Skip to content
This repository has been archived by the owner on Apr 26, 2024. It is now read-only.

Update dependency vinyl-fs to v2 #6

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Update dependency vinyl-fs to v2

066c347
Select commit
Loading
Failed to load commit list.
Open

Update dependency vinyl-fs to v2 #6

Update dependency vinyl-fs to v2
066c347
Select commit
Loading
Failed to load commit list.
Mend for GitHub.com / Mend Security Check failed Apr 26, 2024 in 7m 12s

Security Report

You have successfully remediated 9 vulnerabilities, but introduced 2 new vulnerabilities in this branch.

❌ New vulnerabilities:

CVE Severity CVSS Score Vulnerable Library Suggested Fix Issue
CVE-2020-28469

Path to dependency file: /package.json

Path to vulnerable library: /node_modules/glob-parent/package.json

Dependency Hierarchy:

-> vinyl-fs-2.4.4.tgz (Root Library)

   -> glob-stream-5.3.5.tgz

     -> ❌ glob-parent-3.1.0.tgz (Vulnerable Library)

High 7.5 glob-parent-3.1.0.tgz Upgrade to version: glob-parent - 5.1.2 None
CVE-2020-28469

Path to dependency file: /package.json

Path to vulnerable library: /node_modules/glob-base/node_modules/glob-parent/package.json

Dependency Hierarchy:

-> vinyl-fs-2.4.4.tgz (Root Library)

   -> glob-stream-5.3.5.tgz

     -> micromatch-2.3.11.tgz

       -> parse-glob-3.0.4.tgz

         -> glob-base-0.3.0.tgz

           -> ❌ glob-parent-2.0.0.tgz (Vulnerable Library)

High 7.5 glob-parent-2.0.0.tgz Upgrade to version: glob-parent - 5.1.2 None

✔️ Remediated vulnerabilities:

CVE Vulnerable Library
CVE-2018-3721 lodash-1.0.2.tgz
CVE-2020-28500 lodash-1.0.2.tgz
CVE-2020-8203 lodash-1.0.2.tgz
CVE-2019-10744 lodash-1.0.2.tgz
CVE-2019-1010266 lodash-1.0.2.tgz
CVE-2021-23337 lodash-1.0.2.tgz
CVE-2022-3517 minimatch-0.2.14.tgz
CVE-2018-16487 lodash-1.0.2.tgz
CVE-2016-10540 minimatch-0.2.14.tgz

Base branch total remaining vulnerabilities: 27
Base branch commit: d7ca6919fe4b7eb62ae09036f0bc365e96dd3dad


Total libraries scanned: 154

Scan token: b6b00efb3e274b7ca0fd593cad587f18