Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Snyk] Fix for 1 vulnerabilities #781

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

adamlaska
Copy link
Owner

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to fix one or more vulnerable packages in the `yarn` dependencies of this project.

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • standalone-packages/vscode-extensions/out/extensions/juliettepretot.lucy-vscode-2.6.3/package.json
    • standalone-packages/vscode-extensions/out/extensions/juliettepretot.lucy-vscode-2.6.3/.snyk

Note for zero-installs users

If you are using the Yarn feature zero-installs that was introduced in Yarn V2, note that this PR does not update the .yarn/cache/ directory meaning this code cannot be pulled and immediately developed on as one would expect for a zero-install project - you will need to run yarn to update the contents of the ./yarn/cache directory.
If you are not using zero-install you can ignore this as your flow should likely be unchanged.

⚠️ Warning
Failed to update the yarn.lock, please update manually before merging.

Vulnerabilities that will be fixed

With a Snyk patch:
Severity Priority Score (*) Issue Exploit Maturity
high severity 731/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 8.2
Prototype Pollution
SNYK-JS-LODASH-567746
Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Prototype Pollution

…tot.lucy-vscode-2.6.3/package.json & standalone-packages/vscode-extensions/out/extensions/juliettepretot.lucy-vscode-2.6.3/.snyk to reduce vulnerabilities

The following vulnerabilities are fixed with a Snyk patch:
- https://snyk.io/vuln/SNYK-JS-LODASH-567746
Copy link

google-cla bot commented May 16, 2024

Thanks for your pull request! It looks like this may be your first contribution to a Google open source project. Before we can look at your pull request, you'll need to sign a Contributor License Agreement (CLA).

View this failed invocation of the CLA check for more information.

For the most up to date status, view the checks section at the bottom of the pull request.

Copy link

New and removed dependencies detected. Learn more about Socket for GitHub ↗︎

Package New capabilities Transitives Size Publisher
npm/@absinthe/socket@0.2.1 Transitive: eval +3 4.17 MB mgtitimoli
npm/@apollo/react-common@3.1.3 environment +1 1.9 MB apollo-bot
npm/@apollo/react-hooks@3.1.3 environment 0 370 kB apollo-bot
npm/@babel/cli@7.8.4 Transitive: filesystem, shell +4 203 kB nicolo-ribaudo
npm/@babel/code-frame@7.10.3 None 0 7.72 kB jlhwung
npm/@babel/compat-data@7.24.4 None 0 65.2 kB nicolo-ribaudo
npm/@babel/core@7.24.5 environment, filesystem, unsafe +14 6.75 MB nicolo-ribaudo
npm/@babel/generator@7.10.3 None 0 121 kB jlhwung
npm/@babel/helper-annotate-as-pure@7.8.3 None 0 3.44 kB nicolo-ribaudo
npm/@babel/helper-builder-binary-assignment-operator-visitor@7.8.3 None +1 9.07 kB nicolo-ribaudo
npm/@babel/helper-builder-react-jsx-experimental@7.9.5 None 0 47.2 kB nicolo-ribaudo
npm/@babel/helper-builder-react-jsx@7.9.0 None 0 9.49 kB nicolo-ribaudo
npm/@babel/helper-compilation-targets@7.23.6 None +1 67.7 kB nicolo-ribaudo
npm/@babel/helper-create-class-features-plugin@7.9.5 None 0 39.6 kB nicolo-ribaudo
npm/@babel/helper-create-regexp-features-plugin@7.8.8 None +1 10.2 kB nicolo-ribaudo
npm/@babel/helper-define-map@7.8.3 None 0 6.65 kB nicolo-ribaudo
npm/@babel/helper-function-name@7.10.3 None 0 7.22 kB jlhwung
npm/@babel/helper-get-function-arity@7.10.3 None 0 3.33 kB jlhwung
npm/@babel/helper-hoist-variables@7.22.5 None 0 7.03 kB nicolo-ribaudo
npm/@babel/helper-member-expression-to-functions@7.8.3 None 0 5.98 kB nicolo-ribaudo
npm/@babel/helper-module-imports@7.8.3 None 0 17.9 kB nicolo-ribaudo
npm/@babel/helper-module-transforms@7.24.5 None +1 222 kB nicolo-ribaudo
npm/@babel/helper-optimise-call-expression@7.8.3 None 0 3.48 kB nicolo-ribaudo
npm/@babel/helper-plugin-utils@7.10.4 None 0 4.05 kB jlhwung
npm/@babel/helper-remap-async-to-generator@7.8.3 None +1 11.2 kB nicolo-ribaudo
npm/@babel/helper-replace-supers@7.8.6 None 0 8.38 kB nicolo-ribaudo
npm/@babel/helper-simple-access@7.24.5 None 0 14.1 kB nicolo-ribaudo
npm/@babel/helper-split-export-declaration@7.10.1 None 0 5.06 kB nicolo-ribaudo
npm/@babel/helper-validator-identifier@7.10.4 None 0 18.6 kB jlhwung
npm/@babel/helper-validator-option@7.23.5 None 0 11.7 kB nicolo-ribaudo
npm/@babel/helpers@7.24.5 None 0 650 kB nicolo-ribaudo
npm/@babel/highlight@7.10.3 None 0 5.55 kB jlhwung
npm/@babel/parser@7.11.5 None 0 1.48 MB jlhwung
npm/@babel/plugin-proposal-async-generator-functions@7.8.3 None 0 7.43 kB nicolo-ribaudo
npm/@babel/plugin-proposal-class-properties@7.8.3 None 0 3.14 kB nicolo-ribaudo
npm/@babel/plugin-proposal-decorators@7.8.3 None +1 15.9 kB nicolo-ribaudo
npm/@babel/plugin-proposal-dynamic-import@7.8.3 None 0 3.74 kB nicolo-ribaudo
npm/@babel/plugin-proposal-json-strings@7.8.3 None 0 3.36 kB nicolo-ribaudo
npm/@babel/plugin-proposal-nullish-coalescing-operator@7.8.3 None 0 3.92 kB nicolo-ribaudo
npm/@babel/plugin-proposal-numeric-separator@7.8.3 None 0 3.16 kB nicolo-ribaudo
npm/@babel/plugin-proposal-object-rest-spread@7.9.6 None 0 18.2 kB nicolo-ribaudo
npm/@babel/plugin-proposal-optional-catch-binding@7.8.3 None 0 3.16 kB nicolo-ribaudo
npm/@babel/plugin-proposal-optional-chaining@7.9.0 None 0 6.53 kB nicolo-ribaudo
npm/@babel/plugin-proposal-unicode-property-regex@7.8.8 None 0 3.36 kB nicolo-ribaudo
npm/@babel/plugin-syntax-async-generators@7.8.4 None 0 2.52 kB nicolo-ribaudo
npm/@babel/plugin-syntax-bigint@7.8.3 None 0 2.42 kB nicolo-ribaudo
npm/@babel/plugin-syntax-class-properties@7.8.3 None 0 2.61 kB nicolo-ribaudo
npm/@babel/plugin-syntax-dynamic-import@7.8.3 None 0 2.47 kB nicolo-ribaudo
npm/@babel/plugin-syntax-flow@7.8.3 None 0 2.93 kB nicolo-ribaudo
npm/@babel/plugin-syntax-import-meta@7.10.4 None 0 2.56 kB jlhwung
npm/@babel/plugin-syntax-json-strings@7.8.3 None 0 2.58 kB nicolo-ribaudo
npm/@babel/plugin-syntax-jsx@7.8.3 None 0 2.54 kB nicolo-ribaudo
npm/@babel/plugin-syntax-logical-assignment-operators@7.8.3 None 0 2.69 kB nicolo-ribaudo
npm/@babel/plugin-syntax-nullish-coalescing-operator@7.8.3 None 0 2.63 kB nicolo-ribaudo
npm/@babel/plugin-syntax-numeric-separator@7.8.3 None 0 2.7 kB nicolo-ribaudo
npm/@babel/plugin-syntax-object-rest-spread@7.8.3 None 0 2.53 kB nicolo-ribaudo
npm/@babel/plugin-syntax-optional-catch-binding@7.8.3 None 0 2.57 kB nicolo-ribaudo
npm/@babel/plugin-syntax-optional-chaining@7.8.3 None 0 2.52 kB nicolo-ribaudo
npm/@babel/plugin-syntax-top-level-await@7.8.3 None 0 2.57 kB nicolo-ribaudo
npm/@babel/plugin-syntax-typescript@7.8.3 None 0 3.06 kB nicolo-ribaudo
npm/@babel/plugin-transform-arrow-functions@7.8.3 None 0 2.86 kB nicolo-ribaudo
npm/@babel/plugin-transform-async-to-generator@7.8.3 None 0 3.89 kB nicolo-ribaudo
npm/@babel/plugin-transform-block-scoped-functions@7.8.3 None 0 3.53 kB nicolo-ribaudo
npm/@babel/plugin-transform-block-scoping@7.8.3 None 0 25.6 kB nicolo-ribaudo
npm/@babel/plugin-transform-classes@7.9.5 None 0 25.4 kB nicolo-ribaudo
npm/@babel/plugin-transform-computed-properties@7.8.3 None 0 7.51 kB nicolo-ribaudo
npm/@babel/plugin-transform-destructuring@7.9.5 None 0 19.5 kB nicolo-ribaudo
npm/@babel/plugin-transform-dotall-regex@7.8.3 None 0 2.98 kB nicolo-ribaudo
npm/@babel/plugin-transform-duplicate-keys@7.8.3 None 0 4.07 kB nicolo-ribaudo
npm/@babel/plugin-transform-exponentiation-operator@7.8.3 None 0 3.25 kB nicolo-ribaudo
npm/@babel/plugin-transform-flow-strip-types@7.9.0 None 0 6.5 kB nicolo-ribaudo
npm/@babel/plugin-transform-for-of@7.9.0 None 0 13.4 kB nicolo-ribaudo
npm/@babel/plugin-transform-function-name@7.8.3 None 0 3.34 kB nicolo-ribaudo
npm/@babel/plugin-transform-literals@7.8.3 None 0 2.86 kB nicolo-ribaudo
npm/@babel/plugin-transform-member-expression-literals@7.8.3 None 0 3.08 kB nicolo-ribaudo
npm/@babel/plugin-transform-modules-amd@7.9.6 None 0 7.17 kB nicolo-ribaudo
npm/@babel/plugin-transform-modules-commonjs@7.9.6 None 0 9.06 kB nicolo-ribaudo
npm/@babel/plugin-transform-modules-systemjs@7.9.6 None 0 18.6 kB nicolo-ribaudo
npm/@babel/plugin-transform-modules-umd@7.9.0 None 0 8.75 kB nicolo-ribaudo
npm/@babel/plugin-transform-named-capturing-groups-regex@7.8.3 None 0 3.18 kB nicolo-ribaudo
npm/@babel/plugin-transform-new-target@7.8.3 None 0 4.25 kB nicolo-ribaudo
npm/@babel/plugin-transform-object-super@7.8.3 None 0 3.61 kB nicolo-ribaudo
npm/@babel/plugin-transform-parameters@7.9.5 None 0 17.7 kB nicolo-ribaudo
npm/@babel/plugin-transform-property-literals@7.8.3 None 0 2.96 kB nicolo-ribaudo
npm/@babel/plugin-transform-react-constant-elements@7.9.0 None 0 4.77 kB nicolo-ribaudo
npm/@babel/plugin-transform-react-display-name@7.8.3 None 0 5.11 kB nicolo-ribaudo
npm/@babel/plugin-transform-react-jsx-development@7.9.0 None 0 3.75 kB nicolo-ribaudo
npm/@babel/plugin-transform-react-jsx-self@7.9.0 None 0 3 kB nicolo-ribaudo
npm/@babel/plugin-transform-react-jsx-source@7.9.0 None 0 4.59 kB nicolo-ribaudo
npm/@babel/plugin-transform-react-jsx@7.9.4 None 0 8.29 kB nicolo-ribaudo
npm/@babel/plugin-transform-regenerator@7.8.7 None 0 2.72 kB nicolo-ribaudo
npm/@babel/plugin-transform-reserved-words@7.8.3 None 0 2.77 kB nicolo-ribaudo
npm/@babel/plugin-transform-runtime@7.9.0 None 0 39 kB nicolo-ribaudo
npm/@babel/plugin-transform-shorthand-properties@7.8.3 None 0 3.16 kB nicolo-ribaudo
npm/@babel/plugin-transform-spread@7.8.3 None 0 6.36 kB nicolo-ribaudo
npm/@babel/plugin-transform-sticky-regex@7.8.3 None +1 6.36 kB nicolo-ribaudo
npm/@babel/plugin-transform-template-literals@7.8.3 None 0 6 kB nicolo-ribaudo
npm/@babel/plugin-transform-typeof-symbol@7.8.4 None 0 4.74 kB nicolo-ribaudo
npm/@babel/plugin-transform-typescript@7.9.4 None 0 23.9 kB nicolo-ribaudo
npm/@babel/plugin-transform-unicode-regex@7.8.3 None 0 2.77 kB nicolo-ribaudo
npm/@babel/polyfill@7.4.4 None 0 442 kB nicolo-ribaudo
npm/@babel/preset-env@7.9.0 environment +1 127 kB nicolo-ribaudo
npm/@babel/preset-flow@7.0.0 None 0 3.05 kB hzoo
npm/@babel/preset-react@7.9.1 None 0 4.5 kB nicolo-ribaudo
npm/@babel/preset-typescript@7.9.0 None 0 3.73 kB nicolo-ribaudo
npm/@babel/register@7.13.16 environment, filesystem, unsafe +2 20.2 kB nicolo-ribaudo
npm/@babel/runtime-corejs3@7.19.4 None 0 287 kB nicolo-ribaudo
npm/@babel/runtime@7.11.2 None 0 99.8 kB jlhwung
npm/@babel/template@7.10.3 None 0 24.2 kB jlhwung
npm/@babel/traverse@7.10.1 environment 0 158 kB nicolo-ribaudo
npm/@babel/types@7.11.5 environment 0 726 kB jlhwung
npm/@bcoe/v8-coverage@0.2.3 None 0 277 kB bcoe
npm/@chromaui/localtunnel@2.0.1 environment, filesystem, network +12 473 kB tmeasday
npm/@cnakazawa/watch@1.0.3 filesystem 0 27.3 kB cpojer
npm/@code-hike/classer@0.0.0-e48fa74 None 0 13 kB pomber
npm/@codemirror/autocomplete@0.19.15 None 0 144 kB marijn
npm/@codemirror/closebrackets@0.19.2 None 0 27.7 kB marijn
npm/@codemirror/commands@0.19.8 None 0 124 kB marijn
npm/@codemirror/comment@0.19.1 None 0 24.1 kB marijn
npm/@codemirror/gutter@0.19.9 None 0 45.9 kB marijn
npm/@codemirror/highlight@0.19.8 None 0 111 kB marijn
npm/@codemirror/history@0.19.2 None 0 39.3 kB marijn
npm/@codemirror/lang-css@0.19.3 None 0 33.5 kB marijn
npm/@codemirror/lang-html@0.19.4 None 0 56.2 kB marijn
npm/@codemirror/lang-javascript@0.19.7 None +2 117 kB marijn
npm/@codemirror/language@0.19.10 None 0 118 kB marijn
npm/@codemirror/matchbrackets@0.19.4 None 0 19.9 kB marijn
npm/@codemirror/rangeset@0.19.9 None 0 76 kB marijn
npm/@codemirror/state@0.19.9 None 0 224 kB marijn
npm/@codemirror/text@0.19.6 None 0 63.2 kB marijn
npm/@codemirror/tooltip@0.19.16 None 0 59.6 kB marijn
npm/@codemirror/view@0.19.48 None 0 709 kB marijn
npm/@codesandbox/ab@1.0.5 network 0 14.6 kB danilowoz
npm/@codesandbox/sandpack-client@1.12.1 network 0 98.6 MB danilowoz
npm/@codesandbox/sandpack-react@1.17.0 environment, eval +2 887 kB danilowoz
npm/@codesandbox/sandpack-themes@1.17.0 None 0 211 kB danilowoz
npm/@csstools/convert-colors@1.4.0 None 0 63.2 kB jonathantneal
npm/@csstools/normalize.css@10.1.0 None 0 33 kB jonathantneal
npm/@divyenduz/graphql-language-service-interface@1.2.7 None +3 1.74 MB divyenduz
npm/@divyenduz/graphql-language-service-server@1.2.3 filesystem, network Transitive: environment +5 2.45 MB divyenduz
npm/@divyenduz/graphql-language-service-utils@1.2.7 None +1 24 kB divyenduz
npm/@divyenduz/ts-graphql-plugin@0.1.0 None 0 11.9 kB divyenduz
npm/@emmetio/abbreviation@0.6.5 None +2 57.4 kB emmetio
npm/@emmetio/codemirror-plugin@0.3.5 None +19 1.32 MB emmetio
npm/@emmetio/output-renderer@0.1.2 None +2 63.5 kB emmetio
npm/@emmetio/stream-reader@2.2.0 None 0 7.83 kB emmetio
npm/@emotion/cache@10.0.27 environment +4 206 kB emotion-release-bot
npm/@emotion/core@10.0.35 environment +5 330 kB emotion-release-bot
npm/@emotion/css@10.0.27 environment +1 167 kB emotion-release-bot
npm/@emotion/hash@0.6.6 None 0 8.23 kB mitchellhamilton
npm/@emotion/is-prop-valid@0.8.6 environment 0 38.2 kB emotion-release-bot
npm/@emotion/memoize@0.6.6 None 0 3.06 kB mitchellhamilton
npm/@emotion/serialize@0.9.1 environment +1 53.3 kB mitchellhamilton
npm/@emotion/styled-base@10.0.27 environment 0 112 kB emotion-release-bot
npm/@emotion/styled@10.0.27 environment 0 77.6 kB emotion-release-bot
npm/@emotion/stylis@0.7.1 None 0 90.6 kB mitchellhamilton
npm/@emotion/unitless@0.6.7 None 0 7.34 kB mitchellhamilton
npm/@eslint/eslintrc@0.1.3 filesystem, unsafe +7 1.49 MB eslintbot
npm/@essentials/request-timeout@1.0.1 None 0 5.19 kB jaredlunde
npm/@gatsbyjs/relay-compiler@2.0.0-printer-fix.2 environment, filesystem, shell +19 3.33 MB freiksenet
npm/@graphql-cli/common@4.0.0 Transitive: environment, filesystem, network, unsafe +28 1.25 MB ardatan
npm/@graphql-cli/init@4.0.0 filesystem Transitive: environment, network, shell +23 2.86 MB ardatan
npm/@graphql-codegen/cli@1.15.4 environment, filesystem, shell Transitive: eval, network, unsafe +42 4.49 MB dotansimha
npm/@graphql-codegen/fragment-matcher@1.15.4 Transitive: eval +1 162 kB dotansimha
npm/@graphql-codegen/typescript-graphql-files-modules@1.15.4 Transitive: eval +1 147 kB dotansimha
npm/@graphql-codegen/typescript-operations@1.15.4 Transitive: eval +3 955 kB dotansimha
npm/@graphql-codegen/typescript@1.15.4 Transitive: eval +3 1 MB dotansimha
npm/@graphql-toolkit/common@0.10.7 environment +1 1.63 MB dotansimha
npm/@graphql-toolkit/schema-merging@0.10.7 None 0 270 kB dotansimha
npm/@graphql-tools/merge@6.0.10 None +1 483 kB ardatan
npm/@graphql-tools/url-loader@6.0.10 network +3 953 kB ardatan
npm/@graphql-tools/utils@6.0.10 environment 0 862 kB ardatan
npm/@hapi/address@2.0.0 None 0 74.9 kB hueniverse
npm/@hapi/bourne@1.3.2 None 0 6 kB hueniverse
npm/@hapi/hoek@8.2.1 None 0 45.8 kB hueniverse
npm/@hapi/joi@15.1.1 network +1 203 kB hueniverse
npm/@iarna/toml@2.2.3 eval 0 94.5 kB iarna
npm/@icons/material@0.2.4 None 0 6.33 MB case
npm/@istanbuljs/load-nyc-config@1.0.0 environment, filesystem 0 9.14 kB coreyfarrell
npm/@istanbuljs/schema@0.1.2 None 0 15.2 kB coreyfarrell
npm/@jest/console@24.9.0 None 0 24.2 kB scotthovestadt
npm/@jest/core@24.9.0 filesystem, unsafe 0 180 kB scotthovestadt
npm/@jest/environment@24.9.0 None 0 14.5 kB scotthovestadt
npm/@jest/fake-timers@24.9.0 None 0 21.3 kB scotthovestadt
npm/@jest/globals@25.5.2 Transitive: environment, filesystem +16 3.01 MB simenb
npm/@jest/reporters@24.9.0 environment, filesystem Transitive: shell +3 178 kB scotthovestadt
npm/@jest/source-map@24.9.0 None +1 12.6 kB scotthovestadt
npm/@jest/test-result@24.9.0 None 0 23.1 kB scotthovestadt
npm/@jest/test-sequencer@24.9.0 filesystem 0 8.17 kB scotthovestadt
npm/@jest/transform@24.9.0 unsafe +1 48.5 kB scotthovestadt
npm/@jest/types@24.9.0 None 0 47 kB scotthovestadt
npm/@jimp/bmp@0.6.4 None 0 261 kB alisowski
npm/@jimp/core@0.22.12 environment, filesystem, network +4 550 kB alisowski
npm/@jimp/custom@0.22.12 None 0 35.1 kB alisowski
npm/@jimp/gif@0.6.4 None 0 7.54 kB alisowski
npm/@jimp/jpeg@0.6.4 None 0 160 kB alisowski
npm/@jimp/plugin-blit@0.6.4 None 0 731 kB alisowski
npm/@jimp/plugin-blur@0.6.4 None 0 72.9 kB alisowski
npm/@jimp/plugin-color@0.6.4 None 0 408 kB alisowski
npm/@jimp/plugin-contain@0.6.4 None 0 27.1 kB alisowski
npm/@jimp/plugin-cover@0.6.4 None 0 22.5 kB alisowski
npm/@jimp/plugin-crop@0.22.12 None 0 89.1 kB alisowski
npm/@jimp/plugin-displace@0.6.4 None 0 13.6 kB alisowski
npm/@jimp/plugin-dither@0.6.4 None 0 10.9 kB alisowski
npm/@jimp/plugin-flip@0.6.4 None 0 13 kB alisowski
npm/@jimp/plugin-gaussian@0.6.4 None 0 21.4 kB alisowski
npm/@jimp/plugin-invert@0.6.4 None 0 7.99 kB alisowski
npm/@jimp/plugin-mask@0.6.4 None 0 22.3 kB alisowski
npm/@jimp/plugin-normalize@0.6.4 None 0 21 kB alisowski
npm/@jimp/plugin-print@0.6.4 environment 0 908 kB alisowski
npm/@jimp/plugin-resize@0.22.12 None 0 227 kB alisowski
npm/@jimp/plugin-rotate@0.22.12 None 0 75.6 kB alisowski
npm/@jimp/plugin-scale@0.22.12 None 0 19.6 kB alisowski
npm/@jimp/plugins@0.6.4 None +4 394 kB alisowski
npm/@jimp/png@0.6.4 None 0 261 kB alisowski
npm/@jimp/tiff@0.6.4 None 0 1.46 MB alisowski
npm/@jimp/types@0.6.4 None 0 5.18 kB alisowski

🚮 Removed packages: npm/caniuse-lite@1.0.30001618, npm/es6-promise@4.2.8, npm/js-tokens@4.0.0

View full report↗︎

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants