Skip to content

[Security]: Vite middleware may serve files starting with the same name with the public directory #570

@onissen

Description

@onissen

Link zum Dependbot Alert

https://github.com/ncs-northware/northware/security/dependabot/31

Schweregrad

Low

Betroffenes Package

[email protected]

Abhängigkeiten

northware@ /workspaces/northware
├─┬ @changesets/[email protected] -> ./node_modules/.pnpm/@[email protected]_@[email protected]/node_modules/@changesets/cli
│ └─┬ [email protected] -> ./node_modules/.pnpm/[email protected]/node_modules/package-manager-detector
│   ├─┬ [email protected] -> ./node_modules/.pnpm/[email protected]/node_modules/quansync
│   │ └── [email protected] invalid: "^6.2.2" from node_modules/.pnpm/[email protected]/node_modules/quansync, "^6.0.7" from node_modules/.pnpm/[email protected]/node_modules/strip-literal -> ./node_modules/.pnpm/[email protected]_@[email protected][email protected][email protected][email protected]/node_modules/vite
│   └─┬ [email protected] invalid: "3.1.4" from node_modules/.pnpm/[email protected][email protected]/node_modules/trpc-cli -> ./node_modules/.pnpm/[email protected]_@[email protected]_@[email protected][email protected][email protected][email protected]/node_modules/vitest
│     └── [email protected] deduped -> ./node_modules/.pnpm/[email protected]_@[email protected][email protected][email protected][email protected]/node_modules/vite
├─┬ @commitlint/[email protected] -> ./node_modules/.pnpm/@[email protected]_@[email protected][email protected]/node_modules/@commitlint/cli
│ └─┬ [email protected] -> ./node_modules/.pnpm/[email protected]/node_modules/yargs
│   └─┬ [email protected] invalid: "^2.23.0" from node_modules/.pnpm/[email protected]/node_modules/yargs, "^1.23.1" from node_modules/.pnpm/[email protected]/node_modules/deepmerge, "^2.23.1" from node_modules/.pnpm/[email protected]/node_modules/cliui -> ./node_modules/.pnpm/[email protected]/node_modules/rollup
│     └── [email protected] deduped invalid: "^6.2.2" from node_modules/.pnpm/[email protected]/node_modules/quansync -> ./node_modules/.pnpm/[email protected]_@[email protected][email protected][email protected][email protected]/node_modules/vite
├─┬ [email protected] -> ./node_modules/.pnpm/[email protected]/node_modules/typescript
│ └─┬ [email protected] -> ./node_modules/.pnpm/[email protected]/node_modules/source-map-support
│   └─┬ [email protected] invalid: "^1.15.0" from node_modules/.pnpm/[email protected]/node_modules/source-map-support, "^4.31.0" from node_modules/.pnpm/[email protected]/node_modules/rxjs, "^1.12.0" from node_modules/.pnpm/[email protected]/node_modules/source-map -> ./node_modules/.pnpm/[email protected][email protected]/node_modules/webpack
│     └─┬ [email protected] invalid: "^7.1.2" from node_modules/.pnpm/[email protected][email protected]/node_modules/webpack -> ./node_modules/.pnpm/[email protected][email protected][email protected]_/node_modules/css-loader
│       └─┬ [email protected] invalid: "^6.2.1" from node_modules/.pnpm/[email protected][email protected][email protected]_/node_modules/css-loader -> ./node_modules/.pnpm/[email protected][email protected][email protected][email protected][email protected]_/node_modules/postcss-loader
│         └─┬ [email protected] -> ./node_modules/.pnpm/[email protected]/node_modules/jiti
│           └── [email protected] deduped invalid: "^6.2.2" from node_modules/.pnpm/[email protected]/node_modules/quansync, "^6.0.7" from node_modules/.pnpm/[email protected]/node_modules/strip-literal, "^6.0.7" from node_modules/.pnpm/[email protected]/node_modules/strip-literal, "^6.0.3" from node_modules/.pnpm/[email protected]/node_modules/jiti -> ./node_modules/.pnpm/[email protected]_@[email protected][email protected][email protected][email protected]/node_modules/vite
└─┬ [email protected] -> ./node_modules/.pnpm/[email protected]_@[email protected]_@[email protected][email protected][email protected][email protected][email protected]/node_modules/ultracite
  ├─┬ [email protected] -> ./node_modules/.pnpm/[email protected][email protected]/node_modules/trpc-cli
  │ └─┬ @trpc/[email protected] -> ./node_modules/.pnpm/@[email protected][email protected]/node_modules/@trpc/server
  │   └─┬ [email protected] -> ./node_modules/.pnpm/[email protected]_@[email protected][email protected][email protected][email protected]/node_modules/next
  │     └─┬ [email protected] invalid: "8.6.0" from node_modules/.pnpm/[email protected]_@[email protected][email protected][email protected][email protected]/node_modules/next -> ./node_modules/.pnpm/[email protected]_@[email protected][email protected][email protected]_@[email protected]_a40199458529514178c4bba99236bb07/node_modules/storybook
  │       ├─┬ @storybook/[email protected] -> ./node_modules/.pnpm/@[email protected][email protected][email protected][email protected]/node_modules/@storybook/icons
  │       │ └── [email protected] deduped invalid: "^6.2.2" from node_modules/.pnpm/[email protected]/node_modules/quansync, "^6.0.7" from node_modules/.pnpm/[email protected]/node_modules/strip-literal, "^6.0.7" from node_modules/.pnpm/[email protected]/node_modules/strip-literal, "^6.0.3" from node_modules/.pnpm/[email protected]/node_modules/jiti, "4.2.1" from node_modules/.pnpm/@[email protected][email protected][email protected][email protected]/node_modules/@storybook/icons -> ./node_modules/.pnpm/[email protected]_@[email protected][email protected][email protected][email protected]/node_modules/vite
  │       └─┬ @vitest/[email protected] -> ./node_modules/.pnpm/@[email protected][email protected]_@[email protected][email protected][email protected][email protected]_/node_modules/@vitest/mocker
  │         └─┬ [email protected] invalid: "^5.4.0" from node_modules/.pnpm/@[email protected][email protected]_@[email protected][email protected][email protected][email protected]_/node_modules/@vitest/mocker -> ./node_modules/.pnpm/[email protected]_@[email protected][email protected][email protected][email protected]/node_modules/vite
  │           └─┬ [email protected] -> ./node_modules/.pnpm/[email protected]/node_modules/rollup
  │             └── [email protected] deduped invalid: "^6.2.2" from node_modules/.pnpm/[email protected]/node_modules/quansync, "^6.0.7" from node_modules/.pnpm/[email protected]/node_modules/strip-literal, "^6.0.7" from node_modules/.pnpm/[email protected]/node_modules/strip-literal, "^6.0.3" from node_modules/.pnpm/[email protected]/node_modules/jiti, "4.2.1" from node_modules/.pnpm/@[email protected][email protected][email protected][email protected]/node_modules/@storybook/icons -> ./node_modules/.pnpm/[email protected]_@[email protected][email protected][email protected][email protected]/node_modules/vite
  └─┬ [email protected] -> ./node_modules/.pnpm/[email protected]_@[email protected]_@[email protected][email protected][email protected][email protected]/node_modules/vitest
    ├─┬ @vitest/[email protected] -> ./node_modules/.pnpm/@[email protected][email protected]_@[email protected][email protected][email protected][email protected]_/node_modules/@vitest/mocker
    │ └── [email protected] invalid: "^5.4.0" from node_modules/.pnpm/@[email protected][email protected]_@[email protected][email protected][email protected][email protected]_/node_modules/@vitest/mocker -> ./node_modules/.pnpm/[email protected]_@[email protected][email protected][email protected][email protected]/node_modules/vite
    ├─┬ @vitest/[email protected] -> ./node_modules/.pnpm/@[email protected]/node_modules/@vitest/runner
    │ └─┬ [email protected] -> ./node_modules/.pnpm/[email protected]/node_modules/strip-literal
    │   └── [email protected] deduped invalid: "^6.2.2" from node_modules/.pnpm/[email protected]/node_modules/quansync, "^6.0.7" from node_modules/.pnpm/[email protected]/node_modules/strip-literal, "^6.0.7" from node_modules/.pnpm/[email protected]/node_modules/strip-literal -> ./node_modules/.pnpm/[email protected]_@[email protected][email protected][email protected][email protected]/node_modules/vite
    ├─┬ [email protected] -> ./node_modules/.pnpm/[email protected]/node_modules/strip-literal
    │ └── [email protected] deduped invalid: "^6.2.2" from node_modules/.pnpm/[email protected]/node_modules/quansync, "^6.0.7" from node_modules/.pnpm/[email protected]/node_modules/strip-literal -> ./node_modules/.pnpm/[email protected]_@[email protected][email protected][email protected][email protected]/node_modules/vite
    ├─┬ [email protected] -> ./node_modules/.pnpm/[email protected]_@[email protected][email protected][email protected][email protected]/node_modules/vite-node
    │ └── [email protected] -> ./node_modules/.pnpm/[email protected]_@[email protected][email protected][email protected][email protected]/node_modules/vite
    └─┬ [email protected] -> ./node_modules/.pnpm/[email protected]_@[email protected][email protected][email protected][email protected]/node_modules/vite
      └─┬ [email protected] -> ./node_modules/.pnpm/[email protected]/node_modules/rollup
        └── [email protected] deduped invalid: "^6.2.2" from node_modules/.pnpm/[email protected]/node_modules/quansync, "^6.0.7" from node_modules/.pnpm/[email protected]/node_modules/strip-literal, "^6.0.7" from node_modules/.pnpm/[email protected]/node_modules/strip-literal -> ./node_modules/.pnpm/[email protected]_@[email protected][email protected][email protected][email protected]/node_modules/vite

Beschreibung

No response

Metadata

Metadata

Assignees

No one assigned

    Labels

    securityTracking einer Security Vulnerability

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions