Update dependency resolve-url-loader to v3.1.5 #7
Mend for GitHub.com / Mend Security Check
failed
Feb 14, 2025 in 7m 39s
Security Report
You have successfully remediated 6 vulnerabilities, but introduced 1 new vulnerabilities in this branch.
❌ New vulnerabilities:
CVE | Severity | Vulnerable Library | Suggested Fix | Issue | Reachability | |
---|---|---|---|---|---|---|
CVE-2025-2306Path to dependency file: /baak-dataload-sql/package.json Path to vulnerable library: /baak-dataload-sql/node_modules/mongoose/package.json Dependency Hierarchy: -> ❌ mongoose-5.13.14.tgz (Vulnerable Library) |
9.4 | mongoose-5.13.14.tgz | Upgrade to version: mongoose -6.13.6,7.8.4,8.9.5 | #19 |
✔️ Remediated vulnerabilities:
CVE | Vulnerable Library |
---|---|
CVE-2022-37603 | loader-utils-1.2.3.tgz |
CVE-2022-37599 | loader-utils-2.0.2.tgz |
CVE-2022-37603 | loader-utils-2.0.2.tgz |
CVE-2024-27088 | es5-ext-0.10.53.tgz |
CVE-2022-37601 | loader-utils-1.2.3.tgz |
CVE-2022-37601 | loader-utils-2.0.2.tgz |
Base branch total remaining vulnerabilities: 87
Base branch commit: b2828e2e5760706da2e449bc8b11e5e95aab348e
Total libraries scanned: 1923
Scan token: dbf7998ec1cd470cbd1dacdb75423c14
Loading