[Snyk] Security upgrade twilio from 4.19.0 to 4.19.3 #1380

Closed
opened 2026-04-05 16:27:04 +02:00 by MrUnknownDE · 0 comments
Owner

Originally created by @simlarsen on 12/1/2023

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • Notification/package.json
    • Notification/package-lock.json

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
high severity 676/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 7.1
Cross-site Request Forgery (CSRF)
SNYK-JS-AXIOS-6032459
No Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: twilio The new version differs by 10 commits.
  • 2a51f83 Release 4.19.3
  • 90208b3 [Librarian] Regenerated @ 437c39e3f150e78058f5afb3ef0672e89fc59ec0
  • 00e852f Release 4.19.2
  • 5a3916d [Librarian] Regenerated @ 24dcf52b3ba6769ea21d08329aa544a79742b6c2
  • ce0804c chore: Removing Test Related To Deprecated Endpoint - OAuth (#963)
  • 23eca56 chore: twilio help changes (#958)
  • a981eb0 chore: Update axios to 1.6 to pull in fix for CVE 2023 45857 (#971)
  • e7bbeb1 chore: Removed LTS version (#978)
  • 1f6d8eb Release 4.19.1
  • 31e0189 [Librarian] Regenerated @ 5eb406c4977c9f6976e6053cb5b581056f541a59

See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Cross-site Request Forgery (CSRF)

*Originally created by @simlarsen on 12/1/2023* <p>This PR was automatically created by Snyk using the credentials of a real user.</p><br /><h3>Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.</h3> #### Changes included in this PR - Changes to the following files to upgrade the vulnerable dependencies to a fixed version: - Notification/package.json - Notification/package-lock.json #### Vulnerabilities that will be fixed ##### With an upgrade: Severity | Priority Score (*) | Issue | Breaking Change | Exploit Maturity :-------------------------:|-------------------------|:-------------------------|:-------------------------|:------------------------- ![high severity](https://res.cloudinary.com/snyk/image/upload/w_20,h_20/v1561977819/icon/h.png "high severity") | **676/1000** <br/> **Why?** Proof of Concept exploit, Has a fix available, CVSS 7.1 | Cross-site Request Forgery (CSRF) <br/>[SNYK-JS-AXIOS-6032459](https://snyk.io/vuln/SNYK-JS-AXIOS-6032459) | No | Proof of Concept (*) Note that the real score may have changed since the PR was raised. <details> <summary><b>Commit messages</b></summary> </br> <details> <summary>Package name: <b>twilio</b></summary> The new version differs by 10 commits.</br> <ul> <li><a href="https://snyk.io/redirect/github/twilio/twilio-node/commit/2a51f837687f7be5a15ad8a28639312b86d321fd">2a51f83</a> Release 4.19.3</li> <li><a href="https://snyk.io/redirect/github/twilio/twilio-node/commit/90208b3a7780e2685d472e95c4874f3830308e54">90208b3</a> [Librarian] Regenerated @ 437c39e3f150e78058f5afb3ef0672e89fc59ec0</li> <li><a href="https://snyk.io/redirect/github/twilio/twilio-node/commit/00e852f8617666e54bc1473624e55d994029aac1">00e852f</a> Release 4.19.2</li> <li><a href="https://snyk.io/redirect/github/twilio/twilio-node/commit/5a3916dc0bc799cb3ca5340f39f8ecadee507588">5a3916d</a> [Librarian] Regenerated @ 24dcf52b3ba6769ea21d08329aa544a79742b6c2</li> <li><a href="https://snyk.io/redirect/github/twilio/twilio-node/commit/ce0804c5e1fb8f6d21026aba3858b3e1ac319521">ce0804c</a> chore: Removing Test Related To Deprecated Endpoint - OAuth (#963)</li> <li><a href="https://snyk.io/redirect/github/twilio/twilio-node/commit/23eca5645571da1c293095eca511f4361ab1fb37">23eca56</a> chore: twilio help changes (#958)</li> <li><a href="https://snyk.io/redirect/github/twilio/twilio-node/commit/a981eb0266674ecc165e9fa460e2b81c8c6daa1b">a981eb0</a> chore: Update axios to 1.6 to pull in fix for CVE 2023 45857 (#971)</li> <li><a href="https://snyk.io/redirect/github/twilio/twilio-node/commit/e7bbeb18ddcec8b0874326266b6c73d4e2a073f3">e7bbeb1</a> chore: Removed LTS version (#978)</li> <li><a href="https://snyk.io/redirect/github/twilio/twilio-node/commit/1f6d8ebc2561bfa01b5d1accd24c9cdddda28806">1f6d8eb</a> Release 4.19.1</li> <li><a href="https://snyk.io/redirect/github/twilio/twilio-node/commit/31e018900d3a2c406fc8e2a0022360a70beadfab">31e0189</a> [Librarian] Regenerated @ 5eb406c4977c9f6976e6053cb5b581056f541a59</li> </ul> <a href="https://snyk.io/redirect/github/twilio/twilio-node/compare/de635412136f0ea776fc0223a6235f249e2a5a0b...2a51f837687f7be5a15ad8a28639312b86d321fd">See the full diff</a> </details> </details> Check the changes in this PR to ensure they won't cause issues with your project. ------------ **Note:** *You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.* For more information: <img src="https://api.segment.io/v1/pixel/track?data=eyJ3cml0ZUtleSI6InJyWmxZcEdHY2RyTHZsb0lYd0dUcVg4WkFRTnNCOUEwIiwiYW5vbnltb3VzSWQiOiJkMmYwOGViZC1kOThjLTQ1ZGQtYmU1Ny1mMTRmMTgzZDM4MmMiLCJldmVudCI6IlBSIHZpZXdlZCIsInByb3BlcnRpZXMiOnsicHJJZCI6ImQyZjA4ZWJkLWQ5OGMtNDVkZC1iZTU3LWYxNGYxODNkMzgyYyJ9fQ==" width="0" height="0"/> 🧐 [View latest project report](https://app.snyk.io/org/oneuptime-RsC2nshvQ2Vnr35jHvMnMP/project/0177f54a-1932-4698-9bc3-69701ae8a756?utm_source&#x3D;github&amp;utm_medium&#x3D;referral&amp;page&#x3D;fix-pr) 🛠 [Adjust project settings](https://app.snyk.io/org/oneuptime-RsC2nshvQ2Vnr35jHvMnMP/project/0177f54a-1932-4698-9bc3-69701ae8a756?utm_source&#x3D;github&amp;utm_medium&#x3D;referral&amp;page&#x3D;fix-pr/settings) 📚 [Read more about Snyk's upgrade and patch logic](https://support.snyk.io/hc/en-us/articles/360003891078-Snyk-patches-to-fix-vulnerabilities) [//]: # (snyk:metadata:{"prId":"d2f08ebd-d98c-45dd-be57-f14f183d382c","prPublicId":"d2f08ebd-d98c-45dd-be57-f14f183d382c","dependencies":[{"name":"twilio","from":"4.19.0","to":"4.19.3"}],"packageManager":"npm","projectPublicId":"0177f54a-1932-4698-9bc3-69701ae8a756","projectUrl":"https://app.snyk.io/org/oneuptime-RsC2nshvQ2Vnr35jHvMnMP/project/0177f54a-1932-4698-9bc3-69701ae8a756?utm_source=github&utm_medium=referral&page=fix-pr","type":"auto","patch":[],"vulns":["SNYK-JS-AXIOS-6032459"],"upgrade":["SNYK-JS-AXIOS-6032459"],"isBreakingChange":false,"env":"prod","prType":"fix","templateVariants":["updated-fix-title","priorityScore"],"priorityScoreList":[676],"remediationStrategy":"vuln"}) --- **Learn how to fix vulnerabilities with free interactive lessons:** 🦉 [Cross-site Request Forgery (CSRF)](https://learn.snyk.io/lesson/csrf-attack/?loc&#x3D;fix-pr)
Sign in to join this conversation.
No Label
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: github/oneuptime#1380