Update dependency @google-cloud/dialogflow to v5 #50
Security Report
You have successfully remediated 7 vulnerabilities, but introduced 9 new vulnerabilities in this branch.
❌ New vulnerabilities:
CVE | Severity | CVSS Score | Vulnerable Library | Suggested Fix | Issue |
---|---|---|---|---|---|
CVE-2023-36665Path to dependency file: /firebase/JavaScript/functions/package.json Path to vulnerable library: /firebase/JavaScript/functions/package.json Dependency Hierarchy: -> dialogflow-5.9.0.tgz (Root Library) -> google-gax-3.6.1.tgz -> ❌ protobufjs-7.2.4.tgz (Vulnerable Library) |
Critical | 9.8 | protobufjs-7.2.4.tgz | Upgrade to version: protobufjs - 6.11.4,7.2.5 | None |
CVE-2021-44906Path to dependency file: /firebase/JavaScript/functions/package.json Path to vulnerable library: /firebase/JavaScript/functions/package.json Dependency Hierarchy: -> dialogflow-5.9.0.tgz (Root Library) -> google-gax-3.6.1.tgz -> protobufjs-cli-1.1.1.tgz -> ❌ minimist-1.2.5.tgz (Vulnerable Library) |
Critical | 9.8 | minimist-1.2.5.tgz | Upgrade to version: minimist - 0.2.4,1.2.6 | None |
CVE-2024-45590Path to dependency file: /natural-language/JavaScript/sms-sentiment/package.json Path to vulnerable library: /natural-language/JavaScript/sms-sentiment/node_modules/body-parser/package.json,/cloud-translation/JavaScript/sms-translation/node_modules/body-parser/package.json Dependency Hierarchy: -> ❌ body-parser-1.18.3.tgz (Vulnerable Library) |
High | 7.5 | body-parser-1.18.3.tgz | Upgrade to version: body-parser - 1.20.3 | None |
CVE-2024-45590Path to dependency file: /firebase/JavaScript/functions/package.json Path to vulnerable library: /firebase/JavaScript/functions/package.json Dependency Hierarchy: -> firebase-functions-3.6.1.tgz (Root Library) -> express-4.17.1.tgz -> ❌ body-parser-1.19.0.tgz (Vulnerable Library) |
High | 7.5 | body-parser-1.19.0.tgz | Upgrade to version: body-parser - 1.20.3 | #24 |
CVE-2023-26115Path to dependency file: /firebase/JavaScript/functions/package.json Path to vulnerable library: /firebase/JavaScript/functions/package.json Dependency Hierarchy: -> dialogflow-5.9.0.tgz (Root Library) -> google-gax-3.6.1.tgz -> protobufjs-cli-1.1.1.tgz -> escodegen-1.14.3.tgz -> optionator-0.8.3.tgz -> ❌ word-wrap-1.2.3.tgz (Vulnerable Library) |
Medium | 5.3 | word-wrap-1.2.3.tgz | Upgrade to version: word-wrap - 1.2.4 | None |
CVE-2024-43800Path to dependency file: /natural-language/JavaScript/sms-sentiment/package.json Path to vulnerable library: /natural-language/JavaScript/sms-sentiment/node_modules/serve-static/package.json,/cloud-translation/JavaScript/sms-translation/node_modules/serve-static/package.json Dependency Hierarchy: -> express-4.16.4.tgz (Root Library) -> ❌ serve-static-1.13.2.tgz (Vulnerable Library) |
Medium | 5.0 | serve-static-1.13.2.tgz | Upgrade to version: serve-static - 1.16.0,2.1.0 | #42 |
CVE-2024-43800Path to dependency file: /firebase/JavaScript/functions/package.json Path to vulnerable library: /firebase/JavaScript/functions/package.json Dependency Hierarchy: -> firebase-functions-3.6.1.tgz (Root Library) -> express-4.17.1.tgz -> ❌ serve-static-1.14.1.tgz (Vulnerable Library) |
Medium | 5.0 | serve-static-1.14.1.tgz | Upgrade to version: serve-static - 1.16.0,2.1.0 | #24 |
CVE-2024-43799Path to dependency file: /firebase/JavaScript/functions/package.json Path to vulnerable library: /firebase/JavaScript/functions/package.json Dependency Hierarchy: -> firebase-functions-3.6.1.tgz (Root Library) -> express-4.17.1.tgz -> ❌ send-0.17.1.tgz (Vulnerable Library) |
Medium | 5.0 | send-0.17.1.tgz | Upgrade to version: send - 0.19.0 | #24 |
CVE-2024-43796Path to dependency file: /firebase/JavaScript/functions/package.json Path to vulnerable library: /firebase/JavaScript/functions/package.json Dependency Hierarchy: -> firebase-functions-3.6.1.tgz (Root Library) -> ❌ express-4.17.1.tgz (Vulnerable Library) |
Medium | 5.0 | express-4.17.1.tgz | Upgrade to version: express - 4.20.0,5.0.0 | #24 |
✔️ Remediated vulnerabilities:
CVE | Vulnerable Library |
---|---|
CVE-2024-29041 | express-4.18.2.tgz |
CVE-2024-37890 | ws-5.2.3.tgz |
CVE-2024-28863 | tar-6.1.11.tgz |
CVE-2024-47764 | cookie-0.5.0.tgz |
CVE-2023-36665 | protobufjs-6.11.3.tgz |
CVE-2024-45590 | body-parser-1.20.1.tgz |
CVE-2022-25883 | semver-7.3.8.tgz |
Base branch total remaining vulnerabilities: 67
Base branch commit: null
Total libraries scanned: 594
Scan token: 014c12a5042a46c085307fc6e9a734b7