[Snyk] Fix for 1 vulnerabilities #29
Open
Mend Bolt for GitHub / Mend Security Check
failed
Jun 20, 2024 in 5m 25s
Security Report
You have successfully remediated 2 vulnerabilities, but introduced 1 new vulnerabilities in this branch.
❌ New vulnerabilities:
CVE | Severity | CVSS Score | Vulnerable Library | Suggested Fix | Issue |
---|---|---|---|---|---|
CVE-2024-38355Path to dependency file: /package.json Path to vulnerable library: /node_modules/socket.io/package.json Dependency Hierarchy: -> ❌ socket.io-3.1.2.tgz (Vulnerable Library) |
High | 7.3 | socket.io-3.1.2.tgz | Upgrade to version: socket.io - 2.5.1,4.6.2 | #13 |
✔️ Remediated vulnerabilities:
CVE | Vulnerable Library |
---|---|
CVE-2024-37890 | ws-8.17.0.tgz |
CVE-2024-37890 | ws-8.5.0.tgz |
Base branch total remaining vulnerabilities: 55
Base branch commit: b17520d49acc97f4f5e90502a4a3e6e92b092ddc
Total libraries scanned: 987
Scan token: 5cf25f1d6662432091f80d6bd198c14a
Loading