fix: update dependabot dependencies (backport of #21238)#21332
Pull Request #21332 Alerts: Complete with warnings
| Report | Status | Message |
|---|---|---|
| PR #21332 Alerts | Found 2 project alerts |
Pull request alerts notify when new issues are detected between the diff of the pull request and it's target branch.
Details
Warning
Review the following alerts detected in dependencies.
According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.
| Action | Severity | Alert (click "▶" to expand/collapse) |
|---|---|---|
| Warn | Medium CVE: Fastify's Missing End Anchor in "subtypeNameReg" Allows Malformed Content-Types to Pass ValidationAffected versions: >= 5.7.2 < 5.8.1 Patched version: 5.8.1 From: ℹ Read more on: This package | This alert | What is a medium CVE?
|
|
| Warn | Install-time scripts: npm
|