Finding from security review:
We depend on some outdated packages on push-notifications service that need to be updated
Outdated Packages
As reported via npm outdated:
(no explicit vulnerabilities reported, simply noting for completeness' sake.)
Risk: none
| Package | Current | Wanted | Latest |
|---|---|---|---|
| @types/bluebird | 3.5.31 | 3.5.32 | 3.5.32 |
| @types/concurrently | 5.2.0 | 5.2.1 | 5.2.1 |
| @types/eslint | 6.8.1 | 6.8.1 | 7.2.2 |
| @types/express | 4.17.6 | 4.17.8 | 4.17.8 |
| @types/js-yaml | 3.12.4 | 3.12.5 | 3.12.5 |
| @types/mocha | 7.0.2 | 7.0.2 | 8.0.3 |
| @types/node | 13.13.6 | 13.13.16 | 14.6.3 |
| @typescript-eslint/eslint-plugin | 2.33.0 | 2.34.0 | 4.0.1 |
| @typescript-eslint/parser | 2.33.0 | 2.34.0 | 4.0.1 |
| ajv | 6.12.2 | 6.12.4 | 6.12.4 |
| bunyan | 1.8.12 | 1.8.14 | 1.8.14 |
| concurrently | 5.2.0 | 5.3.0 | 5.3.0 |
| domino | 2.1.5 | 2.1.6 | 2.1.6 |
| eslint-config-wikimedia | 0.10.1 | 0.10.1 | 0.17.0 |
| eslint-plugin-jsdoc | 4.8.4 | 4.8.4 | 30.3.1 |
| eslint-plugin-json | 1.4.0 | 1.4.0 | 2.1.2 |
| firebase-admin | 8.12.1 | 8.13.0 | 9.1.1 |
| js-yaml | 3.13.1 | 3.14.0 | 3.14.0 |
| mocha | 5.2.0 | 5.2.0 | 8.1.3 |
| nock | 12.0.3 | 12.0.3 | 13.0.4 |
| nyc | 14.1.1 | 14.1.1 | 15.1.0 |
| openapi-schema-validator | 3.0.3 | 3.0.3 | 7.0.1 |
| service-runner | 2.8.0 | git | git |
| sinon | 9.0.2 | 9.0.3 | 9.0.3 |
| swagger-ui-dist | 3.25.1 | 3.32.5 | 3.32.5 |
| ts-node | 8.10.1 | 8.10.2 | 9.0.0 |
| typescript | 3.9.2 | 3.9.7 | 4.0.2 |
| uuid | 3.4.0 | 3.4.0 | 8.3.0 |