Update dependency mongoose to v6 #124
Open
Dev - Mend for GitHub.com / Mend Security Check
failed
Feb 25, 2026 in 23m 45s
Security Report
You have successfully remediated 5 vulnerabilities, but introduced 1 new vulnerabilities in this branch.
❌ New vulnerabilities:
| Vulnerability | Severity | Vulnerable Library | Direct Library | Suggested Fix | Issue | Reachability | |
|---|---|---|---|---|---|---|---|
CVE-2024-53900Path to dependency file: /baak-dataload-sql/package.json Path to vulnerable library: /baak-dataload-sql/package.json Dependency Hierarchy: -> ❌ mongoose-6.13.5.tgz (Vulnerable Library) |
9.1 | Direct mongoose-6.13.5.tgz |
mongoose-6.13.5.tgz | mongoose - 7.8.3,mongoose - 6.13.5,mongoose - 8.8.3 | None |
✔️ Remediated vulnerabilities:
| Vulnerability | Vulnerable Library |
|---|---|
| CVE-2025-23061 | mongoose-5.13.14.tgz |
| GHSA-8x6c-cv3v-vp6g | cacheable-request-6.1.0.tgz |
| CVE-2022-2564 | mongoose-5.13.14.tgz |
| CVE-2024-53900 | mongoose-5.13.14.tgz |
| CVE-2022-25881 | http-cache-semantics-4.1.0.tgz |
Base branch total remaining vulnerabilities: 104
Base branch commit: 6fe0ef7fd3ca6bf6339b996c7cbdf6e38c5a74c7
Total libraries scanned: 1997
Scan token: 2daee692c2114a019364cd0d62e05eed
Loading