Update dependency npm-check to v6 #23
Security Report
You have successfully remediated 4 vulnerabilities, but introduced 3 new vulnerabilities in this branch.
❌ New vulnerabilities:
CVE | Severity | CVSS Score | Vulnerable Library | Suggested Fix | Issue |
---|---|---|---|---|---|
CVE-2022-24999Path to dependency file: /package.json Path to vulnerable library: /node_modules/qs/package.json Dependency Hierarchy: -> body-parser-1.18.2.tgz (Root Library) -> ❌ qs-6.5.1.tgz (Vulnerable Library) |
High | 7.5 | qs-6.5.1.tgz | Upgrade to version: qs - 6.2.4,6.3.3,6.4.1,6.5.3,6.6.1,6.7.3,6.8.3,6.9.7,6.10.3 | None |
CVE-2022-24999Path to dependency file: /package.json Path to vulnerable library: /node_modules/express/node_modules/qs/package.json Dependency Hierarchy: -> express-4.15.5.tgz (Root Library) -> ❌ qs-6.5.0.tgz (Vulnerable Library) |
High | 7.5 | qs-6.5.0.tgz | Upgrade to version: qs - 6.2.4,6.3.3,6.4.1,6.5.3,6.6.1,6.7.3,6.8.3,6.9.7,6.10.3 | #4 |
CVE-2022-33987Path to dependency file: /package.json Path to vulnerable library: /node_modules/got/package.json Dependency Hierarchy: -> npm-check-6.0.1.tgz (Root Library) -> package-json-6.5.0.tgz -> ❌ got-9.6.0.tgz (Vulnerable Library) |
Medium | 5.3 | got-9.6.0.tgz | Upgrade to version: got - 11.8.5,12.1.0 | None |
✔️ Remediated vulnerabilities:
CVE | Vulnerable Library |
---|---|
WS-2019-0307 | mem-1.1.0.tgz |
CVE-2022-33987 | got-6.7.1.tgz |
CVE-2021-33623 | trim-newlines-1.0.0.tgz |
CVE-2020-7608 | yargs-parser-7.0.0.tgz |
Base branch total remaining vulnerabilities: 5
Base branch commit: null
Total libraries scanned: 388
Scan token: c4d2d0e3591142279873667482c9519e