Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Fix vulnerabilities #433

Merged
merged 3 commits into from
Sep 16, 2024
Merged

Fix vulnerabilities #433

merged 3 commits into from
Sep 16, 2024

Conversation

amrosu
Copy link
Collaborator

@amrosu amrosu commented Sep 16, 2024

Corrections vulnérabilités node :

  • itowns : mise à jour paquets micromatch (4.0.5 -> 4.0.8) & express (4.19.2 -> 4.21.0) => les 7 vulnérabilités (5 modérées et 2 majeures) ont été toutes corrigées
  • api : mise à jour paquet body-parser (1.20.1 -> 1.20.3) => correction d'une vulnérabilité majeure ; mise à jour paquet express (4.20.0 -> 4.21.0) => correction d'une vulnérabilité modérée ; il reste 6 vulnérabilités majeures qui nécessitent des mise à jour plus en profondeur - pas possible de les corriger "à la main" pour le moment, car elles ne sont pas encore disponibles / utilisables.

@coveralls
Copy link

coveralls commented Sep 16, 2024

Pull Request Test Coverage Report for Build 10885412822

Details

  • 0 of 0 changed or added relevant lines in 0 files are covered.
  • No unchanged relevant lines lost coverage.
  • Overall coverage remained the same at 95.838%

Totals Coverage Status
Change from base Build 10880065940: 0.0%
Covered Lines: 5957
Relevant Lines: 6168

💛 - Coveralls

@amrosu amrosu added the wip Travail en cours (ne pas merger) label Sep 16, 2024
@amrosu amrosu added dependencies Pull requests that update a dependency file and removed wip Travail en cours (ne pas merger) labels Sep 16, 2024
@amrosu amrosu merged commit 89a4b19 into master Sep 16, 2024
4 checks passed
@amrosu amrosu deleted the fix_vulnerabilities branch September 16, 2024 14:10
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies Pull requests that update a dependency file
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants