[Snyk] Security upgrade ethers from 5.7.2 to 6.0.0 #35
Mend Bolt for GitHub / Mend Security Check
failed
Aug 15, 2024 in 8m 39s
Security Report
You have successfully remediated 3 vulnerabilities, but introduced 1 new vulnerabilities in this branch.
❌ New vulnerabilities:
CVE | Severity | CVSS Score | Vulnerable Library | Suggested Fix | Issue |
---|---|---|---|---|---|
CVE-2024-4067Path to dependency file: /package.json Path to vulnerable library: /node_modules/grunt/node_modules/micromatch/package.json,/node_modules/liftup/node_modules/micromatch/package.json Dependency Hierarchy: -> grunt-1.6.1.tgz (Root Library) -> findup-sync-5.0.0.tgz -> ❌ micromatch-4.0.7.tgz (Vulnerable Library) |
Medium | 5.3 | micromatch-4.0.7.tgz | #31 |
✔️ Remediated vulnerabilities:
CVE | Vulnerable Library |
---|---|
CVE-2024-37890 | ws-8.17.0.tgz |
CVE-2024-37890 | ws-8.5.0.tgz |
CVE-2024-4067 | micromatch-4.0.6.tgz |
Base branch total remaining vulnerabilities: 59
Base branch commit: b17520d49acc97f4f5e90502a4a3e6e92b092ddc
Total libraries scanned: 989
Scan token: f9b95e557d7b44ad8186ac31778f6dd5
Loading