-
Notifications
You must be signed in to change notification settings - Fork 0
[Security]: Vite middleware may serve files starting with the same name with the public directory #570
Copy link
Copy link
Open
Labels
securityTracking einer Security VulnerabilityTracking einer Security Vulnerability
Description
Link zum Dependbot Alert
https://github.com/ncs-northware/northware/security/dependabot/31
Schweregrad
Low
Betroffenes Package
Abhängigkeiten
northware@ /workspaces/northware
├─┬ @changesets/[email protected] -> ./node_modules/.pnpm/@[email protected]_@[email protected]/node_modules/@changesets/cli
│ └─┬ [email protected] -> ./node_modules/.pnpm/[email protected]/node_modules/package-manager-detector
│ ├─┬ [email protected] -> ./node_modules/.pnpm/[email protected]/node_modules/quansync
│ │ └── [email protected] invalid: "^6.2.2" from node_modules/.pnpm/[email protected]/node_modules/quansync, "^6.0.7" from node_modules/.pnpm/[email protected]/node_modules/strip-literal -> ./node_modules/.pnpm/[email protected]_@[email protected][email protected][email protected][email protected]/node_modules/vite
│ └─┬ [email protected] invalid: "3.1.4" from node_modules/.pnpm/[email protected][email protected]/node_modules/trpc-cli -> ./node_modules/.pnpm/[email protected]_@[email protected]_@[email protected][email protected][email protected][email protected]/node_modules/vitest
│ └── [email protected] deduped -> ./node_modules/.pnpm/[email protected]_@[email protected][email protected][email protected][email protected]/node_modules/vite
├─┬ @commitlint/[email protected] -> ./node_modules/.pnpm/@[email protected]_@[email protected][email protected]/node_modules/@commitlint/cli
│ └─┬ [email protected] -> ./node_modules/.pnpm/[email protected]/node_modules/yargs
│ └─┬ [email protected] invalid: "^2.23.0" from node_modules/.pnpm/[email protected]/node_modules/yargs, "^1.23.1" from node_modules/.pnpm/[email protected]/node_modules/deepmerge, "^2.23.1" from node_modules/.pnpm/[email protected]/node_modules/cliui -> ./node_modules/.pnpm/[email protected]/node_modules/rollup
│ └── [email protected] deduped invalid: "^6.2.2" from node_modules/.pnpm/[email protected]/node_modules/quansync -> ./node_modules/.pnpm/[email protected]_@[email protected][email protected][email protected][email protected]/node_modules/vite
├─┬ [email protected] -> ./node_modules/.pnpm/[email protected]/node_modules/typescript
│ └─┬ [email protected] -> ./node_modules/.pnpm/[email protected]/node_modules/source-map-support
│ └─┬ [email protected] invalid: "^1.15.0" from node_modules/.pnpm/[email protected]/node_modules/source-map-support, "^4.31.0" from node_modules/.pnpm/[email protected]/node_modules/rxjs, "^1.12.0" from node_modules/.pnpm/[email protected]/node_modules/source-map -> ./node_modules/.pnpm/[email protected][email protected]/node_modules/webpack
│ └─┬ [email protected] invalid: "^7.1.2" from node_modules/.pnpm/[email protected][email protected]/node_modules/webpack -> ./node_modules/.pnpm/[email protected][email protected][email protected]_/node_modules/css-loader
│ └─┬ [email protected] invalid: "^6.2.1" from node_modules/.pnpm/[email protected][email protected][email protected]_/node_modules/css-loader -> ./node_modules/.pnpm/[email protected][email protected][email protected][email protected][email protected]_/node_modules/postcss-loader
│ └─┬ [email protected] -> ./node_modules/.pnpm/[email protected]/node_modules/jiti
│ └── [email protected] deduped invalid: "^6.2.2" from node_modules/.pnpm/[email protected]/node_modules/quansync, "^6.0.7" from node_modules/.pnpm/[email protected]/node_modules/strip-literal, "^6.0.7" from node_modules/.pnpm/[email protected]/node_modules/strip-literal, "^6.0.3" from node_modules/.pnpm/[email protected]/node_modules/jiti -> ./node_modules/.pnpm/[email protected]_@[email protected][email protected][email protected][email protected]/node_modules/vite
└─┬ [email protected] -> ./node_modules/.pnpm/[email protected]_@[email protected]_@[email protected][email protected][email protected][email protected][email protected]/node_modules/ultracite
├─┬ [email protected] -> ./node_modules/.pnpm/[email protected][email protected]/node_modules/trpc-cli
│ └─┬ @trpc/[email protected] -> ./node_modules/.pnpm/@[email protected][email protected]/node_modules/@trpc/server
│ └─┬ [email protected] -> ./node_modules/.pnpm/[email protected]_@[email protected][email protected][email protected][email protected]/node_modules/next
│ └─┬ [email protected] invalid: "8.6.0" from node_modules/.pnpm/[email protected]_@[email protected][email protected][email protected][email protected]/node_modules/next -> ./node_modules/.pnpm/[email protected]_@[email protected][email protected][email protected]_@[email protected]_a40199458529514178c4bba99236bb07/node_modules/storybook
│ ├─┬ @storybook/[email protected] -> ./node_modules/.pnpm/@[email protected][email protected][email protected][email protected]/node_modules/@storybook/icons
│ │ └── [email protected] deduped invalid: "^6.2.2" from node_modules/.pnpm/[email protected]/node_modules/quansync, "^6.0.7" from node_modules/.pnpm/[email protected]/node_modules/strip-literal, "^6.0.7" from node_modules/.pnpm/[email protected]/node_modules/strip-literal, "^6.0.3" from node_modules/.pnpm/[email protected]/node_modules/jiti, "4.2.1" from node_modules/.pnpm/@[email protected][email protected][email protected][email protected]/node_modules/@storybook/icons -> ./node_modules/.pnpm/[email protected]_@[email protected][email protected][email protected][email protected]/node_modules/vite
│ └─┬ @vitest/[email protected] -> ./node_modules/.pnpm/@[email protected][email protected]_@[email protected][email protected][email protected][email protected]_/node_modules/@vitest/mocker
│ └─┬ [email protected] invalid: "^5.4.0" from node_modules/.pnpm/@[email protected][email protected]_@[email protected][email protected][email protected][email protected]_/node_modules/@vitest/mocker -> ./node_modules/.pnpm/[email protected]_@[email protected][email protected][email protected][email protected]/node_modules/vite
│ └─┬ [email protected] -> ./node_modules/.pnpm/[email protected]/node_modules/rollup
│ └── [email protected] deduped invalid: "^6.2.2" from node_modules/.pnpm/[email protected]/node_modules/quansync, "^6.0.7" from node_modules/.pnpm/[email protected]/node_modules/strip-literal, "^6.0.7" from node_modules/.pnpm/[email protected]/node_modules/strip-literal, "^6.0.3" from node_modules/.pnpm/[email protected]/node_modules/jiti, "4.2.1" from node_modules/.pnpm/@[email protected][email protected][email protected][email protected]/node_modules/@storybook/icons -> ./node_modules/.pnpm/[email protected]_@[email protected][email protected][email protected][email protected]/node_modules/vite
└─┬ [email protected] -> ./node_modules/.pnpm/[email protected]_@[email protected]_@[email protected][email protected][email protected][email protected]/node_modules/vitest
├─┬ @vitest/[email protected] -> ./node_modules/.pnpm/@[email protected][email protected]_@[email protected][email protected][email protected][email protected]_/node_modules/@vitest/mocker
│ └── [email protected] invalid: "^5.4.0" from node_modules/.pnpm/@[email protected][email protected]_@[email protected][email protected][email protected][email protected]_/node_modules/@vitest/mocker -> ./node_modules/.pnpm/[email protected]_@[email protected][email protected][email protected][email protected]/node_modules/vite
├─┬ @vitest/[email protected] -> ./node_modules/.pnpm/@[email protected]/node_modules/@vitest/runner
│ └─┬ [email protected] -> ./node_modules/.pnpm/[email protected]/node_modules/strip-literal
│ └── [email protected] deduped invalid: "^6.2.2" from node_modules/.pnpm/[email protected]/node_modules/quansync, "^6.0.7" from node_modules/.pnpm/[email protected]/node_modules/strip-literal, "^6.0.7" from node_modules/.pnpm/[email protected]/node_modules/strip-literal -> ./node_modules/.pnpm/[email protected]_@[email protected][email protected][email protected][email protected]/node_modules/vite
├─┬ [email protected] -> ./node_modules/.pnpm/[email protected]/node_modules/strip-literal
│ └── [email protected] deduped invalid: "^6.2.2" from node_modules/.pnpm/[email protected]/node_modules/quansync, "^6.0.7" from node_modules/.pnpm/[email protected]/node_modules/strip-literal -> ./node_modules/.pnpm/[email protected]_@[email protected][email protected][email protected][email protected]/node_modules/vite
├─┬ [email protected] -> ./node_modules/.pnpm/[email protected]_@[email protected][email protected][email protected][email protected]/node_modules/vite-node
│ └── [email protected] -> ./node_modules/.pnpm/[email protected]_@[email protected][email protected][email protected][email protected]/node_modules/vite
└─┬ [email protected] -> ./node_modules/.pnpm/[email protected]_@[email protected][email protected][email protected][email protected]/node_modules/vite
└─┬ [email protected] -> ./node_modules/.pnpm/[email protected]/node_modules/rollup
└── [email protected] deduped invalid: "^6.2.2" from node_modules/.pnpm/[email protected]/node_modules/quansync, "^6.0.7" from node_modules/.pnpm/[email protected]/node_modules/strip-literal, "^6.0.7" from node_modules/.pnpm/[email protected]/node_modules/strip-literal -> ./node_modules/.pnpm/[email protected]_@[email protected][email protected][email protected][email protected]/node_modules/viteBeschreibung
No response
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
securityTracking einer Security VulnerabilityTracking einer Security Vulnerability