GateLab's security feature has identified some known vulnerabilities in the package-lock.json
file that need to be updated. The message states:
Known security vulnerabilities detected
Dependency
object-path
Version
< 0.11.5
Upgrade to
~> 0.11.5
Defined in
package-lock.json
Vulnerabilities
CVE-2020-15256 High severity
Dependency
elliptic
Version
< 6.5.4
Upgrade to
~> 6.5.4
Defined in
package-lock.json
Vulnerabilities
CVE-2020-28498 Moderate severity
Dependency is-svg Version
= 2.1.0
< 4.2.2
Upgrade to
~> 4.2.2
Defined in
package-lock.json
Vulnerabilities
CVE-2021-28092 Moderate severity
Dependency ssri Version
= 5.2.2
< 8.0.1
Upgrade to
~> 8.0.1
Defined in
package-lock.json
Vulnerabilities
CVE-2021-27290 Moderate severity
However, running npm update
will not automatically update these packages.