chore(deps): update dependency lint-staged to v15.3.0 #10
Security Report
The Security Check found 13 vulnerabilities.
CVE | Severity | CVSS Score | Exploit Maturity | EPSS | Vulnerable Library | Suggested Fix | Issue |
---|---|---|---|---|---|---|---|
CVE-2024-52798Path to dependency file: /package.json Path to vulnerable library: /package.json Dependency Hierarchy: -> probot-13.3.6.tgz (Root Library) -> express-4.19.2.tgz -> ❌ path-to-regexp-0.1.7.tgz (Vulnerable Library) |
High | 7.5 | Not Defined | 0.0% | path-to-regexp-0.1.7.tgz | Upgrade to version: path-to-regexp - 0.1.12 | None |
CVE-2024-51479Path to dependency file: /package.json Path to vulnerable library: /package.json Dependency Hierarchy: -> ❌ next-14.2.5.tgz (Vulnerable Library) |
High | 7.5 | Not Defined | 0.0% | next-14.2.5.tgz | Upgrade to version: next - 14.2.15 | None |
CVE-2024-46982Path to dependency file: /package.json Path to vulnerable library: /package.json Dependency Hierarchy: -> ❌ next-14.2.5.tgz (Vulnerable Library) |
High | 7.5 | Not Defined | 0.0% | next-14.2.5.tgz | Upgrade to version: next - 13.5.7,14.2.10 | None |
CVE-2024-45590Path to dependency file: /package.json Path to vulnerable library: /package.json Dependency Hierarchy: -> probot-13.3.6.tgz (Root Library) -> express-4.19.2.tgz -> ❌ body-parser-1.20.2.tgz (Vulnerable Library) |
High | 7.5 | Not Defined | 0.0% | body-parser-1.20.2.tgz | Upgrade to version: body-parser - 1.20.3 | None |
CVE-2024-45296Path to dependency file: /package.json Path to vulnerable library: /package.json Dependency Hierarchy: -> probot-13.3.6.tgz (Root Library) -> express-4.19.2.tgz -> ❌ path-to-regexp-0.1.7.tgz (Vulnerable Library) |
High | 7.5 | Not Defined | 0.0% | path-to-regexp-0.1.7.tgz | Upgrade to version: path-to-regexp - 0.1.10,1.9.0,3.3.0,6.3.0,8.0.0 | None |
CVE-2024-47831Path to dependency file: /package.json Path to vulnerable library: /package.json Dependency Hierarchy: -> ❌ next-14.2.5.tgz (Vulnerable Library) |
Medium | 5.9 | Not Defined | 0.0% | next-14.2.5.tgz | Upgrade to version: next - 14.2.7 | None |
CVE-2024-47764Path to dependency file: /package.json Path to vulnerable library: /package.json Dependency Hierarchy: -> probot-13.3.6.tgz (Root Library) -> express-4.19.2.tgz -> ❌ cookie-0.6.0.tgz (Vulnerable Library) |
Medium | 5.3 | Not Defined | 0.0% | cookie-0.6.0.tgz | Upgrade to version: cookie - 0.7.0 | None |
CVE-2024-47764Path to dependency file: /package.json Path to vulnerable library: /package.json Dependency Hierarchy: -> probot-13.3.6.tgz (Root Library) -> pino-2.3.5.tgz -> node-6.19.7.tgz -> ❌ cookie-0.4.2.tgz (Vulnerable Library) |
Medium | 5.3 | Not Defined | 0.0% | cookie-0.4.2.tgz | Upgrade to version: cookie - 0.7.0 | None |
CVE-2024-47764Path to dependency file: /package.json Path to vulnerable library: /package.json Dependency Hierarchy: -> next-auth-4.24.7.tgz (Root Library) -> ❌ cookie-0.5.0.tgz (Vulnerable Library) |
Medium | 5.3 | Not Defined | 0.0% | cookie-0.5.0.tgz | Upgrade to version: cookie - 0.7.0 | None |
CVE-2024-43800Path to dependency file: /package.json Path to vulnerable library: /package.json Dependency Hierarchy: -> probot-13.3.6.tgz (Root Library) -> express-4.19.2.tgz -> ❌ serve-static-1.15.0.tgz (Vulnerable Library) |
Medium | 5.0 | Not Defined | 0.1% | serve-static-1.15.0.tgz | Upgrade to version: serve-static - 1.16.0,2.1.0 | None |
CVE-2024-43799Path to dependency file: /package.json Path to vulnerable library: /package.json Dependency Hierarchy: -> probot-13.3.6.tgz (Root Library) -> express-4.19.2.tgz -> ❌ send-0.18.0.tgz (Vulnerable Library) |
Medium | 5.0 | Not Defined | 0.0% | send-0.18.0.tgz | Upgrade to version: send - 0.19.0 | None |
CVE-2024-43796Path to dependency file: /package.json Path to vulnerable library: /package.json Dependency Hierarchy: -> probot-13.3.6.tgz (Root Library) -> ❌ express-4.19.2.tgz (Vulnerable Library) |
Medium | 5.0 | Not Defined | 0.0% | express-4.19.2.tgz | Upgrade to version: express - 4.20.0,5.0.0 | None |
CVE-2024-55565Path to dependency file: /package.json Path to vulnerable library: /package.json Dependency Hierarchy: -> next-14.2.5.tgz (Root Library) -> postcss-8.4.31.tgz -> ❌ nanoid-3.3.7.tgz (Vulnerable Library) |
Medium | 4.3 | Not Defined | 0.0% | nanoid-3.3.7.tgz | Upgrade to version: nanoid - 3.3.8,5.0.9 | None |
Total libraries scanned: 516
Scan token: 905177bd07d14f208812ce58f7c7a2d0