feat: add generated aztec-vm-sim package setup#23084
Pull Request #23084 Alerts: Complete with warnings
| Report | Status | Message |
|---|---|---|
| PR #23084 Alerts | Found 3 project alerts |
Pull request alerts notify when new issues are detected between the diff of the pull request and it's target branch.
Details
Caution
Review the following alerts detected in dependencies.
According to your organization's Security Policy, you must resolve all "Block" alerts before proceeding. It is recommended to resolve "Warn" alerts too. Learn more about Socket for GitHub.
| Action | Severity | Alert (click "▶" to expand/collapse) |
|---|---|---|
| Block | Critical CVE: Handlebars.js has JavaScript Injection via AST Type ConfusionCVE: GHSA-2w6w-674q-4c4q Handlebars.js has JavaScript Injection via AST Type Confusion (CRITICAL) Affected versions: >= 4.0.0 < 4.7.9 Patched version: 4.7.9 From: barretenberg/ts/bb.js/package-lock.json → ℹ Read more on: This package | This alert | What is a critical CVE?
|
|
| Warn | Medium CVE: Handlebars.js has a Prototype Method Access Control Gap via Missing __lookupSetter__ Blocklist EntryAffected versions: >= 4.6.0 < 4.7.9 Patched version: 4.7.9 From: barretenberg/ts/bb.js/package-lock.json → ℹ Read more on: This package | This alert | What is a medium CVE?
|
|
| Warn | Medium CVE: Handlebars.js has Prototype Pollution Leading to XSS through Partial Template InjectionAffected versions: >= 4.0.0 < 4.7.9 Patched version: 4.7.9 From: barretenberg/ts/bb.js/package-lock.json → ℹ Read more on: This package | This alert | What is a medium CVE?
|