Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Bump json5 and @vue/cli-service in /browser/flagr-ui #23

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

dependabot[bot]
Copy link

@dependabot dependabot bot commented on behalf of github Jan 6, 2023

Bumps json5 to 2.2.3 and updates ancestor dependencies json5, json5 and @vue/cli-service. These dependencies need to be updated together.

Updates json5 from 2.1.2 to 2.2.3

Release notes

Sourced from json5's releases.

v2.2.3

v2.2.2

  • Fix: Properties with the name __proto__ are added to objects and arrays. (#199) This also fixes a prototype pollution vulnerability reported by Jonathan Gregson! (#295).

v2.2.1

v2.2.0

  • New: Accurate and documented TypeScript declarations are now included. There is no need to install @types/json5. (#236, #244)

v2.1.3 [code, diff]

  • Fix: An out of memory bug when parsing numbers has been fixed. (#228, #229)
Changelog

Sourced from json5's changelog.

v2.2.3 [code, diff]

v2.2.2 [code, diff]

  • Fix: Properties with the name __proto__ are added to objects and arrays. (#199) This also fixes a prototype pollution vulnerability reported by Jonathan Gregson! (#295).

v2.2.1 [code, diff]

v2.2.0 [code, diff]

  • New: Accurate and documented TypeScript declarations are now included. There is no need to install @types/json5. (#236, #244)

v2.1.3 [code, diff]

  • Fix: An out of memory bug when parsing numbers has been fixed. (#228, #229)
Commits
  • c3a7524 2.2.3
  • 94fd06d docs: update CHANGELOG for v2.2.3
  • 3b8cebf docs(security): use GitHub security advisories
  • f0fd9e1 docs: publish a security policy
  • 6a91a05 docs(template): bug -> bug report
  • 14f8cb1 2.2.2
  • 10cc7ca docs: update CHANGELOG for v2.2.2
  • 7774c10 fix: add proto to objects and arrays
  • edde30a Readme: slight tweak to intro
  • 97286f8 Improve example in readme
  • Additional commits viewable in compare view

Updates json5 from 1.0.1 to 2.2.3

Release notes

Sourced from json5's releases.

v2.2.3

v2.2.2

  • Fix: Properties with the name __proto__ are added to objects and arrays. (#199) This also fixes a prototype pollution vulnerability reported by Jonathan Gregson! (#295).

v2.2.1

v2.2.0

  • New: Accurate and documented TypeScript declarations are now included. There is no need to install @types/json5. (#236, #244)

v2.1.3 [code, diff]

  • Fix: An out of memory bug when parsing numbers has been fixed. (#228, #229)
Changelog

Sourced from json5's changelog.

v2.2.3 [code, diff]

v2.2.2 [code, diff]

  • Fix: Properties with the name __proto__ are added to objects and arrays. (#199) This also fixes a prototype pollution vulnerability reported by Jonathan Gregson! (#295).

v2.2.1 [code, diff]

v2.2.0 [code, diff]

  • New: Accurate and documented TypeScript declarations are now included. There is no need to install @types/json5. (#236, #244)

v2.1.3 [code, diff]

  • Fix: An out of memory bug when parsing numbers has been fixed. (#228, #229)
Commits
  • c3a7524 2.2.3
  • 94fd06d docs: update CHANGELOG for v2.2.3
  • 3b8cebf docs(security): use GitHub security advisories
  • f0fd9e1 docs: publish a security policy
  • 6a91a05 docs(template): bug -> bug report
  • 14f8cb1 2.2.2
  • 10cc7ca docs: update CHANGELOG for v2.2.2
  • 7774c10 fix: add proto to objects and arrays
  • edde30a Readme: slight tweak to intro
  • 97286f8 Improve example in readme
  • Additional commits viewable in compare view

Updates @vue/cli-service from 4.2.3 to 5.0.8

Release notes

Sourced from @​vue/cli-service's releases.

v5.0.8

🐛 Bug Fix

v5.0.7

  • @vue/cli-service
  • @vue/cli-ui
    • #7210 chore: upgrade to apollo-server-express 3.x

Committers: 2

v5.0.6

Fix compatibility with the upcoming Vue 2.7 (currently in alpha) and Vue Loader 15.10 (currently in beta).

In Vue 2.7, vue-template-compiler is no longer a required peer dependency. Rather, there's a new export under the main package as vue/compiler-sfc.

v5.0.5

🐛 Bug Fix

  • @vue/cli
    • #7167 fix(upgrade): prevent changing the structure of package.json file during upgrade (@​blzsaa)
  • @vue/cli-service
  • @vue/cli-plugin-e2e-cypress
    • [697bb44] fix: should correctly resolve cypress bin path for Cypress 10 (Note that the project is still created with Cypress 9 by default, but you can upgrade to Cypress 10 on your own now)

Committers: 3

v5.0.4

🐛 Bug Fix

  • @vue/cli-service
  • @vue/cli-shared-utils, @vue/cli-ui
    • 75826d6 fix: replace node-ipc with @achrinza/node-ipc to further secure the dependency chain

Committers: 1

v5.0.3

... (truncated)

Changelog

Sourced from @​vue/cli-service's changelog.

5.0.7 (2022-07-05)

  • @vue/cli-service
  • @vue/cli-ui
    • #7210 chore: upgrade to apollo-server-express 3.x

Committers: 2

5.0.6 (2022-06-16)

Fix compatibility with the upcoming Vue 2.7 (currently in alpha) and Vue Loader 15.10 (currently in beta).

In Vue 2.7, vue-template-compiler is no longer a required peer dependency. Rather, there's a new export under the main package as vue/compiler-sfc.

5.0.5 (2022-06-16)

🐛 Bug Fix

  • @vue/cli
    • #7167 feat(upgrade): prevent changing the structure of package.json file during upgrade (@​blzsaa)
  • @vue/cli-service

Committers: 3

5.0.4 (2022-03-22)

🐛 Bug Fix

  • @vue/cli-service
  • @vue/cli-shared-utils, @vue/cli-ui
    • 75826d6 fix: replace node-ipc with @achrinza/node-ipc to further secure the dependency chain

Committers: 1

... (truncated)

Commits
  • b154dbd v5.0.8
  • 0260e4d fix: add devServer.server.type to useHttps judgement (#7222)
  • 4a0655f v5.0.7
  • beffe8a fix: allow disabling progress plugin via devServer.client.progress
  • 558dea2 fix: support devServer.server option, avoid deprecation warning
  • bddd64d fix: optimize the judgment on whether HTTPS has been set in options (#7202)
  • ef08a08 v5.0.6
  • fcf27e3 fixup! fix: compatibility with Vue 2.7
  • a648958 fix: compatibility with Vue 2.7
  • 98c66c9 v5.0.5
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
  • @dependabot use these labels will set the current labels as the default for future PRs for this repo and language
  • @dependabot use these reviewers will set the current reviewers as the default for future PRs for this repo and language
  • @dependabot use these assignees will set the current assignees as the default for future PRs for this repo and language
  • @dependabot use this milestone will set the current milestone as the default for future PRs for this repo and language

You can disable automated security fix PRs for this repo from the Security Alerts page.

Bumps [json5](https://github.com/json5/json5) to 2.2.3 and updates ancestor dependencies [json5](https://github.com/json5/json5), [json5](https://github.com/json5/json5) and [@vue/cli-service](https://github.com/vuejs/vue-cli/tree/HEAD/packages/@vue/cli-service). These dependencies need to be updated together.


Updates `json5` from 2.1.2 to 2.2.3
- [Release notes](https://github.com/json5/json5/releases)
- [Changelog](https://github.com/json5/json5/blob/main/CHANGELOG.md)
- [Commits](json5/json5@v2.1.2...v2.2.3)

Updates `json5` from 1.0.1 to 2.2.3
- [Release notes](https://github.com/json5/json5/releases)
- [Changelog](https://github.com/json5/json5/blob/main/CHANGELOG.md)
- [Commits](json5/json5@v2.1.2...v2.2.3)

Updates `@vue/cli-service` from 4.2.3 to 5.0.8
- [Release notes](https://github.com/vuejs/vue-cli/releases)
- [Changelog](https://github.com/vuejs/vue-cli/blob/dev/CHANGELOG.md)
- [Commits](https://github.com/vuejs/vue-cli/commits/v5.0.8/packages/@vue/cli-service)

---
updated-dependencies:
- dependency-name: json5
  dependency-type: indirect
- dependency-name: json5
  dependency-type: indirect
- dependency-name: "@vue/cli-service"
  dependency-type: direct:development
...

Signed-off-by: dependabot[bot] <[email protected]>
@dependabot dependabot bot added dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code labels Jan 6, 2023
@ImagineBuildBot
Copy link

Scan submitted to Checkmarx

@ImagineBuildBot
Copy link

Logo
Checkmarx SAST - Scan Summary & Details

Cx-SAST Summary

Total of 503 vulnerabilities
High 58 High
Medium 445 Medium
Low 0 Low
Info 0 Info

Checkmarx Scan Summary

Severity Count
High 58
Medium 445
Low 0
Informational 0

Violation Summary

High 14 High
Medium 205 Medium

View more details on Checkmarx UI

Cx-SAST Details

Lines Severity Category File Link
545 Medium Use_of_Cryptographically_Weak_PRNG vendor/go.opencensus.io/trace/trace.go Checkmarx
25 26 Medium Use_of_Cryptographically_Weak_PRNG vendor/gopkg.in/DataDog/dd-trace-go.v1/ddtrace/tracer/rand.go Checkmarx
325 Medium Use_of_Cryptographically_Weak_PRNG vendor/github.com/DataDog/datadog-go/statsd/statsd.go Checkmarx
30 Medium Use_of_Cryptographically_Weak_PRNG vendor/google.golang.org/grpc/internal/grpcrand/grpcrand.go Checkmarx
569 Medium Use_of_Cryptographically_Weak_PRNG vendor/github.com/getsentry/raven-go/client.go Checkmarx
28 Medium Use_of_Cryptographically_Weak_PRNG pkg/handler/export.go Checkmarx
91 Medium Use_of_Cryptographically_Weak_PRNG vendor/github.com/Shopify/sarama/partitioner.go Checkmarx
26 27 Medium Use_of_Cryptographically_Weak_PRNG vendor/cloud.google.com/go/internal/testutil/rand.go Checkmarx
452 Medium Use_of_Cryptographically_Weak_PRNG vendor/golang.org/x/net/http2/transport.go Checkmarx
29 Medium Use_of_Cryptographically_Weak_PRNG vendor/github.com/aws/aws-sdk-go/internal/sdkrand/locked_source.go Checkmarx
134 Medium Use_of_Cryptographically_Weak_PRNG vendor/github.com/googleapis/gax-go/v2/call_option.go Checkmarx
148 Medium Use_of_Cryptographically_Weak_PRNG pkg/handler/eval.go Checkmarx
172 514 Medium Use_of_Cryptographically_Weak_PRNG vendor/github.com/rcrowley/go-metrics/sample.go Checkmarx
64 Medium Use_of_Cryptographically_Weak_PRNG vendor/github.com/jpillora/backoff/backoff.go Checkmarx
145 Medium Use_of_Cryptographically_Weak_PRNG vendor/github.com/Shopify/sarama/client.go Checkmarx
14 Medium Use_of_Cryptographically_Weak_PRNG vendor/github.com/newrelic/go-agent/internal/rand.go Checkmarx
478 Medium SSRF vendor/github.com/newrelic/go-agent/internal/attributes.go Checkmarx
58 61 86 159 162 336 424 427 Medium Race_Condition_Concurrent_Instances vendor/golang.org/x/net/trace/events.go Checkmarx
202 222 233 258 366 370 374 377 389 534 544 555 558 961 964 Medium Race_Condition_Concurrent_Instances vendor/golang.org/x/net/trace/trace.go Checkmarx
72 Medium Privacy_Violation vendor/github.com/davecgh/go-spew/spew/config.go Checkmarx
430 Medium Privacy_Violation vendor/golang.org/x/net/http2/server.go Checkmarx
166 171 Medium Path_Traversal vendor/github.com/lib/pq/conn.go Checkmarx
193 Medium Path_Traversal vendor/golang.org/x/oauth2/google/sdk.go Checkmarx
55 91 112 Medium Path_Traversal vendor/cloud.google.com/go/internal/testutil/context.go Checkmarx
80 144 Medium Path_Traversal vendor/golang.org/x/oauth2/google/default.go Checkmarx
64 Medium Path_Traversal vendor/github.com/rcrowley/go-metrics/opentsdb.go Checkmarx
436 Medium Path_Traversal vendor/golang.org/x/net/http2/transport.go Checkmarx
33 Medium Path_Traversal vendor/github.com/lib/pq/url.go Checkmarx
60 Medium Path_Traversal vendor/github.com/rcrowley/go-metrics/graphite.go Checkmarx
35 39 Medium Path_Traversal vendor/github.com/aws/aws-sdk-go/internal/shareddefaults/shared_config.go Checkmarx
36 Medium Missing_HSTS_Header pkg/config/middleware_test.go Checkmarx
430 Medium Insecure_Credential_Storage_Mechanism vendor/golang.org/x/net/http2/server.go Checkmarx
696 723 Medium Denial_Of_Service_Resource_Exhaustion vendor/github.com/Shopify/sarama/broker.go Checkmarx
145 Medium Denial_Of_Service_Resource_Exhaustion vendor/google.golang.org/appengine/urlfetch/urlfetch.go Checkmarx
105 Medium Denial_Of_Service_Resource_Exhaustion vendor/golang.org/x/net/trace/events.go Checkmarx
342 356 371 413 Medium Denial_Of_Service_Resource_Exhaustion vendor/github.com/go-openapi/spec/expander.go Checkmarx
183 204 Medium Denial_Of_Service_Resource_Exhaustion vendor/github.com/Shopify/sarama/message.go Checkmarx
292 Medium Denial_Of_Service_Resource_Exhaustion vendor/golang.org/x/net/trace/trace.go Checkmarx
20 Medium Denial_Of_Service_Resource_Exhaustion vendor/golang.org/x/net/http2/gotrack.go Checkmarx
144 Medium Denial_Of_Service_Resource_Exhaustion vendor/golang.org/x/oauth2/google/default.go Checkmarx
48 Medium Denial_Of_Service_Resource_Exhaustion vendor/github.com/prometheus/procfs/mdstat.go Checkmarx
85 88 106 109 116 121 Medium Denial_Of_Service_Resource_Exhaustion vendor/google.golang.org/appengine/internal/identity_vm.go Checkmarx
167 Medium Denial_Of_Service_Resource_Exhaustion vendor/github.com/prometheus/procfs/ipvs.go Checkmarx
182 193 Medium Denial_Of_Service_Resource_Exhaustion vendor/golang.org/x/oauth2/google/sdk.go Checkmarx
32 Medium Denial_Of_Service_Resource_Exhaustion vendor/github.com/prometheus/procfs/nfs/parse_nfs.go Checkmarx
46 Medium Denial_Of_Service_Resource_Exhaustion vendor/google.golang.org/api/transport/http/internal/propagation/http.go Checkmarx
25 50 Medium Denial_Of_Service_Resource_Exhaustion vendor/github.com/go-openapi/runtime/middleware/negotiate.go Checkmarx
49 51 Medium Denial_Of_Service_Resource_Exhaustion vendor/github.com/go-openapi/swag/path.go Checkmarx
284 337 347 Medium Denial_Of_Service_Resource_Exhaustion vendor/github.com/go-openapi/runtime/middleware/context.go Checkmarx
113 123 135 Medium Denial_Of_Service_Resource_Exhaustion vendor/github.com/prometheus/procfs/proc_stat.go Checkmarx
346 470 471 498 Medium Denial_Of_Service_Resource_Exhaustion pkg/config/middleware.go Checkmarx
93 111 117 Medium Denial_Of_Service_Resource_Exhaustion pkg/handler/eval_cache_fetcher.go Checkmarx
59 Medium Denial_Of_Service_Resource_Exhaustion vendor/google.golang.org/appengine/internal/metadata.go Checkmarx
19 20 21 22 25 28 31 Medium Denial_Of_Service_Resource_Exhaustion vendor/github.com/getsentry/raven-go/http.go Checkmarx
76 158 159 160 161 Medium Denial_Of_Service_Resource_Exhaustion vendor/go.opencensus.io/plugin/ochttp/trace.go Checkmarx
114 Medium Denial_Of_Service_Resource_Exhaustion vendor/golang.org/x/oauth2/transport.go Checkmarx
93 94 167 Medium Denial_Of_Service_Resource_Exhaustion vendor/github.com/prometheus/procfs/stat.go Checkmarx
134 Medium Denial_Of_Service_Resource_Exhaustion vendor/github.com/lib/pq/ssl.go Checkmarx
207 Medium Denial_Of_Service_Resource_Exhaustion vendor/github.com/aws/aws-sdk-go/aws/session/env_config.go Checkmarx
153 Medium Denial_Of_Service_Resource_Exhaustion vendor/github.com/jessevdk/go-flags/parser.go Checkmarx
38 Medium Denial_Of_Service_Resource_Exhaustion vendor/google.golang.org/api/internal/creds.go Checkmarx
319 Medium Denial_Of_Service_Resource_Exhaustion vendor/github.com/aws/aws-sdk-go/aws/signer/v4/v4.go Checkmarx
146 157 215 224 Medium Denial_Of_Service_Resource_Exhaustion vendor/github.com/go-openapi/runtime/middleware/parameter.go Checkmarx
18 Medium Denial_Of_Service_Resource_Exhaustion vendor/github.com/lib/pq/user_posix.go Checkmarx
51 54 Medium Denial_Of_Service_Resource_Exhaustion vendor/github.com/prometheus/procfs/diskstats.go Checkmarx
55 Medium Denial_Of_Service_Resource_Exhaustion vendor/github.com/newrelic/go-agent/internal/sysinfo/docker.go Checkmarx
47 Medium Denial_Of_Service_Resource_Exhaustion pkg/handler/export.go Checkmarx
32 Medium Denial_Of_Service_Resource_Exhaustion vendor/github.com/prometheus/procfs/nfs/parse_nfsd.go Checkmarx
64 Medium Denial_Of_Service_Resource_Exhaustion vendor/github.com/prometheus/procfs/xfs/parse.go Checkmarx
409 Medium Denial_Of_Service_Resource_Exhaustion vendor/github.com/aws/aws-sdk-go/aws/session/session.go Checkmarx
436 980 1368 1370 1396 1524 1534 2514 Medium Denial_Of_Service_Resource_Exhaustion vendor/golang.org/x/net/http2/transport.go Checkmarx
363 Medium Denial_Of_Service_Resource_Exhaustion vendor/github.com/getsentry/raven-go/client.go Checkmarx
117 Medium Denial_Of_Service_Resource_Exhaustion vendor/github.com/go-openapi/jsonreference/reference.go Checkmarx
28 Medium Denial_Of_Service_Resource_Exhaustion pkg/handler/subject.go Checkmarx
108 Medium Denial_Of_Service_Resource_Exhaustion vendor/github.com/aws/aws-sdk-go/aws/session/shared_config.go Checkmarx
69 74 285 Medium Denial_Of_Service_Resource_Exhaustion vendor/github.com/prometheus/client_golang/prometheus/http.go Checkmarx
124 129 Medium Denial_Of_Service_Resource_Exhaustion vendor/github.com/prometheus/client_golang/prometheus/promhttp/http.go Checkmarx
306 Medium Denial_Of_Service_Resource_Exhaustion vendor/github.com/prometheus/client_golang/prometheus/promhttp/instrument_server.go Checkmarx
32 78 Medium Denial_Of_Service_Resource_Exhaustion vendor/github.com/go-openapi/swag/loading.go Checkmarx
58 Medium Denial_Of_Service_Resource_Exhaustion vendor/cloud.google.com/go/pubsub/pubsub.go Checkmarx
153 Medium Denial_Of_Service_Resource_Exhaustion vendor/github.com/PuerkitoBio/purell/purell.go Checkmarx
16 Medium Denial_Of_Service_Resource_Exhaustion vendor/github.com/newrelic/go-agent/internal/cat/path_hash.go Checkmarx
141 Medium Denial_Of_Service_Resource_Exhaustion vendor/github.com/aws/aws-sdk-go/aws/credentials/ec2rolecreds/ec2_role_provider.go Checkmarx
15 Medium Denial_Of_Service_Resource_Exhaustion vendor/github.com/newrelic/go-agent/internal/cross_process_http.go Checkmarx
73 Medium Denial_Of_Service_Resource_Exhaustion swagger_gen/restapi/operations/flag/find_flags_parameters.go Checkmarx
64 Medium Denial_Of_Service_Resource_Exhaustion vendor/github.com/prometheus/procfs/buddyinfo.go Checkmarx
127 Medium Denial_Of_Service_Resource_Exhaustion vendor/google.golang.org/api/transport/http/dial.go Checkmarx
79 Medium Denial_Of_Service_Resource_Exhaustion vendor/github.com/prometheus/procfs/proc_psi.go Checkmarx
15 Medium Denial_Of_Service_Resource_Exhaustion vendor/github.com/newrelic/go-agent/internal/sysinfo/bootid.go Checkmarx
111 602 Medium Denial_Of_Service_Resource_Exhaustion vendor/github.com/aws/aws-sdk-go/aws/request/request.go Checkmarx
17 Medium Denial_Of_Service_Resource_Exhaustion vendor/github.com/newrelic/go-agent/internal/utilization/pcf.go Checkmarx
37 38 39 40 41 42 Medium Denial_Of_Service_Resource_Exhaustion vendor/go.opencensus.io/plugin/ochttp/client_stats.go Checkmarx
17 Medium Denial_Of_Service_Resource_Exhaustion vendor/github.com/aws/aws-sdk-go/aws/request/http_request.go Checkmarx
64 Medium Denial_Of_Service_Resource_Exhaustion vendor/google.golang.org/grpc/internal/binarylog/binarylog.go Checkmarx
267 Medium Denial_Of_Service_Resource_Exhaustion vendor/github.com/rs/cors/cors.go Checkmarx
88 Medium Denial_Of_Service_Resource_Exhaustion vendor/github.com/go-openapi/runtime/middleware/denco/server.go Checkmarx
202 Medium Denial_Of_Service_Resource_Exhaustion vendor/github.com/getsentry/raven-go/stacktrace.go Checkmarx
57 Medium Denial_Of_Service_Resource_Exhaustion vendor/google.golang.org/grpc/internal/transport/handler_server.go Checkmarx
277 Medium Denial_Of_Service_Resource_Exhaustion swagger_gen/restapi/server.go Checkmarx
184 193 Medium Denial_Of_Service_Resource_Exhaustion vendor/github.com/Shopify/sarama/record_batch.go Checkmarx
119 120 126 155 156 Medium Denial_Of_Service_Resource_Exhaustion vendor/github.com/meatballhat/negroni-logrus/middleware.go Checkmarx
29 Medium Denial_Of_Service_Resource_Exhaustion vendor/golang.org/x/sys/cpu/cpu_linux.go Checkmarx
154 Medium Denial_Of_Service_Resource_Exhaustion vendor/cloud.google.com/go/compute/metadata/metadata.go Checkmarx
87 Medium Denial_Of_Service_Resource_Exhaustion pkg/handler/data_recorder_kafka.go Checkmarx
49 53 Medium Denial_Of_Service_Resource_Exhaustion vendor/go.opencensus.io/plugin/ochttp/propagation/b3/b3.go Checkmarx
98 Medium Denial_Of_Service_Resource_Exhaustion vendor/go.opencensus.io/resource/resource.go Checkmarx
122 134 Medium Denial_Of_Service_Resource_Exhaustion vendor/github.com/aws/aws-sdk-go/aws/defaults/defaults.go Checkmarx
155 Medium Denial_Of_Service_Resource_Exhaustion vendor/github.com/go-sql-driver/mysql/infile.go Checkmarx
147 666 Medium Denial_Of_Service_Resource_Exhaustion vendor/google.golang.org/grpc/rpc_util.go Checkmarx
35 39 Medium Denial_Of_Service_Resource_Exhaustion vendor/github.com/aws/aws-sdk-go/internal/shareddefaults/shared_config.go Checkmarx
166 171 Medium Denial_Of_Service_Resource_Exhaustion vendor/github.com/lib/pq/conn.go Checkmarx
240 262 267 298 High Reflected_XSS_All_Clients vendor/github.com/rs/cors/cors.go Checkmarx
74 75 High Reflected_XSS_All_Clients vendor/github.com/urfave/negroni/logger.go Checkmarx
347 High Reflected_XSS_All_Clients vendor/github.com/go-openapi/runtime/middleware/context.go Checkmarx
347 High CGI_XSS vendor/github.com/go-openapi/runtime/middleware/context.go Checkmarx
74 75 High CGI_XSS vendor/github.com/urfave/negroni/logger.go Checkmarx
240 262 267 298 High CGI_XSS vendor/github.com/rs/cors/cors.go Checkmarx

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant