities are fixed by pinning transitive dependencies: - https://snyk.io/vuln/SNYK-PYTHON-DJANGO-2606966 - https://snyk.io/vuln/SNYK-PYTHON-DJANGO-2606969 - https://snyk.io/vuln/SNYK-PYTHON-DJANGO-2940618 - https://snyk.io/vuln/SNYK-PYTHON-DJANGO-40027 - https://snyk.io/vuln/SNYK-PYTHON-DJANGO-40439 - https://snyk.io/vuln/SNYK-PYTHON-DJANGO-559326
…abilities The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-JS-LODASH-450202 - https://snyk.io/vuln/SNYK-JS-LODASH-73638
…b77f22451131d9cba8b4a3186a0 [Snyk] Security upgrade lodash from 4.17.0 to 4.17.12
…b4ea41836b16a880a90de2a20f8 [Snyk] Security upgrade django from 1.6.1 to 3.2.14
…900daec797fdf72c68c03febe12 [Snyk] Security upgrade lodash from 4.17.15 to 4.17.21
…on & packages/snyk-protect/test/fixtures/no-matching-paths/package-lock.json to reduce vulnerabilities The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-JS-AJV-15274295 - https://snyk.io/vuln/SNYK-JS-QS-15268416
…pp-2/bundler-app-3/bundler-app-4/bundler-app-5/bundler-app-17/Gemfile & test/acceptance/workspaces/large-mono-repo/bundler-app/bundler-app-2/bundler-app-3/bundler-app-4/bundler-app-5/bundler-app-17/Gemfile.lock to reduce vulnerabilities The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-RUBY-RACK-2848599
…ile & test/acceptance/workspaces/mono-repo-project-manifests-only/Gemfile.lock to reduce vulnerabilities The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-RUBY-ACTIONVIEW-569156 - https://snyk.io/vuln/SNYK-RUBY-ACTIVESUPPORT-569598 - https://snyk.io/vuln/SNYK-RUBY-NOKOGIRI-20432 - https://snyk.io/vuln/SNYK-RUBY-ACTIONVIEW-20262 - https://snyk.io/vuln/SNYK-RUBY-ACTIONPACK-20264
…e vulnerabilities The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-JS-QS-15268416
….json & test/acceptance/workspaces/large-mono-repo/npm-project-3/package-lock.json to reduce vulnerabilities The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-JS-QS-15268416
The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-JS-QS-15268416
…patches-for-version/package.json to reduce vulnerabilities The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-JS-UUID-16133035
The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-JS-UUID-16133035
…5d51f327a12ebb061e21fc024583
…ccb8783c2f7f0340ea702e98bbd0
…patches-for-version/package.json to reduce vulnerabilities The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-JS-TAR-15032660 - https://snyk.io/vuln/SNYK-JS-TAR-15038581 - https://snyk.io/vuln/SNYK-JS-TAR-15127355 - https://snyk.io/vuln/SNYK-JS-TAR-15307072 - https://snyk.io/vuln/SNYK-JS-TAR-15416075 - https://snyk.io/vuln/SNYK-JS-TAR-15456201 - https://snyk.io/vuln/SNYK-JS-INFLIGHT-6095116
…cf2cafe667b789d739a06826dd3c
….json to reduce vulnerabilities (#451) The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-JS-MONGOOSE-16425765 Co-authored-by: snyk-bot <snyk-bot@snyk.io>
….json & test/acceptance/workspaces/large-mono-repo/npm-project-7/package-lock.json to reduce vulnerabilities (#447) The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-JS-QS-15268416 Co-authored-by: snyk-bot <snyk-bot@snyk.io>
…e.json to reduce vulnerabilities (#446) The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-JS-QS-15268416 Co-authored-by: snyk-bot <snyk-bot@snyk.io>
…-version/package.json & test/acceptance/workspaces/npm-lock-v2-with-npm-prefixed-sub-dep-version/package-lock.json to reduce vulnerabilities (#445) The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-JS-GLOB-14040952 - https://snyk.io/vuln/SNYK-JS-TAR-6476909 Co-authored-by: snyk-bot <snyk-bot@snyk.io>
…package.json & test/acceptance/workspaces/npm-package-lockfile-v3-bundled-deps/package-lock.json to reduce vulnerabilities The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-JS-AXIOS-15252993
…2a4ae3c8390c033068da977bc11d [Snyk] Security upgrade qs from 0.6.6 to 6.14.2
…b311d5548bf6a746782baa9fc0d5 [Snyk] Security upgrade qs from 0.0.6 to 6.14.2
…c20dcee8813b5f63b1406f5fc8c8 [Snyk] Security upgrade qs from 0.0.6 to 6.14.2
…089bf6833aa28d1c5fff216e61b7 [Snyk] Security upgrade actionpack from 4.2.5 to 5.2.4.3
…911a4ce710ece07342f70e461f57 [Snyk] Security upgrade rack from 1.6.5 to 2.0.9.1
…92cde9e35e2236aca67725397cad [Snyk] Security upgrade tap from 11.1.3 to 18.0.0
…on & packages/snyk-protect/test/fixtures/no-matching-paths/package-lock.json to reduce vulnerabilities The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-JS-TAR-15307072 - https://snyk.io/vuln/SNYK-JS-TAR-15416075 - https://snyk.io/vuln/SNYK-JS-TAR-15456201 - https://snyk.io/vuln/SNYK-JS-BRACEEXPANSION-18313044 - https://snyk.io/vuln/SNYK-JS-BRACEEXPANSION-18512280
…099fec929f75a135d8bb17cebac9
|
Ron Sherfey seems not to be a GitHub user. You need a GitHub account to be able to sign the CLA. If you have already a GitHub account, please add the email address used for this commit to your account. You have signed the CLA already but the status is still pending? Let us recheck it. |
✅ Snyk checks have passed. No issues have been found so far.
💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse. |
There was a problem hiding this comment.
Cursor Bugbot has reviewed your changes using default effort and found 2 potential issues.
Reviewed by Cursor Bugbot for commit 6f42919. Configure here.
| -r base.txt | ||
| -r base2.txt | ||
| Django==1.6.1 | ||
| Django==3.2.14 |
There was a problem hiding this comment.
Fixture Django version breaks fix test
Medium Severity
The pip-app acceptance workspace now pins Django==3.2.14, but the fixes multiple files that are included via -r test still supplies remediation for django@1.6.1 and expects an upgrade to 2.0.1. Upgrade matching keys off the installed version, so the Django fix is skipped and assertions on write count and change messages fail.
Reviewed by Cursor Bugbot for commit 6f42919. Configure here.
| "strip-ansi": "^6.0.1", | ||
| "tar": "^7.5.8", | ||
| "uuid": "^11.1.1", | ||
| "uuid": "^14.0.0", |
There was a problem hiding this comment.
Lockfile still pins old uuid
Medium Severity
Root package.json now requires uuid ^14.0.0, but this commit does not update package-lock.json, which still resolves uuid to 11.1.1. CI flows using npm ci continue installing the older package, so the intended vulnerability bump may not take effect in automated builds.
Reviewed by Cursor Bugbot for commit 6f42919. Configure here.


Pull Request Submission Checklist
are release-note ready, emphasizing
what was changed, not how.
What does this PR do?
Where should the reviewer start?
How should this be manually tested?
What's the product update that needs to be communicated to CLI users?
Note
Low Risk
Changes are a direct dependency version bump and a test fixture pin; no production logic or auth flows are modified in the diff.
Overview
Bumps the root CLI dependency
uuidfrom^11.1.1to^14.0.0, aligning with existingpackage.jsonoverrides that pin transitiveuuidconsumers to the same version.Updates the snyk-fix pip-requirements acceptance workspace so
pip-app/requirements.txtexpectsDjango==3.2.14instead of1.6.1, keeping the update-dependencies test fixture in line with the remediated pin.Reviewed by Cursor Bugbot for commit 6f42919. Bugbot is set up for automated code reviews on this repo. Configure here.