Skip to content

Replace dependency faker with @faker-js/faker - #48

Open
mend-for-github-com[bot] wants to merge 1 commit into
mainfrom
whitesource-remediate/faker-replacement
Open

Replace dependency faker with @faker-js/faker#48
mend-for-github-com[bot] wants to merge 1 commit into
mainfrom
whitesource-remediate/faker-replacement

Replace dependency faker with @faker-js/faker

1962d9c
Select commit
Loading
Failed to load commit list.
Mend for GitHub.com / Mend Security Check failed Aug 25, 2026 in 4m 2s

Security Report

❗️Scan Warnings: The scan completed with warnings. The integration encountered issues with one or more projects in this repository. Consequently, there may be gaps in the coverage of open-source dependencies used in the repository.

Scan Details Report

maven

/tmp/ws-scm/WebGoat/pom.xml

Step Level Description Details
Preparing the project for scan ⚠Warn One or more of the installations failed [ERROR] [ERROR] Some problems were encountered while processing the POMs:
[FATAL] Non-resolvable parent POM for org.owasp.webgoat:webgoat:2023.4: The following artifacts could not be resolved: org.springframework.boot:spring-boot-starter-parent:pom:2.7.1 (absent): Could not transfer artifact org.springframework.boot:spring-boot-starter-parent:pom:2.7.1 from/to central (https://repo.maven.apache...
Resolving the project ⚠Warn Some problems occurred while performing the resolution operation
  • Failed to execute command: mvn org.apache.maven.plugins:maven-dependency-plugin:3.6.0:tree -DoutputFile=whitesource_mvn_dependency_tree.txt -Dverbose -DoutputType=text -T1 -B
    Error lines:
    [NOTE: Picked up JDK_JAVA_OPTIONS: --add-opens java.base/java.util=ALL-UNNAMED --add-opens java.base/sun.reflect.generics.reflectiveObjects=ALL-UNNAMED]
    Output lines:
    [[INFO] Scanning for project...
  • Fallback is used, returns direct dependencies only

You have successfully remediated 166 vulnerabilities, but introduced 4 new vulnerabilities in this branch.

❌ New vulnerabilities:
Vulnerability Severity CVSS Score Exploit Maturity EPSS Vulnerable Library Direct Library Suggested Fix Issue Reachability
CVE-2026-73231

Path to dependency file: /package.json

Path to vulnerable library: /node_modules/@⁠faker-js/faker/package.json

Dependency Hierarchy:

-> ❌ faker-5.5.3.tgz (Vulnerable Library)

High 7.8 Not Defined 0.154% Direct faker-5.5.3.tgz faker-5.5.3.tgz 10.5.0 None

Unreachable

CVE-2025-4641

Path to dependency file: /pom.xml

Path to vulnerable library: /pom.xml

Dependency Hierarchy:

-> ❌ webdrivermanager-4.3.1.jar (Vulnerable Library)

Critical 10.0 Not Defined 0.555% Direct webdrivermanager-4.3.1.jar webdrivermanager-4.3.1.jar 6.1.0 None
CVE-2024-25710

Path to dependency file: /pom.xml

Path to vulnerable library: /pom.xml

Dependency Hierarchy:

-> ❌ commons-compress-1.21.jar (Vulnerable Library)

High 8.1 Not Defined 0.441% Direct commons-compress-1.21.jar commons-compress-1.21.jar 1.26.0 None
CVE-2024-26308

Path to dependency file: /pom.xml

Path to vulnerable library: /pom.xml

Dependency Hierarchy:

-> ❌ commons-compress-1.21.jar (Vulnerable Library)

Medium 5.5 Not Defined 0.898% Direct commons-compress-1.21.jar commons-compress-1.21.jar 1.26.0 None

✔️ Remediated vulnerabilities:

Vulnerability Vulnerable Library
CVE-2022-31692 spring-security-core-5.7.2.jar
CVE-2026-54512 jackson-databind-2.13.3.jar
CVE-2026-40973 spring-boot-2.7.1.jar
CVE-2024-38809 spring-web-5.3.21.jar
CVE-2022-25857 snakeyaml-1.30.jar
CVE-2024-9823 jetty-servlets-9.4.48.v20220622.jar
CVE-2023-26049 jetty-server-9.4.48.v20220622.jar
CVE-2023-3223 undertow-servlet-2.2.18.Final.jar
CVE-2026-40975 spring-boot-2.7.1.jar
CVE-2023-24998 commons-fileupload-1.4.jar
CVE-2021-23369 handlebars-4.0.7.jar
CVE-2026-41853 spring-webmvc-5.3.21.jar
CVE-2024-38820 spring-context-5.3.21.jar
CVE-2026-41841 spring-webmvc-5.3.21.jar
CVE-2025-9784 undertow-core-2.2.18.Final.jar
CVE-2023-4639 undertow-core-2.2.18.Final.jar
CVE-2023-40167 jetty-http-9.4.48.v20220622.jar
CVE-2026-41706 spring-security-web-5.7.2.jar
CVE-2024-38828 spring-webmvc-5.3.21.jar
CVE-2024-38816 spring-webmvc-5.3.21.jar
CVE-2024-6763 jetty-http-9.4.48.v20220622.jar
CVE-2026-22745 spring-webmvc-5.3.21.jar
CVE-2026-41844 spring-webmvc-5.3.21.jar
CVE-2022-38752 snakeyaml-1.30.jar
CVE-2023-20862 spring-security-core-5.7.2.jar
CVE-2026-41846 spring-webmvc-5.3.21.jar
CVE-2024-38827 spring-security-core-5.7.2.jar
CVE-2025-41242 spring-webmvc-5.3.21.jar
CVE-2024-22262 spring-web-5.3.21.jar
CVE-2023-38286 thymeleaf-3.0.15.RELEASE.jar
CVE-2026-41001 spring-boot-autoconfigure-2.7.1.jar
CVE-2026-22735 spring-webmvc-5.3.21.jar
CVE-2024-38819 spring-webmvc-5.3.21.jar
CVE-2024-13009 jetty-server-9.4.48.v20220622.jar
CVE-2024-22259 spring-web-5.3.21.jar
CVE-2026-10050 jetty-security-9.4.48.v20220622.jar
WS-2023-0236 jetty-xml-9.4.48.v20220622.jar
CVE-2026-40992 spring-boot-autoconfigure-2.7.1.jar
CVE-2026-40478 thymeleaf-3.0.15.RELEASE.jar
WS-2022-0468 jackson-core-2.13.3.jar
CVE-2026-41716 spring-data-commons-2.7.1.jar
CVE-2022-1259 undertow-core-2.2.18.Final.jar
CVE-2026-40977 spring-boot-2.7.1.jar
CVE-2026-19879 undertow-core-2.2.18.Final.jar
CVE-2024-31573 xmlunit-core-2.9.0.jar
CVE-2022-38749 snakeyaml-1.30.jar
CVE-2022-38751 snakeyaml-1.30.jar
CVE-2024-38828 spring-core-5.3.21.jar
CVE-2026-41848 spring-core-5.3.21.jar
CVE-2023-36479 jetty-servlets-9.4.48.v20220622.jar
CVE-2024-1635 undertow-core-2.2.18.Final.jar
CVE-2024-3653 undertow-servlet-2.2.18.Final.jar
CVE-2024-38808 spring-expression-5.3.21.jar
CVE-2026-41721 spring-data-commons-2.7.1.jar
CVE-2026-19880 logback-classic-1.2.11.jar
CVE-2024-38821 spring-security-web-5.7.2.jar
CVE-2026-22740 spring-web-5.3.21.jar
CVE-2024-38827 spring-security-crypto-5.7.2.jar
CVE-2026-0603 hibernate-core-5.6.9.Final.jar
CVE-2023-26049 jetty-http-9.4.48.v20220622.jar
CVE-2022-4492 undertow-core-2.2.18.Final.jar
CVE-2026-41843 spring-webmvc-5.3.21.jar
CVE-2026-6790 jetty-server-9.4.48.v20220622.jar
CVE-2023-20862 spring-security-web-5.7.2.jar
CVE-2024-6763 jetty-server-9.4.48.v20220622.jar
CVE-2025-48924 commons-lang3-3.12.0.jar
CVE-2025-22235 spring-boot-actuator-autoconfigure-2.7.1.jar
CVE-2026-40478 thymeleaf-spring5-3.0.15.RELEASE.jar
CVE-2026-41845 spring-web-5.3.21.jar
CVE-2026-59295 micrometer-core-1.9.1.jar
CVE-2023-20883 spring-boot-autoconfigure-2.7.1.jar
CVE-2026-47838 spring-security-web-5.7.2.jar
CVE-2024-38827 spring-security-config-5.7.2.jar
CVE-2026-15561 undertow-core-2.2.18.Final.jar
CVE-2023-20861 spring-expression-5.3.21.jar
CVE-2023-26048 jetty-server-9.4.48.v20220622.jar
CVE-2024-6162 undertow-core-2.2.18.Final.jar
CVE-2026-59296 micrometer-core-1.9.1.jar
CVE-2026-41901 thymeleaf-spring5-3.0.15.RELEASE.jar
CVE-2024-38820 spring-web-5.3.21.jar
CVE-2026-40477 thymeleaf-spring5-3.0.15.RELEASE.jar
CVE-2026-49844 log4j-api-2.17.2.jar
CVE-2026-40974 spring-boot-autoconfigure-2.7.1.jar
CVE-2026-1225 logback-core-1.2.11.jar
CVE-2026-41845 spring-webmvc-5.3.21.jar
CVE-2026-55760 handlebars-4.0.7.jar
CVE-2026-2332 jetty-http-9.4.48.v20220622.jar
CVE-2025-22228 spring-security-crypto-5.7.2.jar
CVE-2026-41711 spring-data-commons-2.7.1.jar
CVE-2026-22746 spring-security-core-5.7.2.jar
CVE-2016-1000027 spring-web-5.3.21.jar
CVE-2026-41853 spring-web-5.3.21.jar
CVE-2023-36478 jetty-http-9.4.48.v20220622.jar
CVE-2026-22735 spring-web-5.3.21.jar
CVE-2024-7885 undertow-core-2.2.18.Final.jar
CVE-2026-41840 spring-web-5.3.21.jar
CVE-2026-41849 spring-expression-5.3.21.jar
CVE-2026-22732 spring-security-web-5.7.2.jar
CVE-2024-5971 undertow-core-2.2.18.Final.jar
CVE-2025-41242 spring-beans-5.3.21.jar
CVE-2025-12543 undertow-core-2.2.18.Final.jar
CVE-2025-41249 spring-core-5.3.21.jar
CVE-2026-41842 spring-webmvc-5.3.21.jar
CVE-2022-2053 undertow-core-2.2.18.Final.jar
CVE-2025-22233 spring-context-5.3.21.jar
CVE-2023-1973 undertow-core-2.2.18.Final.jar
CVE-2026-22733 spring-boot-actuator-autoconfigure-2.7.1.jar
CVE-2022-41854 snakeyaml-1.30.jar
CVE-2022-38750 snakeyaml-1.30.jar
CVE-2024-12798 logback-core-1.2.11.jar
CVE-2023-34055 spring-boot-actuator-2.7.1.jar
CVE-2026-24400 assertj-core-3.22.0.jar
CVE-2023-20863 spring-expression-5.3.21.jar
CVE-2026-15554 undertow-core-2.2.18.Final.jar
CVE-2024-38828 spring-web-5.3.21.jar
CVE-2026-54513 jackson-databind-2.13.3.jar
CVE-2023-6378 logback-core-1.2.11.jar
CVE-2025-48976 commons-fileupload-1.4.jar
CVE-2023-20860 spring-webmvc-5.3.21.jar
CVE-2026-22737 spring-webmvc-5.3.21.jar
CVE-2026-22733 spring-boot-starter-actuator-2.7.1.jar
CVE-2024-22257 spring-security-core-5.7.2.jar
CVE-2025-52999 jackson-core-2.13.3.jar
CVE-2026-41901 thymeleaf-3.0.15.RELEASE.jar
CVE-2026-40984 micrometer-core-1.9.1.jar
CVE-2024-12798 logback-classic-1.2.11.jar
CVE-2026-13006 logback-core-1.2.11.jar
CVE-2023-5685 xnio-api-3.8.7.Final.jar
CVE-2024-4027 undertow-core-2.2.18.Final.jar
CVE-2026-10532 logback-core-1.2.11.jar
CVE-2025-11143 jetty-http-9.4.48.v20220622.jar
CVE-2026-9828 logback-core-1.2.11.jar
CVE-2022-31692 spring-security-web-5.7.2.jar
CVE-2024-38827 spring-security-web-5.7.2.jar
CVE-2026-41852 spring-expression-5.3.21.jar
CVE-2026-41839 spring-web-5.3.21.jar
CVE-2022-42004 jackson-databind-2.13.3.jar
CVE-2026-15565 undertow-websockets-jsr-2.2.18.Final.jar
CVE-2024-12801 logback-core-1.2.11.jar
CVE-2022-1471 snakeyaml-1.30.jar
CVE-2023-20873 spring-boot-actuator-autoconfigure-2.7.1.jar
CVE-2026-47838 spring-security-config-5.7.2.jar
CVE-2024-3653 undertow-core-2.2.18.Final.jar
CVE-2022-0084 xnio-api-3.8.7.Final.jar
CVE-2026-54514 jackson-databind-2.13.3.jar
CVE-2026-40477 thymeleaf-3.0.15.RELEASE.jar
CVE-2023-34034 spring-security-config-5.7.2.jar
CVE-2026-41850 spring-expression-5.3.21.jar
CVE-2024-1459 undertow-core-2.2.18.Final.jar
CVE-2026-50193 jackson-databind-2.13.3.jar
CVE-2024-3884 undertow-core-2.2.18.Final.jar
CVE-2024-38820 spring-core-5.3.21.jar
CVE-2025-22235 spring-boot-2.7.1.jar
CVE-2023-5379 undertow-core-2.2.18.Final.jar
CVE-2026-22741 spring-webmvc-5.3.21.jar
CVE-2023-1108 undertow-core-2.2.18.Final.jar
CVE-2025-11226 logback-core-1.2.11.jar
CVE-2022-42003 jackson-databind-2.13.3.jar
CVE-2024-8184 jetty-server-9.4.48.v20220622.jar
CVE-2023-1370 json-smart-2.4.8.jar
CVE-2024-22243 spring-web-5.3.21.jar
CVE-2023-6378 logback-classic-1.2.11.jar
CVE-2023-51074 json-path-2.7.0.jar
CVE-2026-54515 jackson-databind-2.13.3.jar
CVE-2026-41851 spring-expression-5.3.21.jar
CVE-2024-38820 spring-webmvc-5.3.21.jar

Base branch total remaining vulnerabilities: 231
Base branch commit: c84be84af55fb04e04baf4725d37d15807a4e6da


Total libraries scanned: 27

Scan token: 32a34921dcb34fd6a4863074118ec5fb