Skip to content

[Snyk] Fix for 4 vulnerabilities#20

Open
CryptoJones wants to merge 1 commit into
masterfrom
snyk-fix-1a897092c75249a448f6f1598fd2679f
Open

[Snyk] Fix for 4 vulnerabilities#20
CryptoJones wants to merge 1 commit into
masterfrom
snyk-fix-1a897092c75249a448f6f1598fd2679f

Conversation

@CryptoJones
Copy link
Copy Markdown
Owner

snyk-top-banner

Snyk has created this PR to fix 4 vulnerabilities in the npm dependencies of this project.

Snyk changed the following file(s):

  • package.json
⚠️ Warning
Failed to update the package-lock.json, please update manually before merging.

Vulnerabilities that will be fixed with an upgrade:

Issue Score
high severity Asymmetric Resource Consumption (Amplification)
SNYK-JS-BODYPARSER-7926860
  696  
medium severity Cross-site Scripting
SNYK-JS-EXPRESS-7926867
  541  
low severity Cross-site Scripting
SNYK-JS-SEND-7926862
  391  
low severity Cross-site Scripting
SNYK-JS-SERVESTATIC-7926865
  391  

Important

  • Check the changes in this PR to ensure they won't cause issues with your project.
  • Max score is 1000. Note that the real score may have changed since the PR was raised.
  • This PR was automatically created by Snyk using the credentials of a real user.

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report
📜 Customise PR templates
🛠 Adjust project settings
📚 Read about Snyk's upgrade logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Cross-site Scripting

@CryptoJones
Copy link
Copy Markdown
Owner Author

CryptoJones commented May 15, 2026

Triage note (#30): Generic "Fix for 4 vulnerabilities" title — no in-title dep info. Created same day as #21 (the express 4.17.1 → 4.20.0 PR that's now closed as obsolete), so the four vulnerabilities here are very likely the same ones already addressed by current master's express 4.21.1.

Leaving open for a quick diff review. If the four CVEs are all express-related and predate 4.21.1, close as obsolete.


Proudly Made in Nebraska. Go Big Red! 🌽 https://xkcd.com/2347/

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants