Skip to content
This repository has been archived by the owner on Nov 30, 2023. It is now read-only.

Update dependency handlebars to v4 #17

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Update dependency handlebars to v4

60172b4
Select commit
Loading
Failed to load commit list.
Open

Update dependency handlebars to v4 #17

Update dependency handlebars to v4
60172b4
Select commit
Loading
Failed to load commit list.
Mend for GitHub.com / Mend Security Check failed Nov 29, 2023 in 1h 46m 54s

Security Report

You have successfully remediated 9 vulnerabilities, but introduced 5 new vulnerabilities in this branch.

❌ New vulnerabilities:

CVE Severity CVSS Score Vulnerable Library Suggested Fix Issue
CVE-2022-37598

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> i18nliner-canvas-0.0.1.tgz (Root Library)

   -> handlebars-4.6.0.tgz

     -> ❌ uglify-js-3.7.0.tgz (Vulnerable Library)

Critical 9.8 uglify-js-3.7.0.tgz Upgrade to version: uglify-js - 3.13.10 None
CVE-2021-44906

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> i18nliner-canvas-0.0.1.tgz (Root Library)

   -> handlebars-4.6.0.tgz

     -> optimist-0.6.1.tgz

       -> ❌ minimist-0.0.10.tgz (Vulnerable Library)

Critical 9.8 minimist-0.0.10.tgz Upgrade to version: minimist - 0.2.4,1.2.6 None
CVE-2021-23383

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> i18nliner-canvas-0.0.1.tgz (Root Library)

   -> ❌ handlebars-4.6.0.tgz (Vulnerable Library)

Critical 9.8 handlebars-4.6.0.tgz Upgrade to version: handlebars - 4.7.7 None
CVE-2021-23369

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> i18nliner-canvas-0.0.1.tgz (Root Library)

   -> ❌ handlebars-4.6.0.tgz (Vulnerable Library)

Critical 9.8 handlebars-4.6.0.tgz Upgrade to version: com.github.jknack:handlebars:4.2.0, handlebars - 4.7.7 None
CVE-2020-7598

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> i18nliner-canvas-0.0.1.tgz (Root Library)

   -> handlebars-4.6.0.tgz

     -> optimist-0.6.1.tgz

       -> ❌ minimist-0.0.10.tgz (Vulnerable Library)

Medium 5.6 minimist-0.0.10.tgz Upgrade to version: minimist - 0.2.1,1.2.3 None

✔️ Remediated vulnerabilities:

CVE Vulnerable Library
CVE-2019-20920 handlebars-1.3.0.tgz
WS-2019-0103 handlebars-1.3.0.tgz
CVE-2015-8861 handlebars-1.3.0.tgz
CVE-2015-8858 uglify-js-2.3.6.tgz
CVE-2021-23369 handlebars-1.3.0.tgz
WS-2020-0450 handlebars-1.3.0.tgz
CVE-2015-8857 uglify-js-2.3.6.tgz
CVE-2021-23383 handlebars-1.3.0.tgz
CVE-2019-19919 handlebars-1.3.0.tgz

Base branch total remaining vulnerabilities: 265
Base branch commit: 1a4b0fc08231f6e699600f99972cf70d042154ec


Total libraries scanned: 1529

Scan token: 88c1e5e2b4dc454db828cf58920fe6b1