Update dependency vsts-task-lib to ^0.9.0 #9
WS on WS / WhiteSource Security Check
failed
Mar 20, 2024 in 2h 1m 28s
Security Report
You have successfully remediated 1 vulnerabilities, but introduced 1 new vulnerabilities in this branch.
❌ New vulnerabilities:
CVE | Severity | CVSS Score | Vulnerable Library | Suggested Fix | Issue |
---|---|---|---|---|---|
CVE-2022-37614Path to dependency file: /whitesource/package.json Path to vulnerable library: /whitesource/node_modules/mockery/package.json Dependency Hierarchy: -> vsts-task-lib-0.9.20.tgz (Root Library) -> ❌ mockery-1.7.0.tgz (Vulnerable Library) |
Critical | 9.8 | mockery-1.7.0.tgz | None |
✔️ Remediated vulnerabilities:
CVE | Vulnerable Library |
---|---|
CVE-2022-25883 | semver-5.7.1.tgz |
Base branch total remaining vulnerabilities: 13
Base branch commit: null
Total libraries scanned: 138
Scan token: b1286f95e4414d9b9ee71f8053784d59
Loading