mause / launtel Goto Github PK
View Code? Open in Web Editor NEWHome Page: https://launtel.vc.mause.me/openapi.yaml
Home Page: https://launtel.vc.mause.me/openapi.yaml
Path to dependency file: /package.json
Path to vulnerable library: /node_modules/got/package.json
Found in HEAD commit: 0503d7c9c4cecacc2458f017cfc0afaea6e811be
CVE | Severity | CVSS | Dependency | Type | Fixed in | Remediation Available |
---|---|---|---|---|---|---|
CVE-2022-33987 | Medium | 5.3 | got-11.8.2.tgz | Transitive | N/A | ❌ |
Human-friendly and powerful HTTP request library for Node.js
Library home page: https://registry.npmjs.org/got/-/got-11.8.2.tgz
Path to dependency file: /package.json
Path to vulnerable library: /node_modules/got/package.json
Dependency Hierarchy:
Found in HEAD commit: 0503d7c9c4cecacc2458f017cfc0afaea6e811be
Found in base branch: main
The got package before 12.1.0 (also fixed in 11.8.5) for Node.js allows a redirect to a UNIX socket.
Publish Date: 2022-06-18
URL: CVE-2022-33987
Base Score Metrics:
Type: Upgrade version
Origin: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-33987
Release Date: 2022-06-18
Fix Resolution: got - 11.8.5,12.1.0
Step up your Open Source Security Game with Mend here
Path to dependency file: /package.json
Path to vulnerable library: /node_modules/minimist/package.json
Found in HEAD commit: 0503d7c9c4cecacc2458f017cfc0afaea6e811be
CVE | Severity | CVSS | Dependency | Type | Fixed in | Remediation Available |
---|---|---|---|---|---|---|
CVE-2022-31129 | High | 7.5 | moment-2.29.1.tgz | Transitive | N/A | ❌ |
CVE-2022-24785 | High | 7.5 | moment-2.29.1.tgz | Transitive | N/A | ❌ |
CVE-2021-44906 | Medium | 5.0 | minimist-1.2.5.tgz | Transitive | N/A | ❌ |
Parse, validate, manipulate, and display dates
Library home page: https://registry.npmjs.org/moment/-/moment-2.29.1.tgz
Path to dependency file: /package.json
Path to vulnerable library: /node_modules/moment/package.json
Dependency Hierarchy:
Found in HEAD commit: 0503d7c9c4cecacc2458f017cfc0afaea6e811be
Found in base branch: main
moment is a JavaScript date library for parsing, validating, manipulating, and formatting dates. Affected versions of moment were found to use an inefficient parsing algorithm. Specifically using string-to-date parsing in moment (more specifically rfc2822 parsing, which is tried by default) has quadratic (N^2) complexity on specific inputs. Users may notice a noticeable slowdown is observed with inputs above 10k characters. Users who pass user-provided strings without sanity length checks to moment constructor are vulnerable to (Re)DoS attacks. The problem is patched in 2.29.4, the patch can be applied to all affected versions with minimal tweaking. Users are advised to upgrade. Users unable to upgrade should consider limiting date lengths accepted from user input.
Publish Date: 2022-07-06
URL: CVE-2022-31129
Base Score Metrics:
Type: Upgrade version
Origin: GHSA-wc69-rhjr-hc9g
Release Date: 2022-07-06
Fix Resolution: moment - 2.29.4
Step up your Open Source Security Game with Mend here
Parse, validate, manipulate, and display dates
Library home page: https://registry.npmjs.org/moment/-/moment-2.29.1.tgz
Path to dependency file: /package.json
Path to vulnerable library: /node_modules/moment/package.json
Dependency Hierarchy:
Found in HEAD commit: 0503d7c9c4cecacc2458f017cfc0afaea6e811be
Found in base branch: main
Moment.js is a JavaScript date library for parsing, validating, manipulating, and formatting dates. A path traversal vulnerability impacts npm (server) users of Moment.js between versions 1.0.1 and 2.29.1, especially if a user-provided locale string is directly used to switch moment locale. This problem is patched in 2.29.2, and the patch can be applied to all affected versions. As a workaround, sanitize the user-provided locale name before passing it to Moment.js.
Publish Date: 2022-04-04
URL: CVE-2022-24785
Base Score Metrics:
Type: Upgrade version
Origin: GHSA-8hfj-j24r-96c4
Release Date: 2022-04-04
Fix Resolution: moment - 2.29.2,Moment.js - 2.29.2
Step up your Open Source Security Game with Mend here
parse argument options
Library home page: https://registry.npmjs.org/minimist/-/minimist-1.2.5.tgz
Path to dependency file: /package.json
Path to vulnerable library: /node_modules/minimist/package.json
Dependency Hierarchy:
Found in HEAD commit: 0503d7c9c4cecacc2458f017cfc0afaea6e811be
Found in base branch: main
Minimist <=1.2.5 is vulnerable to Prototype Pollution via file index.js, function setKey() (lines 69-95).
Publish Date: 2022-03-17
URL: CVE-2021-44906
Base Score Metrics:
Type: Upgrade version
Release Date: 2022-03-17
Fix Resolution: minimist - 1.2.6
Step up your Open Source Security Game with Mend here
Path to dependency file: /package.json
Path to vulnerable library: /node_modules/async/package.json
Found in HEAD commit: 0503d7c9c4cecacc2458f017cfc0afaea6e811be
CVE | Severity | CVSS | Dependency | Type | Fixed in | Remediation Available |
---|---|---|---|---|---|---|
CVE-2021-43138 | High | 7.8 | async-1.5.2.tgz | Transitive | 1.1.10 | ❌ |
Higher-order functions and common patterns for asynchronous code
Library home page: https://registry.npmjs.org/async/-/async-1.5.2.tgz
Path to dependency file: /package.json
Path to vulnerable library: /node_modules/async/package.json
Dependency Hierarchy:
Found in HEAD commit: 0503d7c9c4cecacc2458f017cfc0afaea6e811be
Found in base branch: main
In Async before 2.6.4 and 3.x before 3.2.2, a malicious user can obtain privileges via the mapValues() method, aka lib/internal/iterator.js createObjectIterator prototype pollution.
Publish Date: 2022-04-06
URL: CVE-2021-43138
Base Score Metrics:
Type: Upgrade version
Origin: https://nvd.nist.gov/vuln/detail/CVE-2021-43138
Release Date: 2022-04-06
Fix Resolution (async): 2.6.4
Direct dependency fix Resolution (vercel-jwt-auth): 1.1.10
Step up your Open Source Security Game with Mend here
This issue lists Renovate updates and detected dependencies. Read the Dependency Dashboard docs to learn more.
These updates are currently rate-limited. Click on a checkbox below to force their creation now.
These updates have all been created already. Click a checkbox below to force a retry/rebase of any.
@types/jest
, jest
, ts-jest
).github/workflows/typecheck.yml
actions/checkout v2
actions/setup-node v2.5.1
andoshin11/typescript-error-reporter-action v1.0.2
actions/upload-artifact v2
.github/workflows/validate-openapi.yaml
actions/checkout v2
char0n/swagger-editor-validate v1.3.0
package.json
@js-joda/core ^5.2.0
@logtail/bunyan ^0.1.10
@logtail/node ^0.1.10
@types/bunyan ^1.8.8
@vercel/node ^2.0.0
axios ^0.22.0
axios-cookiejar-support ^1.0.1
bunyan ^1.8.15
class-validator ^0.13.2
joi ^17.6.0
lodash ^4.17.21
tabletojson ^2.0.7
tough-cookie ^4.0.0
typescript ^4.5.4
vercel-jwt-auth ^1.1.9
@types/jest ^27.4.0
@types/jsonwebtoken ^8.5.8
@types/lodash ^4.14.178
@types/moxios ^0.4.12
@types/node ^16
@types/test-listen ^1.1.0
@types/tough-cookie ^4.0.1
dotenv ^16.0.0
jest ^27.2.4
moxios ^0.4.0
test-listen ^1.1.0
ts-jest ^27
vercel-node-server ^2.2.1
vercel-openapi ^0.1.13
Path to dependency file: /package.json
Path to vulnerable library: /node_modules/node-fetch/package.json
Found in HEAD commit: 0503d7c9c4cecacc2458f017cfc0afaea6e811be
CVE | Severity | CVSS | Dependency | Type | Fixed in | Remediation Available |
---|---|---|---|---|---|---|
CVE-2022-0235 | Medium | 6.1 | node-fetch-2.6.1.tgz | Transitive | N/A | ❌ |
A light-weight module that brings window.fetch to node.js
Library home page: https://registry.npmjs.org/node-fetch/-/node-fetch-2.6.1.tgz
Path to dependency file: /package.json
Path to vulnerable library: /node_modules/node-fetch/package.json
Dependency Hierarchy:
Found in HEAD commit: 0503d7c9c4cecacc2458f017cfc0afaea6e811be
Found in base branch: main
node-fetch is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor
Publish Date: 2022-01-16
URL: CVE-2022-0235
Base Score Metrics:
Type: Upgrade version
Origin: GHSA-r683-j2x4-v87g
Release Date: 2022-01-16
Fix Resolution: node-fetch - 2.6.7,3.1.1
Step up your Open Source Security Game with Mend here
A declarative, efficient, and flexible JavaScript library for building user interfaces.
🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.
TypeScript is a superset of JavaScript that compiles to clean JavaScript output.
An Open Source Machine Learning Framework for Everyone
The Web framework for perfectionists with deadlines.
A PHP framework for web artisans
Bring data to life with SVG, Canvas and HTML. 📊📈🎉
JavaScript (JS) is a lightweight interpreted programming language with first-class functions.
Some thing interesting about web. New door for the world.
A server is a program made to process requests and deliver data to clients.
Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.
Some thing interesting about visualization, use data art
Some thing interesting about game, make everyone happy.
We are working to build community through open source technology. NB: members must have two-factor auth.
Open source projects and samples from Microsoft.
Google ❤️ Open Source for everyone.
Alibaba Open Source for everyone
Data-Driven Documents codes.
China tencent open source team.