Update dependency sanitize-html to v2 - autoclosed #13
Security Report
You have successfully remediated 35 vulnerabilities, but introduced 2 new vulnerabilities in this branch.
❌ New vulnerabilities:
CVE | Severity | Vulnerable Library | Suggested Fix | Issue | |
---|---|---|---|---|---|
CVE-2024-29415Path to dependency file: /package.json Path to vulnerable library: /node_modules/ip/package.json Dependency Hierarchy: -> express-ipfilter-1.3.2.tgz (Root Library) -> ❌ ip-2.0.1.tgz (Vulnerable Library) |
9.1 | ip-2.0.1.tgz | None | ||
CVE-2024-47764Path to dependency file: /package.json Path to vulnerable library: /node_modules/engine.io/node_modules/cookie/package.json Dependency Hierarchy: -> socket.io-3.1.2.tgz (Root Library) -> engine.io-4.1.2.tgz -> ❌ cookie-0.4.2.tgz (Vulnerable Library) |
5.3 | cookie-0.4.2.tgz | Upgrade to version: cookie - 0.7.0 | #7 |
✔️ Remediated vulnerabilities:
CVE | Vulnerable Library |
---|---|
CVE-2018-16487 | lodash-2.4.2.tgz |
CVE-2024-28863 | tar-6.1.13.tgz |
CVE-2024-29041 | express-4.18.2.tgz |
CVE-2024-45590 | body-parser-1.20.2.tgz |
CVE-2020-28500 | lodash-2.4.2.tgz |
CVE-2023-42282 | ip-2.0.0.tgz |
CVE-2023-26132 | dottie-2.0.3.tgz |
CVE-2023-26115 | word-wrap-1.2.3.tgz |
CVE-2024-29415 | ip-2.0.0.tgz |
CVE-2017-16016 | sanitize-html-1.4.2.tgz |
CVE-2020-8203 | lodash-2.4.2.tgz |
CVE-2021-26540 | sanitize-html-1.4.2.tgz |
CVE-2022-25883 | semver-6.3.0.tgz |
CVE-2024-47764 | cookie-0.5.0.tgz |
CVE-2024-45296 | path-to-regexp-0.1.7.tgz |
CVE-2021-23337 | lodash-2.4.2.tgz |
CVE-2024-43796 | express-4.18.2.tgz |
CVE-2023-42282 | ip-1.1.8.tgz |
CVE-2022-25887 | sanitize-html-1.4.2.tgz |
CVE-2024-47764 | cookie-0.4.1.tgz |
CVE-2022-25883 | semver-5.7.1.tgz |
CVE-2024-21501 | sanitize-html-1.4.2.tgz |
CVE-2016-1000237 | sanitize-html-1.4.2.tgz |
CVE-2024-29415 | ip-1.1.8.tgz |
CVE-2019-1010266 | lodash-2.4.2.tgz |
CVE-2024-4067 | micromatch-4.0.5.tgz |
CVE-2018-3721 | lodash-2.4.2.tgz |
CVE-2024-4068 | braces-3.0.2.tgz |
CVE-2021-26539 | sanitize-html-1.4.2.tgz |
CVE-2024-52798 | path-to-regexp-0.1.7.tgz |
CVE-2024-45590 | body-parser-1.20.1.tgz |
CVE-2019-10744 | lodash-2.4.2.tgz |
CVE-2024-43800 | serve-static-1.15.0.tgz |
CVE-2024-43799 | send-0.18.0.tgz |
CVE-2022-25883 | semver-7.3.8.tgz |
Base branch total remaining vulnerabilities: 71
Base branch commit: null
Total libraries scanned: 1010
Scan token: 003d91f603524f72abc586f5c1602c18