Skip to content

Update dependency @vitest/eslint-plugin to v1.1.16 (#9914)

Mend Bolt for GitHub / WhiteSource Security Check succeeded Dec 12, 2024 in 16m 5s

Security Report

The Security Check found 10 vulnerabilities.

CVE Severity CVSS Score Vulnerable Library Suggested Fix Issue
CVE-2024-29415

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> sass-1.81.0.tgz (Root Library)

   -> watcher-2.4.1.tgz

     -> node-gyp-8.2.0.tgz

       -> make-fetch-happen-8.0.14.tgz

         -> socks-proxy-agent-5.0.1.tgz

           -> socks-2.6.1.tgz

             -> ❌ ip-1.1.9.tgz (Vulnerable Library)

Critical 9.1 ip-1.1.9.tgz #9842
CVE-2024-21529

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> doc-site-0.0.0.tgz (Root Library)

   -> graphql-file-loader-8.0.6.tgz

     -> utils-10.6.2.tgz

       -> ❌ dset-3.1.2.tgz (Vulnerable Library)

High 8.2 dset-3.1.2.tgz Upgrade to version: dset - 3.1.4 #6560
CVE-2024-52798

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> doc-site-0.0.0.tgz (Root Library)

   -> core-3.6.2.tgz

     -> webpack-dev-server-4.15.2.tgz

       -> express-4.20.0.tgz

         -> ❌ path-to-regexp-0.1.10.tgz (Vulnerable Library)

High 7.5 path-to-regexp-0.1.10.tgz Upgrade to version: path-to-regexp - 0.1.12 #6560
CVE-2024-45296

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> doc-site-0.0.0.tgz (Root Library)

   -> core-3.6.2.tgz

     -> react-router-5.3.4.tgz

       -> ❌ path-to-regexp-1.8.0.tgz (Vulnerable Library)

High 7.5 path-to-regexp-1.8.0.tgz Upgrade to version: path-to-regexp - 0.1.10,1.9.0,3.3.0,6.3.0,8.0.0 #6560
CVE-2024-37890

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> doc-site-0.0.0.tgz (Root Library)

   -> graphql-config-5.1.3.tgz

     -> url-loader-8.0.0.tgz

       -> executor-graphql-ws-1.0.0.tgz

         -> ❌ ws-8.13.0.tgz (Vulnerable Library)

High 7.5 ws-8.13.0.tgz Upgrade to version: ws - 5.2.4,6.2.3,7.5.10,8.17.1 #6560
CVE-2024-37890

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> doc-site-0.0.0.tgz (Root Library)

   -> core-3.6.2.tgz

     -> webpack-bundle-analyzer-4.10.2.tgz

       -> ❌ ws-7.5.4.tgz (Vulnerable Library)

High 7.5 ws-7.5.4.tgz Upgrade to version: ws - 5.2.4,6.2.3,7.5.10,8.17.1 #6560
CVE-2022-37603

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> doc-site-0.0.0.tgz (Root Library)

   -> core-3.6.2.tgz

     -> react-dev-utils-12.0.1.tgz

       -> ❌ loader-utils-3.2.0.tgz (Vulnerable Library)

High 7.5 loader-utils-3.2.0.tgz Upgrade to version: loader-utils - 1.4.2,2.0.4,3.2.1 #6560
CVE-2022-3517

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> doc-site-0.0.0.tgz (Root Library)

   -> core-3.6.2.tgz

     -> react-dev-utils-12.0.1.tgz

       -> recursive-readdir-2.2.2.tgz

         -> ❌ minimatch-3.0.4.tgz (Vulnerable Library)

High 7.5 minimatch-3.0.4.tgz Upgrade to version: minimatch - 3.0.5 #6560
CVE-2024-47764

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> doc-site-0.0.0.tgz (Root Library)

   -> core-3.6.2.tgz

     -> webpack-dev-server-4.15.2.tgz

       -> express-4.20.0.tgz

         -> ❌ cookie-0.6.0.tgz (Vulnerable Library)

Medium 5.3 cookie-0.6.0.tgz Upgrade to version: cookie - 0.7.0 #6560
CVE-2024-43799

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> doc-site-0.0.0.tgz (Root Library)

   -> core-3.6.2.tgz

     -> webpack-dev-server-4.15.2.tgz

       -> express-4.20.0.tgz

         -> serve-static-1.16.0.tgz

           -> ❌ send-0.18.0.tgz (Vulnerable Library)

Medium 5.0 send-0.18.0.tgz Upgrade to version: send - 0.19.0 #6560

Total libraries scanned: 1942
Scan token: 7f6e88cf77c84d928c8556aff8791bbc