[Snyk] Upgrade: react, react-dom #868
Security Report
3 new vulnerabilities were introduced in this branch.
❌ New vulnerabilities:
CVE | Severity | CVSS Score | Vulnerable Library | Suggested Fix | Issue |
---|---|---|---|---|---|
CVE-2024-4068Path to dependency file: /dependentApp/package.json Path to vulnerable library: /dependentApp/node_modules/braces/package.json Dependency Hierarchy: -> webpack-dev-server-5.0.4.tgz (Root Library) -> http-proxy-middleware-2.0.4.tgz -> micromatch-4.0.4.tgz -> ❌ braces-3.0.2.tgz (Vulnerable Library) |
High | 7.5 | braces-3.0.2.tgz | Upgrade to version: braces - 3.0.3 | None |
CVE-2024-29041Path to dependency file: /dependentApp/package.json Path to vulnerable library: /dependentApp/node_modules/express/package.json Dependency Hierarchy: -> webpack-dev-server-5.0.4.tgz (Root Library) -> ❌ express-4.17.3.tgz (Vulnerable Library) |
Medium | 6.1 | express-4.17.3.tgz | Upgrade to version: express - 4.19.0 | None |
CVE-2024-4067Path to dependency file: /dependentApp/package.json Path to vulnerable library: /dependentApp/node_modules/micromatch/package.json Dependency Hierarchy: -> webpack-dev-server-5.0.4.tgz (Root Library) -> http-proxy-middleware-2.0.4.tgz -> ❌ micromatch-4.0.4.tgz (Vulnerable Library) |
Medium | 5.3 | micromatch-4.0.4.tgz | Upgrade to version: micromatch - 4.0.6 | None |
Base branch total remaining vulnerabilities: 3
Base branch commit: 846821dde7052c549b51750f571bf6c62c828b97
Total libraries scanned: 256
Scan token: a7e5aec6e8a04b85a30bbd848221c02a