Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Snyk] Security upgrade mongoose from 5.13.14 to 5.13.20 #39

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

fix: package.json to reduce vulnerabilities

7748e69
Select commit
Loading
Failed to load commit list.
Open

[Snyk] Security upgrade mongoose from 5.13.14 to 5.13.20 #39

fix: package.json to reduce vulnerabilities
7748e69
Select commit
Loading
Failed to load commit list.
Mend Bolt for GitHub / WhiteSource Security Check failed Jul 17, 2023 in 8m 23s

Security Report

3 new vulnerabilities were introduced in this branch.

❌ New vulnerabilities:

CVE Severity CVSS Score Vulnerable Library Suggested Fix Issue
CVE-2022-25883

Dependency Hierarchy:

-> preset-env-7.18.6.tgz (Root Library)

   -> ❌ semver-6.3.0.tgz (Vulnerable Library)

Medium 5.3 semver-6.3.0.tgz Upgrade to version: semver - 7.5.2 None
CVE-2022-25883

Dependency Hierarchy:

-> preset-env-7.18.6.tgz (Root Library)

   -> core-js-compat-3.22.1.tgz

     -> ❌ semver-7.0.0.tgz (Vulnerable Library)

Medium 5.3 semver-7.0.0.tgz Upgrade to version: semver - 7.5.2 None
CVE-2022-25883

Dependency Hierarchy:

-> cli-7.18.6.tgz (Root Library)

   -> make-dir-2.1.0.tgz

     -> ❌ semver-5.7.1.tgz (Vulnerable Library)

Medium 5.3 semver-5.7.1.tgz Upgrade to version: semver - 7.5.2 None

Base branch total remaining vulnerabilities: 1
Base branch commit: 7b5fe0215318641675b73ec5ee42c2571053b042


Total libraries scanned: 326

Scan token: 16beb5507f2a4ec48eb612443138d5c4