Update dependency bcrypt to v4 #44
Open
Mend for GitHub.com / Mend Security Check
failed
Mar 16, 2026 in 2m 16s
Security Report
You have successfully remediated 6 vulnerabilities, but introduced 1 new vulnerabilities in this branch.
❌ New vulnerabilities:
| Vulnerability | Severity | Exploit Maturity | EPSS | Vulnerable Library | Direct Library | Suggested Fix | Issue | Reachability | |
|---|---|---|---|---|---|---|---|---|---|
CVE-2020-7689Path to dependency file: /package.json Path to vulnerable library: /node_modules/bcrypt/package.json Dependency Hierarchy: -> ❌ bcrypt-4.0.1.tgz (Vulnerable Library) |
5.9 | Not Defined | 0.1% | Direct bcrypt-4.0.1.tgz |
bcrypt-4.0.1.tgz | bcrypt - 5.0.0 | None |
✔️ Remediated vulnerabilities:
| Vulnerability | Vulnerable Library |
|---|---|
| CVE-2026-26996 | minimatch-3.1.2.tgz |
| CVE-2026-27904 | minimatch-3.1.2.tgz |
| CVE-2026-27837 | dottie-2.0.6.tgz |
| CVE-2026-2391 | qs-6.14.1.tgz |
| CVE-2020-7689 | bcrypt-3.0.8.tgz |
| CVE-2026-27903 | minimatch-3.1.2.tgz |
Base branch total remaining vulnerabilities: 44
Base branch commit: d2c070ac17e2f796a7e8cf5e4e36d9e9a9b6b951
Total libraries scanned: 276
Scan token: 567dd26a46a74e15beb127652d070962
Loading