Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- # npm audit report
- nth-check <2.0.1
- Severity: high
- Inefficient Regular Expression Complexity in nth-check - https://github.com/advisories/GHSA-rp65-9cf3-cjxr
- fix available via `npm audit fix --force`
- Will install [email protected], which is a breaking change
- node_modules/svgo/node_modules/nth-check
- css-select <=3.1.0
- Depends on vulnerable versions of nth-check
- node_modules/svgo/node_modules/css-select
- svgo 1.0.0 - 1.3.2
- Depends on vulnerable versions of css-select
- node_modules/svgo
- @svgr/plugin-svgo <=5.5.0
- Depends on vulnerable versions of svgo
- node_modules/@svgr/plugin-svgo
- @svgr/webpack 4.0.0 - 5.5.0
- Depends on vulnerable versions of @svgr/plugin-svgo
- node_modules/@svgr/webpack
- react-scripts >=2.1.4
- Depends on vulnerable versions of @svgr/webpack
- Depends on vulnerable versions of resolve-url-loader
- Depends on vulnerable versions of workbox-webpack-plugin
- node_modules/react-scripts
- postcss <8.4.31
- Severity: moderate
- PostCSS line return parsing error - https://github.com/advisories/GHSA-7fh5-64p2-3v2j
- fix available via `npm audit fix --force`
- Will install [email protected], which is a breaking change
- node_modules/resolve-url-loader/node_modules/postcss
- resolve-url-loader 0.0.1-experiment-postcss || 3.0.0-alpha.1 - 4.0.0
- Depends on vulnerable versions of postcss
- node_modules/resolve-url-loader
- serialize-javascript <6.0.2
- Severity: moderate
- Cross-site Scripting (XSS) in serialize-javascript - https://github.com/advisories/GHSA-76p7-773f-r4q5
- fix available via `npm audit fix --force`
- Will install [email protected], which is a breaking change
- node_modules/rollup-plugin-terser/node_modules/serialize-javascript
- rollup-plugin-terser 3.0.0 || >=4.0.4
- Depends on vulnerable versions of serialize-javascript
- node_modules/rollup-plugin-terser
- workbox-build 5.0.0-alpha.0 - 7.0.0
- Depends on vulnerable versions of rollup-plugin-terser
- node_modules/workbox-build
- workbox-webpack-plugin 5.0.0-alpha.0 - 7.0.0
- Depends on vulnerable versions of workbox-build
- node_modules/workbox-webpack-plugin
- 12 vulnerabilities (6 moderate, 6 high)
- To address all issues (including breaking changes), run:
- npm audit fix --force
Advertisement
Add Comment
Please, Sign In to add comment