Skip to content

Conversation

@snyk-bot
Copy link

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • deps/npm/node_modules/tweetnacl/package.json

Vulnerabilities that will be fixed

With an upgrade:
SeverityIssueBreaking ChangeExploit Maturity
high severityPrototype Pollution
SNYK-JS-AJV-584908
YesNo Known Exploit
high severityRegular Expression Denial of Service (ReDoS)
SNYK-JS-ANSIREGEX-1583908
YesProof of Concept
high severityDenial of Service (DoS)
SNYK-JS-ECSTATIC-540354
YesProof of Concept
high severityHeap-based Buffer Overflow
SNYK-JS-ELECTRON-1021884
YesMature
high severityUse After Free
SNYK-JS-ELECTRON-1041745
YesMature
high severityImproper Validation
SNYK-JS-ELECTRON-1047306
YesMature
high severityHeap-based Buffer Overflow
SNYK-JS-ELECTRON-1048693
YesNo Known Exploit
high severityImproper Access Control
SNYK-JS-ELECTRON-1049321
YesNo Known Exploit
high severityImproper Input Validation
SNYK-JS-ELECTRON-1049323
YesNo Known Exploit
high severityUse After Free
SNYK-JS-ELECTRON-1049547
YesNo Known Exploit
high severityUse After Free
SNYK-JS-ELECTRON-1050424
YesNo Known Exploit
medium severityInformation Exposure
SNYK-JS-ELECTRON-1050427
YesNo Known Exploit
high severityInsufficient Validation
SNYK-JS-ELECTRON-1050882
YesMature
critical severityUse After Free
SNYK-JS-ELECTRON-1050999
YesNo Known Exploit
high severityOut-of-bounds Read
SNYK-JS-ELECTRON-1051000
YesNo Known Exploit
medium severityImproper Input Validation
SNYK-JS-ELECTRON-1064555
YesProof of Concept
high severityUse After Free
SNYK-JS-ELECTRON-1064558
YesNo Known Exploit
high severityUse After Free
SNYK-JS-ELECTRON-1064561
YesNo Known Exploit
medium severityInformation Exposure
SNYK-JS-ELECTRON-1065981
YesNo Known Exploit
critical severityUse After Free
SNYK-JS-ELECTRON-1070013
YesNo Known Exploit
high severityInsufficient Validation
SNYK-JS-ELECTRON-1070014
YesNo Known Exploit
medium severityUse After Free
SNYK-JS-ELECTRON-1070015
YesNo Known Exploit
high severityHeap Buffer Overflow
SNYK-JS-ELECTRON-1085647
YesNo Known Exploit
high severityUse After Free
SNYK-JS-ELECTRON-1085705
YesMature
high severityUse After Free
SNYK-JS-ELECTRON-1085994
YesNo Known Exploit
high severityOut-of-Bounds
SNYK-JS-ELECTRON-1085996
YesNo Known Exploit
medium severityInformation Exposure
SNYK-JS-ELECTRON-1085998
YesNo Known Exploit
high severityOut-of-Bounds
SNYK-JS-ELECTRON-1086693
YesNo Known Exploit
medium severityAccess Restriction Bypass
SNYK-JS-ELECTRON-1086694
YesNo Known Exploit
high severityImproper Input Validation
SNYK-JS-ELECTRON-1086695
YesNo Known Exploit
high severityUse After Free
SNYK-JS-ELECTRON-1087442
YesNo Known Exploit
high severityOut-of-bounds Write
SNYK-JS-ELECTRON-1088600
YesMature
high severityInsecure Defaults
SNYK-JS-ELECTRON-1088602
YesNo Known Exploit
high severityUse After Free
SNYK-JS-ELECTRON-1252279
YesMature
high severityUse After Free
SNYK-JS-ELECTRON-1252280
YesNo Known Exploit
high severityUse After Free
SNYK-JS-ELECTRON-1253279
YesNo Known Exploit
high severityUse After Free
SNYK-JS-ELECTRON-1253281
YesNo Known Exploit
critical severityOut-of-bounds
SNYK-JS-ELECTRON-1257943
YesMature
high severityUse After Free
SNYK-JS-ELECTRON-1258207
YesNo Known Exploit
high severityUse After Free
SNYK-JS-ELECTRON-1259349
YesNo Known Exploit
high severityInteger Overflow or Wraparound
SNYK-JS-ELECTRON-1260586
YesNo Known Exploit
high severityOut-of-bounds Read
SNYK-JS-ELECTRON-1261111
YesNo Known Exploit
high severityHeap-based Buffer Overflow
SNYK-JS-ELECTRON-1277203
YesNo Known Exploit
high severityInteger Overflow
SNYK-JS-ELECTRON-1277205
YesNo Known Exploit
medium severityImproper Input Validation
SNYK-JS-ELECTRON-1277526
YesNo Known Exploit
low severityOut Of Bounds Read
SNYK-JS-ELECTRON-1278596
YesNo Known Exploit
high severityHeap-based Buffer Overflow
SNYK-JS-ELECTRON-1296553
YesNo Known Exploit
high severityHeap-based Buffer Overflow
SNYK-JS-ELECTRON-1296555
YesNo Known Exploit
high severityUse After Free
SNYK-JS-ELECTRON-1296557
YesNo Known Exploit
high severityType Confusion
SNYK-JS-ELECTRON-1296559
YesProof of Concept
high severityUse After Free
SNYK-JS-ELECTRON-1296561
YesNo Known Exploit
high severityRace Condition
SNYK-JS-ELECTRON-1296563
YesNo Known Exploit
high severityHeap-based Buffer Overflow
SNYK-JS-ELECTRON-1296565
YesNo Known Exploit
high severityUse After Free
SNYK-JS-ELECTRON-1312313
YesNo Known Exploit
high severityAccess of Resource Using Incompatible Type ('Type Confusion')
SNYK-JS-ELECTRON-1312314
YesMature
high severityUse After Free
SNYK-JS-ELECTRON-1312315
YesNo Known Exploit
high severityUse After Free
SNYK-JS-ELECTRON-1313765
YesMature
medium severityUse After Free
SNYK-JS-ELECTRON-1313767
YesNo Known Exploit
high severityUse After Free
SNYK-JS-ELECTRON-1314896
YesNo Known Exploit
high severityUse After Free
SNYK-JS-ELECTRON-1315151
YesNo Known Exploit
critical severityOut-of-bounds Write
SNYK-JS-ELECTRON-1315668
YesNo Known Exploit
high severityUse After Free
SNYK-JS-ELECTRON-1533614
YesNo Known Exploit
high severityUse After Free
SNYK-JS-ELECTRON-1534881
YesNo Known Exploit
high severityUse After Free
SNYK-JS-ELECTRON-1534882
YesNo Known Exploit
high severityType Confusion
SNYK-JS-ELECTRON-1534883
YesMature
medium severityHeap-based Buffer Overflow
SNYK-JS-ELECTRON-1534884
YesNo Known Exploit
medium severityUse After Free
SNYK-JS-ELECTRON-1536579
YesNo Known Exploit
high severityUse After Free
SNYK-JS-ELECTRON-1536581
YesProof of Concept
high severityUse After Free
SNYK-JS-ELECTRON-1536587
YesNo Known Exploit
medium severityOut-of-Bounds
SNYK-JS-ELECTRON-1585619
YesMature
high severityType Confusion
SNYK-JS-ELECTRON-1586050
YesNo Known Exploit
high severityBuffer Overflow
SNYK-JS-ELECTRON-1656742
YesNo Known Exploit
high severityUse After Free
SNYK-JS-ELECTRON-1656743
YesMature
high severityOut-of-Bounds
SNYK-JS-ELECTRON-1656745
YesNo Known Exploit
high severityAccess Restriction Bypass
SNYK-JS-ELECTRON-1656746
YesNo Known Exploit
medium severityImproper Input Validation
SNYK-JS-ELECTRON-1727344
YesMature
medium severitySandbox Bypass
SNYK-JS-ELECTRON-1731315
YesProof of Concept
high severityUse After Free
SNYK-JS-ELECTRON-174045
YesMature
high severityUse After Free
SNYK-JS-ELECTRON-1910985
YesMature
high severityUse After Free
SNYK-JS-ELECTRON-1910987
YesNo Known Exploit
medium severityExposure of Resource to Wrong Sphere
SNYK-JS-ELECTRON-1910988
YesNo Known Exploit
medium severityImproper Access Control
SNYK-JS-ELECTRON-1910991
YesNo Known Exploit
critical severityType Confusion
SNYK-JS-ELECTRON-1911949
YesProof of Concept
high severityUse After Free
SNYK-JS-ELECTRON-1912074
YesNo Known Exploit
high severityHeap-based Buffer Overflow
SNYK-JS-ELECTRON-1912084
YesNo Known Exploit
medium severityInformation Exposure
SNYK-JS-ELECTRON-1912085
YesMature
high severityArbitrary Code Execution
SNYK-JS-ELECTRON-483050
YesNo Known Exploit
high severityArbitrary Code Execution
SNYK-JS-ELECTRON-483056
YesNo Known Exploit
high severityUse After Free
SNYK-JS-ELECTRON-564272
YesNo Known Exploit
high severityHeap Overflow
SNYK-JS-ELECTRON-565051
YesNo Known Exploit
high severityOut-of-bounds Read
SNYK-JS-ELECTRON-565052
YesNo Known Exploit
high severityImproper Access Control
SNYK-JS-ELECTRON-565362
YesNo Known Exploit
high severityUse After Free
SNYK-JS-ELECTRON-565366
YesNo Known Exploit
high severityUse After Free
SNYK-JS-ELECTRON-565368
YesNo Known Exploit
high severityUse After Free
SNYK-JS-ELECTRON-565441
YesNo Known Exploit
medium severityBuffer Underflow
SNYK-JS-ELECTRON-565488
YesNo Known Exploit
high severityUse After Free
SNYK-JS-ELECTRON-565490
YesNo Known Exploit
high severityUse After Free
SNYK-JS-ELECTRON-565494
YesNo Known Exploit
high severityUse After Free
SNYK-JS-ELECTRON-565571
YesNo Known Exploit
high severityUse After Free
SNYK-JS-ELECTRON-565705
YesNo Known Exploit
medium severityUse After Free
SNYK-JS-ELECTRON-565709
YesNo Known Exploit
high severitySite Isolation Bypass
SNYK-JS-ELECTRON-565713
YesNo Known Exploit
high severityUse After Free
SNYK-JS-ELECTRON-570624
YesNo Known Exploit
high severityType Confusion
SNYK-JS-ELECTRON-570833
YesProof of Concept
medium severityArbitrary File Read
SNYK-JS-ELECTRON-575393
YesNo Known Exploit
high severityPrivilege Escalation
SNYK-JS-ELECTRON-575394
YesNo Known Exploit
high severityPrivilege Escalation
SNYK-JS-ELECTRON-575395
YesNo Known Exploit
high severityPrivilege Escalation
SNYK-JS-ELECTRON-575396
YesNo Known Exploit
low severityPrototype Pollution
SNYK-JS-MINIMIST-2429795
YesProof of Concept
medium severityPrototype Pollution
SNYK-JS-MINIMIST-559764
YesProof of Concept
high severityPrototype Pollution
SNYK-JS-PLIST-2405644
YesProof of Concept
high severityImproper Privilege Management
SNYK-JS-SHELLJS-2332187
YesProof of Concept
medium severityRegular Expression Denial of Service (ReDoS)
SNYK-JS-UGLIFYJS-1727251
YesNo Known Exploit
low severityRegular Expression Denial of Service (ReDoS)
npm:eslint:20180222
YesProof of Concept
Commit messages
Package name: eslint The new version differs by 250 commits.

See the full diff

Package name: tape-run The new version differs by 33 commits.

See the full diff

Package name: uglify-js The new version differs by 250 commits.

See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note:You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Prototype Pollution
🦉 Regular Expression Denial of Service (ReDoS)
🦉 Improper Access Control
🦉 More lessons are available in Snyk Learn

…lities The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-JS-AJV-584908 - https://snyk.io/vuln/SNYK-JS-ANSIREGEX-1583908 - https://snyk.io/vuln/SNYK-JS-ECSTATIC-540354 - https://snyk.io/vuln/SNYK-JS-ELECTRON-1021884 - https://snyk.io/vuln/SNYK-JS-ELECTRON-1041745 - https://snyk.io/vuln/SNYK-JS-ELECTRON-1047306 - https://snyk.io/vuln/SNYK-JS-ELECTRON-1048693 - https://snyk.io/vuln/SNYK-JS-ELECTRON-1049321 - https://snyk.io/vuln/SNYK-JS-ELECTRON-1049323 - https://snyk.io/vuln/SNYK-JS-ELECTRON-1049547 - https://snyk.io/vuln/SNYK-JS-ELECTRON-1050424 - https://snyk.io/vuln/SNYK-JS-ELECTRON-1050427 - https://snyk.io/vuln/SNYK-JS-ELECTRON-1050882 - https://snyk.io/vuln/SNYK-JS-ELECTRON-1050999 - https://snyk.io/vuln/SNYK-JS-ELECTRON-1051000 - https://snyk.io/vuln/SNYK-JS-ELECTRON-1064555 - https://snyk.io/vuln/SNYK-JS-ELECTRON-1064558 - https://snyk.io/vuln/SNYK-JS-ELECTRON-1064561 - https://snyk.io/vuln/SNYK-JS-ELECTRON-1065981 - https://snyk.io/vuln/SNYK-JS-ELECTRON-1070013 - https://snyk.io/vuln/SNYK-JS-ELECTRON-1070014 - https://snyk.io/vuln/SNYK-JS-ELECTRON-1070015 - https://snyk.io/vuln/SNYK-JS-ELECTRON-1085647 - https://snyk.io/vuln/SNYK-JS-ELECTRON-1085705 - https://snyk.io/vuln/SNYK-JS-ELECTRON-1085994 - https://snyk.io/vuln/SNYK-JS-ELECTRON-1085996 - https://snyk.io/vuln/SNYK-JS-ELECTRON-1085998 - https://snyk.io/vuln/SNYK-JS-ELECTRON-1086693 - https://snyk.io/vuln/SNYK-JS-ELECTRON-1086694 - https://snyk.io/vuln/SNYK-JS-ELECTRON-1086695 - https://snyk.io/vuln/SNYK-JS-ELECTRON-1087442 - https://snyk.io/vuln/SNYK-JS-ELECTRON-1088600 - https://snyk.io/vuln/SNYK-JS-ELECTRON-1088602 - https://snyk.io/vuln/SNYK-JS-ELECTRON-1252279 - https://snyk.io/vuln/SNYK-JS-ELECTRON-1252280 - https://snyk.io/vuln/SNYK-JS-ELECTRON-1253279 - https://snyk.io/vuln/SNYK-JS-ELECTRON-1253281 - https://snyk.io/vuln/SNYK-JS-ELECTRON-1257943 - https://snyk.io/vuln/SNYK-JS-ELECTRON-1258207 - https://snyk.io/vuln/SNYK-JS-ELECTRON-1259349 - https://snyk.io/vuln/SNYK-JS-ELECTRON-1260586 - https://snyk.io/vuln/SNYK-JS-ELECTRON-1261111 - https://snyk.io/vuln/SNYK-JS-ELECTRON-1277203 - https://snyk.io/vuln/SNYK-JS-ELECTRON-1277205 - https://snyk.io/vuln/SNYK-JS-ELECTRON-1277526 - https://snyk.io/vuln/SNYK-JS-ELECTRON-1278596 - https://snyk.io/vuln/SNYK-JS-ELECTRON-1296553 - https://snyk.io/vuln/SNYK-JS-ELECTRON-1296555 - https://snyk.io/vuln/SNYK-JS-ELECTRON-1296557 - https://snyk.io/vuln/SNYK-JS-ELECTRON-1296559 - https://snyk.io/vuln/SNYK-JS-ELECTRON-1296561 - https://snyk.io/vuln/SNYK-JS-ELECTRON-1296563 - https://snyk.io/vuln/SNYK-JS-ELECTRON-1296565 - https://snyk.io/vuln/SNYK-JS-ELECTRON-1312313 - https://snyk.io/vuln/SNYK-JS-ELECTRON-1312314 - https://snyk.io/vuln/SNYK-JS-ELECTRON-1312315 - https://snyk.io/vuln/SNYK-JS-ELECTRON-1313765 - https://snyk.io/vuln/SNYK-JS-ELECTRON-1313767 - https://snyk.io/vuln/SNYK-JS-ELECTRON-1314896 - https://snyk.io/vuln/SNYK-JS-ELECTRON-1315151 - https://snyk.io/vuln/SNYK-JS-ELECTRON-1315668 - https://snyk.io/vuln/SNYK-JS-ELECTRON-1533614 - https://snyk.io/vuln/SNYK-JS-ELECTRON-1534881 - https://snyk.io/vuln/SNYK-JS-ELECTRON-1534882 - https://snyk.io/vuln/SNYK-JS-ELECTRON-1534883 - https://snyk.io/vuln/SNYK-JS-ELECTRON-1534884 - https://snyk.io/vuln/SNYK-JS-ELECTRON-1536579 - https://snyk.io/vuln/SNYK-JS-ELECTRON-1536581 - https://snyk.io/vuln/SNYK-JS-ELECTRON-1536587 - https://snyk.io/vuln/SNYK-JS-ELECTRON-1585619 - https://snyk.io/vuln/SNYK-JS-ELECTRON-1586050 - https://snyk.io/vuln/SNYK-JS-ELECTRON-1656742 - https://snyk.io/vuln/SNYK-JS-ELECTRON-1656743 - https://snyk.io/vuln/SNYK-JS-ELECTRON-1656745 - https://snyk.io/vuln/SNYK-JS-ELECTRON-1656746 - https://snyk.io/vuln/SNYK-JS-ELECTRON-1727344 - https://snyk.io/vuln/SNYK-JS-ELECTRON-1731315 - https://snyk.io/vuln/SNYK-JS-ELECTRON-174045 - https://snyk.io/vuln/SNYK-JS-ELECTRON-1910985 - https://snyk.io/vuln/SNYK-JS-ELECTRON-1910987 - https://snyk.io/vuln/SNYK-JS-ELECTRON-1910988 - https://snyk.io/vuln/SNYK-JS-ELECTRON-1910991 - https://snyk.io/vuln/SNYK-JS-ELECTRON-1911949 - https://snyk.io/vuln/SNYK-JS-ELECTRON-1912074 - https://snyk.io/vuln/SNYK-JS-ELECTRON-1912084 - https://snyk.io/vuln/SNYK-JS-ELECTRON-1912085 - https://snyk.io/vuln/SNYK-JS-ELECTRON-483050 - https://snyk.io/vuln/SNYK-JS-ELECTRON-483056 - https://snyk.io/vuln/SNYK-JS-ELECTRON-564272 - https://snyk.io/vuln/SNYK-JS-ELECTRON-565051 - https://snyk.io/vuln/SNYK-JS-ELECTRON-565052 - https://snyk.io/vuln/SNYK-JS-ELECTRON-565362 - https://snyk.io/vuln/SNYK-JS-ELECTRON-565366 - https://snyk.io/vuln/SNYK-JS-ELECTRON-565368 - https://snyk.io/vuln/SNYK-JS-ELECTRON-565441 - https://snyk.io/vuln/SNYK-JS-ELECTRON-565488 - https://snyk.io/vuln/SNYK-JS-ELECTRON-565490 - https://snyk.io/vuln/SNYK-JS-ELECTRON-565494 - https://snyk.io/vuln/SNYK-JS-ELECTRON-565571 - https://snyk.io/vuln/SNYK-JS-ELECTRON-565705 - https://snyk.io/vuln/SNYK-JS-ELECTRON-565709 - https://snyk.io/vuln/SNYK-JS-ELECTRON-565713 - https://snyk.io/vuln/SNYK-JS-ELECTRON-570624 - https://snyk.io/vuln/SNYK-JS-ELECTRON-570833 - https://snyk.io/vuln/SNYK-JS-ELECTRON-575393 - https://snyk.io/vuln/SNYK-JS-ELECTRON-575394 - https://snyk.io/vuln/SNYK-JS-ELECTRON-575395 - https://snyk.io/vuln/SNYK-JS-ELECTRON-575396 - https://snyk.io/vuln/SNYK-JS-MINIMIST-2429795 - https://snyk.io/vuln/SNYK-JS-MINIMIST-559764 - https://snyk.io/vuln/SNYK-JS-PLIST-2405644 - https://snyk.io/vuln/SNYK-JS-SHELLJS-2332187 - https://snyk.io/vuln/SNYK-JS-UGLIFYJS-1727251 - https://snyk.io/vuln/npm:eslint:20180222
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

2 participants

@snyk-bot