Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

fix(deps): update react-router monorepo to v6.23.1 #416

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

fix(deps): update react-router monorepo to v6.23.1

2c8a7e3
Select commit
Failed to load commit list.
Open

fix(deps): update react-router monorepo to v6.23.1 #416

fix(deps): update react-router monorepo to v6.23.1
2c8a7e3
Select commit
Failed to load commit list.
Mend Bolt for GitHub / WhiteSource Security Check failed May 10, 2024 in 1h 8m 40s

Security Report

You have successfully remediated 19 vulnerabilities, but introduced 52 new vulnerabilities in this branch.

❌ New vulnerabilities:

CVE Severity CVSS Score Vulnerable Library Suggested Fix Issue
CVE-2023-26136

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> react-scripts-4.0.3.tgz (Root Library)

   -> jest-26.6.0.tgz

     -> jest-cli-26.6.3.tgz

       -> jest-config-26.6.3.tgz

         -> jest-environment-jsdom-26.6.2.tgz

           -> jsdom-16.4.0.tgz

             -> ❌ tough-cookie-3.0.1.tgz (Vulnerable Library)

Critical 9.8 tough-cookie-3.0.1.tgz Upgrade to version: tough-cookie - 4.1.3 #572
CVE-2023-26136

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> react-scripts-4.0.3.tgz (Root Library)

   -> jest-26.6.0.tgz

     -> jest-cli-26.6.3.tgz

       -> jest-config-26.6.3.tgz

         -> jest-environment-jsdom-26.6.2.tgz

           -> jsdom-16.4.0.tgz

             -> request-promise-native-1.0.9.tgz

               -> ❌ tough-cookie-2.5.0.tgz (Vulnerable Library)

Critical 9.8 tough-cookie-2.5.0.tgz Upgrade to version: tough-cookie - 4.1.3 #572
CVE-2022-0691

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> react-scripts-4.0.3.tgz (Root Library)

   -> webpack-dev-server-3.11.1.tgz

     -> sockjs-client-1.5.0.tgz

       -> ❌ url-parse-1.5.1.tgz (Vulnerable Library)

Critical 9.8 url-parse-1.5.1.tgz Upgrade to version: url-parse - 1.5.9 #459
CVE-2021-3918

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> react-scripts-4.0.3.tgz (Root Library)

   -> jest-26.6.0.tgz

     -> jest-cli-26.6.3.tgz

       -> jest-config-26.6.3.tgz

         -> jest-environment-jsdom-26.6.2.tgz

           -> jsdom-16.4.0.tgz

             -> request-2.88.2.tgz

               -> http-signature-1.2.0.tgz

                 -> jsprim-1.4.1.tgz

                   -> ❌ json-schema-0.2.3.tgz (Vulnerable Library)

Critical 9.8 json-schema-0.2.3.tgz Upgrade to version: json-schema - 0.4.0 None
CVE-2020-7788

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> react-scripts-4.0.3.tgz (Root Library)

   -> react-dev-utils-11.0.3.tgz

     -> global-modules-2.0.0.tgz

       -> global-prefix-3.0.0.tgz

         -> ❌ ini-1.3.5.tgz (Vulnerable Library)

Critical 9.8 ini-1.3.5.tgz Upgrade to version: v1.3.6 #90
CVE-2022-1650

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> react-scripts-4.0.3.tgz (Root Library)

   -> webpack-dev-server-3.11.1.tgz

     -> sockjs-client-1.5.0.tgz

       -> ❌ eventsource-1.0.7.tgz (Vulnerable Library)

Critical 9.3 eventsource-1.0.7.tgz Upgrade to version: eventsource - 1.1.1,2.0.2 #488
CVE-2022-0686

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> react-scripts-4.0.3.tgz (Root Library)

   -> webpack-dev-server-3.11.1.tgz

     -> sockjs-client-1.5.0.tgz

       -> ❌ url-parse-1.5.1.tgz (Vulnerable Library)

Critical 9.1 url-parse-1.5.1.tgz Upgrade to version: url-parse - 1.5.8 #450
CVE-2023-45133

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> styled-components-5.3.3.tgz (Root Library)

   -> ❌ traverse-7.9.6.tgz (Vulnerable Library)

High 8.8 traverse-7.9.6.tgz Upgrade to version: @babel/traverse - 7.23.2 #561
CVE-2023-45133

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> react-scripts-4.0.3.tgz (Root Library)

   -> core-7.12.3.tgz

     -> ❌ traverse-7.13.0.tgz (Vulnerable Library)

High 8.8 traverse-7.13.0.tgz Upgrade to version: @babel/traverse - 7.23.2 #561
CVE-2021-37713

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> react-scripts-4.0.3.tgz (Root Library)

   -> terser-webpack-plugin-4.2.3.tgz

     -> cacache-15.0.5.tgz

       -> ❌ tar-6.1.0.tgz (Vulnerable Library)

High 8.6 tar-6.1.0.tgz Upgrade to version: tar - 4.4.18,5.0.10,6.1.9 #351
CVE-2021-37712

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> react-scripts-4.0.3.tgz (Root Library)

   -> terser-webpack-plugin-4.2.3.tgz

     -> cacache-15.0.5.tgz

       -> ❌ tar-6.1.0.tgz (Vulnerable Library)

High 8.6 tar-6.1.0.tgz Upgrade to version: tar - 4.4.18,5.0.10,6.1.9 #342
CVE-2021-37701

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> react-scripts-4.0.3.tgz (Root Library)

   -> terser-webpack-plugin-4.2.3.tgz

     -> cacache-15.0.5.tgz

       -> ❌ tar-6.1.0.tgz (Vulnerable Library)

High 8.6 tar-6.1.0.tgz Upgrade to version: tar - 4.4.16,5.0.8,6.1.7 #350
CVE-2021-32804

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> react-scripts-4.0.3.tgz (Root Library)

   -> terser-webpack-plugin-4.2.3.tgz

     -> cacache-15.0.5.tgz

       -> ❌ tar-6.1.0.tgz (Vulnerable Library)

High 8.1 tar-6.1.0.tgz Upgrade to version: tar - 3.2.2, 4.4.14, 5.0.6, 6.1.1 #348
CVE-2021-32803

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> react-scripts-4.0.3.tgz (Root Library)

   -> terser-webpack-plugin-4.2.3.tgz

     -> cacache-15.0.5.tgz

       -> ❌ tar-6.1.0.tgz (Vulnerable Library)

High 8.1 tar-6.1.0.tgz Upgrade to version: tar - 3.2.3, 4.4.15, 5.0.7, 6.1.2 #349
WS-2021-0152

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> react-scripts-4.0.3.tgz (Root Library)

   -> optimize-css-assets-webpack-plugin-5.0.4.tgz

     -> cssnano-4.1.10.tgz

       -> cssnano-preset-default-4.0.7.tgz

         -> postcss-colormin-4.0.3.tgz

           -> color-3.1.3.tgz

             -> ❌ color-string-1.5.4.tgz (Vulnerable Library)

High 7.5 color-string-1.5.4.tgz Upgrade to version: color-string - 1.5.5 #284
CVE-2022-25883

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> react-scripts-4.0.3.tgz (Root Library)

   -> sass-loader-10.1.1.tgz

     -> ❌ semver-7.3.4.tgz (Vulnerable Library)

High 7.5 semver-7.3.4.tgz Upgrade to version: semver - 5.7.2,6.3.1,7.5.2;org.webjars.npm:semver:7.5.2 #567
CVE-2022-25883

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> react-scripts-4.0.3.tgz (Root Library)

   -> ❌ semver-7.3.2.tgz (Vulnerable Library)

High 7.5 semver-7.3.2.tgz Upgrade to version: semver - 5.7.2,6.3.1,7.5.2;org.webjars.npm:semver:7.5.2 #567
CVE-2022-25858

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> react-scripts-4.0.3.tgz (Root Library)

   -> terser-webpack-plugin-4.2.3.tgz

     -> ❌ terser-5.6.0.tgz (Vulnerable Library)

High 7.5 terser-5.6.0.tgz Upgrade to version: terser - 4.8.1,5.14.2 #493
CVE-2022-24999

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> react-scripts-4.0.3.tgz (Root Library)

   -> jest-26.6.0.tgz

     -> jest-cli-26.6.3.tgz

       -> jest-config-26.6.3.tgz

         -> jest-environment-jsdom-26.6.2.tgz

           -> jsdom-16.4.0.tgz

             -> request-2.88.2.tgz

               -> ❌ qs-6.5.2.tgz (Vulnerable Library)

High 7.5 qs-6.5.2.tgz Upgrade to version: qs - 6.2.4,6.3.3,6.4.1,6.5.3,6.6.1,6.7.3,6.8.3,6.9.7,6.10.3 #568
CVE-2021-3777

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> react-scripts-4.0.3.tgz (Root Library)

   -> jest-26.6.0.tgz

     -> core-26.6.3.tgz

       -> jest-haste-map-26.6.2.tgz

         -> walker-1.0.7.tgz

           -> makeerror-1.0.11.tgz

             -> ❌ tmpl-1.0.4.tgz (Vulnerable Library)

High 7.5 tmpl-1.0.4.tgz Upgrade to version: tmpl - 1.0.5 #353
CVE-2021-29059

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> react-scripts-4.0.3.tgz (Root Library)

   -> optimize-css-assets-webpack-plugin-5.0.4.tgz

     -> cssnano-4.1.10.tgz

       -> cssnano-preset-default-4.0.7.tgz

         -> postcss-svgo-4.0.2.tgz

           -> ❌ is-svg-3.0.0.tgz (Vulnerable Library)

High 7.5 is-svg-3.0.0.tgz Upgrade to version: is-svg - 4.3.0 #288
CVE-2021-28092

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> react-scripts-4.0.3.tgz (Root Library)

   -> optimize-css-assets-webpack-plugin-5.0.4.tgz

     -> cssnano-4.1.10.tgz

       -> cssnano-preset-default-4.0.7.tgz

         -> postcss-svgo-4.0.2.tgz

           -> ❌ is-svg-3.0.0.tgz (Vulnerable Library)

High 7.5 is-svg-3.0.0.tgz Upgrade to version: v4.2.2 #194
CVE-2021-27290

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> react-scripts-4.0.3.tgz (Root Library)

   -> webpack-4.44.2.tgz

     -> terser-webpack-plugin-1.4.5.tgz

       -> cacache-12.0.4.tgz

         -> ❌ ssri-6.0.1.tgz (Vulnerable Library)

High 7.5 ssri-6.0.1.tgz Upgrade to version: ssri - 6.0.2,7.1.1,8.0.1 #195
CVE-2021-23382

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> react-scripts-4.0.3.tgz (Root Library)

   -> css-loader-4.3.0.tgz

     -> ❌ postcss-7.0.35.tgz (Vulnerable Library)

High 7.5 postcss-7.0.35.tgz Upgrade to version: postcss - 8.2.13 #243
CVE-2021-23382

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> react-scripts-4.0.3.tgz (Root Library)

   -> resolve-url-loader-3.1.2.tgz

     -> ❌ postcss-7.0.21.tgz (Vulnerable Library)

High 7.5 postcss-7.0.21.tgz Upgrade to version: postcss - 8.2.13 #243
CVE-2021-23382

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> react-scripts-4.0.3.tgz (Root Library)

   -> postcss-safe-parser-5.0.2.tgz

     -> ❌ postcss-8.2.6.tgz (Vulnerable Library)

High 7.5 postcss-8.2.6.tgz Upgrade to version: postcss - 8.2.13 #243
CVE-2021-23343

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> react-scripts-4.0.3.tgz (Root Library)

   -> resolve-1.18.1.tgz

     -> ❌ path-parse-1.0.6.tgz (Vulnerable Library)

High 7.5 path-parse-1.0.6.tgz Upgrade to version: path-parse - 1.0.7 #244
CVE-2020-28469

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> react-scripts-4.0.3.tgz (Root Library)

   -> eslint-7.20.0.tgz

     -> ❌ glob-parent-5.1.1.tgz (Vulnerable Library)

High 7.5 glob-parent-5.1.1.tgz Upgrade to version: glob-parent - 5.1.2 #279
CVE-2024-29180

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> react-scripts-4.0.3.tgz (Root Library)

   -> webpack-dev-server-3.11.1.tgz

     -> ❌ webpack-dev-middleware-3.7.3.tgz (Vulnerable Library)

High 7.4 webpack-dev-middleware-3.7.3.tgz Upgrade to version: webpack-dev-middleware - 5.3.4,6.1.2,7.1.0 None
CVE-2024-28863

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> react-scripts-4.0.3.tgz (Root Library)

   -> terser-webpack-plugin-4.2.3.tgz

     -> cacache-15.0.5.tgz

       -> ❌ tar-6.1.0.tgz (Vulnerable Library)

Medium 6.5 tar-6.1.0.tgz Upgrade to version: tar - 6.2.1 None
CVE-2024-28849

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> axios-0.24.0.tgz (Root Library)

   -> ❌ follow-redirects-1.14.5.tgz (Vulnerable Library)

Medium 6.5 follow-redirects-1.14.5.tgz Upgrade to version: follow-redirects - 1.15.6 None
CVE-2023-45857

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> ❌ axios-0.24.0.tgz (Vulnerable Library)

Medium 6.5 axios-0.24.0.tgz Upgrade to version: axios - 1.6.0 None
CVE-2022-0155

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> axios-0.24.0.tgz (Root Library)

   -> ❌ follow-redirects-1.14.5.tgz (Vulnerable Library)

Medium 6.5 follow-redirects-1.14.5.tgz Upgrade to version: follow-redirects - v1.14.7 #563
CVE-2021-23386

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> react-scripts-4.0.3.tgz (Root Library)

   -> webpack-dev-server-3.11.1.tgz

     -> bonjour-3.5.0.tgz

       -> multicast-dns-6.2.3.tgz

         -> ❌ dns-packet-1.3.1.tgz (Vulnerable Library)

Medium 6.5 dns-packet-1.3.1.tgz Upgrade to version: dns-packet - 5.2.2 #287
CVE-2024-29041

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> react-scripts-4.0.3.tgz (Root Library)

   -> webpack-dev-server-3.11.1.tgz

     -> ❌ express-4.17.1.tgz (Vulnerable Library)

Medium 6.1 express-4.17.1.tgz Upgrade to version: express - 4.19.0 None
CVE-2023-28155

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> react-scripts-4.0.3.tgz (Root Library)

   -> jest-26.6.0.tgz

     -> jest-cli-26.6.3.tgz

       -> jest-config-26.6.3.tgz

         -> jest-environment-jsdom-26.6.2.tgz

           -> jsdom-16.4.0.tgz

             -> ❌ request-2.88.2.tgz (Vulnerable Library)

Medium 6.1 request-2.88.2.tgz Upgrade to version: @cypress/request - 3.0.0 None
CVE-2023-26159

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> axios-0.24.0.tgz (Root Library)

   -> ❌ follow-redirects-1.14.5.tgz (Vulnerable Library)

Medium 6.1 follow-redirects-1.14.5.tgz Upgrade to version: follow-redirects - 1.15.4 #570
CVE-2022-0536

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> axios-0.24.0.tgz (Root Library)

   -> ❌ follow-redirects-1.14.5.tgz (Vulnerable Library)

Medium 5.9 follow-redirects-1.14.5.tgz Upgrade to version: follow-redirects - 1.14.8 #564
CVE-2021-24033

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> react-scripts-4.0.3.tgz (Root Library)

   -> ❌ react-dev-utils-11.0.3.tgz (Vulnerable Library)

Medium 5.6 react-dev-utils-11.0.3.tgz Upgrade to version: react-dev-utils-11.0.4 #179
CVE-2021-23566

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> react-scripts-4.0.3.tgz (Root Library)

   -> postcss-safe-parser-5.0.2.tgz

     -> postcss-8.2.6.tgz

       -> ❌ nanoid-3.1.30.tgz (Vulnerable Library)

Medium 5.5 nanoid-3.1.30.tgz Upgrade to version: nanoid - 3.1.31 #439
CVE-2023-44270

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> react-scripts-4.0.3.tgz (Root Library)

   -> postcss-safe-parser-5.0.2.tgz

     -> ❌ postcss-8.2.6.tgz (Vulnerable Library)

Medium 5.3 postcss-8.2.6.tgz Upgrade to version: postcss - 8.4.31 None
CVE-2022-0639

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> react-scripts-4.0.3.tgz (Root Library)

   -> webpack-dev-server-3.11.1.tgz

     -> sockjs-client-1.5.0.tgz

       -> ❌ url-parse-1.5.1.tgz (Vulnerable Library)

Medium 5.3 url-parse-1.5.1.tgz Upgrade to version: url-parse - 1.5.7 #451
CVE-2022-0512

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> react-scripts-4.0.3.tgz (Root Library)

   -> webpack-dev-server-3.11.1.tgz

     -> sockjs-client-1.5.0.tgz

       -> ❌ url-parse-1.5.1.tgz (Vulnerable Library)

Medium 5.3 url-parse-1.5.1.tgz Upgrade to version: url-parse - 1.5.6 #449
CVE-2021-3664

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> react-scripts-4.0.3.tgz (Root Library)

   -> webpack-dev-server-3.11.1.tgz

     -> sockjs-client-1.5.0.tgz

       -> ❌ url-parse-1.5.1.tgz (Vulnerable Library)

Medium 5.3 url-parse-1.5.1.tgz Upgrade to version: url-parse - 1.5.2 #343
CVE-2021-32640

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> react-scripts-4.0.3.tgz (Root Library)

   -> webpack-dev-server-3.11.1.tgz

     -> ❌ ws-6.2.1.tgz (Vulnerable Library)

Medium 5.3 ws-6.2.1.tgz Upgrade to version: 5.2.3,6.2.2,7.4.6 #282
CVE-2021-32640

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> react-scripts-4.0.3.tgz (Root Library)

   -> jest-26.6.0.tgz

     -> jest-cli-26.6.3.tgz

       -> jest-config-26.6.3.tgz

         -> jest-environment-jsdom-26.6.2.tgz

           -> jsdom-16.4.0.tgz

             -> ❌ ws-7.4.3.tgz (Vulnerable Library)

Medium 5.3 ws-7.4.3.tgz Upgrade to version: 5.2.3,6.2.2,7.4.6 #282
CVE-2021-29060

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> react-scripts-4.0.3.tgz (Root Library)

   -> optimize-css-assets-webpack-plugin-5.0.4.tgz

     -> cssnano-4.1.10.tgz

       -> cssnano-preset-default-4.0.7.tgz

         -> postcss-colormin-4.0.3.tgz

           -> color-3.1.3.tgz

             -> ❌ color-string-1.5.4.tgz (Vulnerable Library)

Medium 5.3 color-string-1.5.4.tgz Upgrade to version: color-string - 1.5.5 #281
CVE-2021-23368

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> react-scripts-4.0.3.tgz (Root Library)

   -> css-loader-4.3.0.tgz

     -> ❌ postcss-7.0.35.tgz (Vulnerable Library)

Medium 5.3 postcss-7.0.35.tgz Upgrade to version: postcss -8.2.10 #245
CVE-2021-23368

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> react-scripts-4.0.3.tgz (Root Library)

   -> resolve-url-loader-3.1.2.tgz

     -> ❌ postcss-7.0.21.tgz (Vulnerable Library)

Medium 5.3 postcss-7.0.21.tgz Upgrade to version: postcss -8.2.10 #245
CVE-2021-23368

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> react-scripts-4.0.3.tgz (Root Library)

   -> postcss-safe-parser-5.0.2.tgz

     -> ❌ postcss-8.2.6.tgz (Vulnerable Library)

Medium 5.3 postcss-8.2.6.tgz Upgrade to version: postcss -8.2.10 #245
CVE-2021-23364

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> react-scripts-4.0.3.tgz (Root Library)

   -> postcss-preset-env-6.7.0.tgz

     -> ❌ browserslist-4.16.3.tgz (Vulnerable Library)

Medium 5.3 browserslist-4.16.3.tgz Upgrade to version: browserslist - 4.16.5 #235
CVE-2021-23362

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> react-scripts-4.0.3.tgz (Root Library)

   -> eslint-plugin-import-2.22.1.tgz

     -> read-pkg-up-2.0.0.tgz

       -> read-pkg-2.0.0.tgz

         -> normalize-package-data-2.5.0.tgz

           -> ❌ hosted-git-info-2.8.8.tgz (Vulnerable Library)

Medium 5.3 hosted-git-info-2.8.8.tgz Upgrade to version: hosted-git-info - 2.8.9,3.0.8 #212

✔️ Remediated vulnerabilities:

CVE Vulnerable Library
CVE-2022-0536 follow-redirects-1.14.4.tgz
CVE-2022-25881 http-cache-semantics-4.1.0.tgz
CVE-2023-26159 follow-redirects-1.14.4.tgz
CVE-2022-1650 eventsource-1.1.0.tgz
CVE-2022-25883 semver-7.3.5.tgz
CVE-2024-28863 tar-6.1.11.tgz
CVE-2021-33502 normalize-url-3.3.0.tgz
CVE-2022-0155 follow-redirects-1.14.4.tgz
CVE-2022-0691 url-parse-1.5.3.tgz
CVE-2021-33502 normalize-url-1.9.1.tgz
CVE-2024-28849 follow-redirects-1.14.4.tgz
CVE-2022-33987 got-9.6.0.tgz
CVE-2022-0512 url-parse-1.5.3.tgz
CVE-2022-0639 url-parse-1.5.3.tgz
CVE-2022-0686 url-parse-1.5.3.tgz
CVE-2022-25858 terser-5.9.0.tgz
CVE-2023-26136 tough-cookie-4.0.0.tgz
CVE-2023-45133 traverse-7.15.4.tgz
CVE-2021-23566 nanoid-3.1.28.tgz

Base branch total remaining vulnerabilities: 58
Base branch commit: null


Total libraries scanned: 1581

Scan token: d3307f6e81c14f9ba260a21257d2bffc