How to fix security alert on github – Prototype Pollution in minimist
It is not direct deps .
package and package.lock on link
Any suggestion ?
LOGO:
proxy | 2024/06/03 16:51:27 [213] 200 https://registry.npmjs.org:443/ws
updater | 2024/06/03 16:51:27 INFO <job_836735885> VulnerabilityAuditor: audit result viable
updater | 2024/06/03 16:51:27 INFO <job_836735885> Requirements to unlock all
proxy | 2024/06/03 16:51:27 [215] GET https://registry.npmjs.org:443/magic-three-serve
proxy | 2024/06/03 16:51:27 [215] 404 https://registry.npmjs.org:443/magic-three-serve
updater | 2024/06/03 16:51:27 INFO <job_836735885> Requirements update strategy bump_versions
proxy | 2024/06/03 16:51:27 [217] GET https://registry.npmjs.org:443/magic-three-serve
proxy | 2024/06/03 16:51:27 [217] 404 https://registry.npmjs.org:443/magic-three-serve
proxy | 2024/06/03 16:51:27 [219] GET https://registry.npmjs.org:443/magic-three-serve
proxy | 2024/06/03 16:51:28 [219] 404 https://registry.npmjs.org:443/magic-three-serve
updater | 2024/06/03 16:51:27 INFO <job_836735885> Updating minimist, optimist
updater | 2024/06/03 16:51:28 ERROR <job_836735885> Error processing minimist (Dependabot::NpmAndYarn::FileUpdater::NoChangeError)
updater | 2024/06/03 16:51:28 ERROR <job_836735885> No files were updated!
updater | 2024/06/03 16:51:28 ERROR <job_836735885> /home/dependabot/npm_and_yarn/lib/dependabot/npm_and_yarn/file_updater.rb:52:in `updated_dependency_files'
updater | 2024/06/03 16:51:28 ERROR <job_836735885> /home/dependabot/dependabot-updater/vendor/ruby/3.3.0/gems/sorbet-runtime-0.5.11353/lib/types/private/methods/call_validation.rb:270:in `bind_call'
updater | 2024/06/03 16:51:28 ERROR <job_836735885> /home/dependabot/dependabot-updater/vendor/ruby/3.3.0/gems/sorbet-runtime-0.5.11353/lib/types/private/methods/call_validation.rb:270:in `validate_call'
updater | 2024/06/03 16:51:28 ERROR <job_836735885> /home/dependabot/dependabot-updater/vendor/ruby/3.3.0/gems/sorbet-runtime-0.5.11353/lib/types/private/methods/_methods.rb:277:in `block in _on_method_added'
updater | 2024/06/03 16:51:28 ERROR <job_836735885> /home/dependabot/dependabot-updater/lib/dependabot/dependency_change_builder.rb:135:in `generate_dependency_files'
updater | 2024/06/03 16:51:28 ERROR <job_836735885> /home/dependabot/dependabot-updater/vendor/ruby/3.3.0/gems/sorbet-runtime-0.5.11353/lib/types/private/methods/call_validation.rb:270:in `bind_call'
updater | 2024/06/03 16:51:28 ERROR <job_836735885> /home/dependabot/dependabot-updater/vendor/ruby/3.3.0/gems/sorbet-runtime-0.5.11353/lib/types/private/methods/call_validation.rb:270:in `validate_call'
updater | 2024/06/03 16:51:28 ERROR <job_836735885> /home/dependabot/dependabot-updater/vendor/ruby/3.3.0/gems/sorbet-runtime-0.5.11353/lib/types/private/methods/_methods.rb:277:in `block in _on_method_added'
updater | 2024/06/03 16:51:28 ERROR <job_836735885> /home/dependabot/dependabot-updater/lib/dependabot/dependency_change_builder.rb:68:in `run'
updater | 2024/06/03 16:51:28 ERROR <job_836735885> /home/dependabot/dependabot-updater/vendor/ruby/3.3.0/gems/sorbet-runtime-0.5.11353/lib/types/private/methods/call_validation.rb:270:in `bind_call'
updater | 2024/06/03 16:51:28 ERROR <job_836735885> /home/dependabot/dependabot-updater/vendor/ruby/3.3.0/gems/sorbet-runtime-0.5.11353/lib/types/private/methods/call_validation.rb:270:in `validate_call'
updater | 2024/06/03 16:51:28 ERROR <job_836735885> /home/dependabot/dependabot-updater/vendor/ruby/3.3.0/gems/sorbet-runtime-0.5.11353/lib/types/private/methods/_methods.rb:277:in `block in _on_method_added'
updater | 2024/06/03 16:51:28 ERROR <job_836735885> /home/dependabot/dependabot-updater/lib/dependabot/dependency_change_builder.rb:42:in `create_from'
updater | 2024/06/03 16:51:28 ERROR <job_836735885> /home/dependabot/dependabot-updater/vendor/ruby/3.3.0/gems/sorbet-runtime-0.5.11353/lib/types/private/methods/call_validation.rb:270:in `bind_call'
updater | 2024/06/03 16:51:28 ERROR <job_836735885> /home/dependabot/dependabot-updater/vendor/ruby/3.3.0/gems/sorbet-runtime-0.5.11353/lib/types/private/methods/call_validation.rb:270:in `validate_call'
updater | 2024/06/03 16:51:28 ERROR <job_836735885> /home/dependabot/dependabot-updater/vendor/ruby/3.3.0/gems/sorbet-runtime-0.5.11353/lib/types/private/methods/_methods.rb:277:in `block in _on_method_added'
updater | 2024/06/03 16:51:28 ERROR <job_836735885> /home/dependabot/dependabot-updater/lib/dependabot/updater/group_update_creation.rb:107:in `create_change_for'
updater | 2024/06/03 16:51:28 ERROR <job_836735885> /home/dependabot/dependabot-updater/lib/dependabot/updater/group_update_creation.rb:66:in `block in compile_all_dependency_changes_for'
updater | 2024/06/03 16:51:28 ERROR <job_836735885> /home/dependabot/dependabot-updater/lib/dependabot/updater/group_update_creation.rb:32:in `each'
updater | 2024/06/03 16:51:28 ERROR <job_836735885> /home/dependabot/dependabot-updater/lib/dependabot/updater/group_update_creation.rb:32:in `compile_all_dependency_changes_for'
updater | 2024/06/03 16:51:28 ERROR <job_836735885> /home/dependabot/dependabot-updater/lib/dependabot/updater/operations/create_group_update_pull_request.rb:75:in `block in dependency_change'
updater | 2024/06/03 16:51:28 ERROR <job_836735885> /home/dependabot/dependabot-updater/lib/dependabot/updater/operations/create_group_update_pull_request.rb:72:in `map'
updater | 2024/06/03 16:51:28 ERROR <job_836735885> /home/dependabot/dependabot-updater/lib/dependabot/updater/operations/create_group_update_pull_request.rb:72:in `dependency_change'
updater | 2024/06/03 16:51:28 ERROR <job_836735885> /home/dependabot/dependabot-updater/lib/dependabot/updater/operations/create_group_update_pull_request.rb:44:in `perform'
updater | 2024/06/03 16:51:28 ERROR <job_836735885> /home/dependabot/dependabot-updater/lib/dependabot/updater/operations/group_update_all_versions.rb:127:in `run_update_for'
updater | 2024/06/03 16:51:28 ERROR <job_836735885> /home/dependabot/dependabot-updater/lib/dependabot/updater/operations/group_update_all_versions.rb:109:in `block in run_grouped_dependency_updates'
updater | 2024/06/03 16:51:28 ERROR <job_836735885> /home/dependabot/dependabot-updater/lib/dependabot/updater/operations/group_update_all_versions.rb:108:in `each'
updater | 2024/06/03 16:51:28 ERROR <job_836735885> /home/dependabot/dependabot-updater/lib/dependabot/updater/operations/group_update_all_versions.rb:108:in `run_grouped_dependency_updates'
updater | 2024/06/03 16:51:28 ERROR <job_836735885> /home/dependabot/dependabot-updater/lib/dependabot/updater/operations/group_update_all_versions.rb:55:in `perform'
updater | 2024/06/03 16:51:28 ERROR <job_836735885> /home/dependabot/dependabot-updater/lib/dependabot/updater.rb:45:in `run'
updater | 2024/06/03 16:51:28 ERROR <job_836735885> /home/dependabot/dependabot-updater/lib/dependabot/update_files_command.rb:44:in `block in perform_job'
updater | 2024/06/03 16:51:28 ERROR <job_836735885> /home/dependabot/dependabot-updater/vendor/ruby/3.3.0/gems/opentelemetry-api-1.2.3/lib/opentelemetry/trace/tracer.rb:37:in `block in in_span'
updater | 2024/06/03 16:51:28 ERROR <job_836735885> /home/dependabot/dependabot-updater/vendor/ruby/3.3.0/gems/opentelemetry-api-1.2.3/lib/opentelemetry/trace.rb:70:in `block in with_span'
updater | 2024/06/03 16:51:28 ERROR <job_836735885> /home/dependabot/dependabot-updater/vendor/ruby/3.3.0/gems/opentelemetry-api-1.2.3/lib/opentelemetry/context.rb:87:in `with_value'
updater | 2024/06/03 16:51:28 ERROR <job_836735885> /home/dependabot/dependabot-updater/vendor/ruby/3.3.0/gems/opentelemetry-api-1.2.3/lib/opentelemetry/trace.rb:70:in `with_span'
updater | 2024/06/03 16:51:28 ERROR <job_836735885> /home/dependabot/dependabot-updater/vendor/ruby/3.3.0/gems/opentelemetry-api-1.2.3/lib/opentelemetry/trace/tracer.rb:37:in `in_span'
updater | 2024/06/03 16:51:28 ERROR <job_836735885> /home/dependabot/dependabot-updater/lib/dependabot/update_files_command.rb:18:in `perform_job'
updater | 2024/06/03 16:51:28 ERROR <job_836735885> /home/dependabot/dependabot-updater/lib/dependabot/base_command.rb:37:in `run'
updater | 2024/06/03 16:51:28 ERROR <job_836735885> bin/update_files.rb:46:in `<main>'
updater | 2024/06/03 16:51:29 INFO <job_836735885> Nothing to update for Dependency Group: 'npm_and_yarn'
updater | 2024/06/03 16:51:29 INFO <job_836735885> Finished job processing
updater | 2024/06/03 16:51:29 INFO Results:
updater | Dependabot encountered '1' error(s) during execution, please check the logs for more details.
updater | +-------------------------------+
updater | | Dependencies failed to update |
updater | +---------------+---------------+
updater | | minimist | unknown_error |
updater | +---------------+---------------+
updater | time="2024-06-03T16:51:29Z" level=info msg="task complete" container_id=job-836735885-updater exit_code=0 job_id=836735885 step=updater