Skip to content

Update dependency bunyan to v1.8.15

9afeeac
Select commit
Loading
Failed to load commit list.
Open

Update dependency bunyan to v1.8.15 #11

Update dependency bunyan to v1.8.15
9afeeac
Select commit
Loading
Failed to load commit list.
Dev - Mend for GitHub.com / Mend Security Check failed Mar 27, 2026 in 1m 52s

Security Report

You have successfully remediated 9 vulnerabilities, but introduced 6 new vulnerabilities in this branch.

❌ New vulnerabilities:

Vulnerability Severity CVSS Score Vulnerable Library Direct Library Suggested Fix Issue Reachability
CVE-607537-903744

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> request-2.88.2.tgz (Root Library)

   -> har-validator-5.1.5.tgz

     -> ❌ ajv-6.12.6.tgz (Vulnerable Library)

Critical 9.8 Transitive ajv-6.12.6.tgz request-2.88.2.tgz #7

Reachable

CVE-2026-33671

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> snyk-1.434.3.tgz (Root Library)

   -> micromatch-4.0.2.tgz

     -> ❌ picomatch-2.2.2.tgz (Vulnerable Library)

High 7.5 Transitive picomatch-2.2.2.tgz snyk-1.434.3.tgz Transitive Upgrade to version picomatch - 4.0.4 or greater #2

Reachable

CVE-2026-33672

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> snyk-1.434.3.tgz (Root Library)

   -> micromatch-4.0.2.tgz

     -> ❌ picomatch-2.2.2.tgz (Vulnerable Library)

Medium 5.3 Transitive picomatch-2.2.2.tgz snyk-1.434.3.tgz Transitive Upgrade to version picomatch - 3.0.2 or greater #2

Reachable

CVE-2026-33916

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> ❌ handlebars-4.6.0.tgz (Vulnerable Library)

Medium 4.7 Direct handlebars-4.6.0.tgz handlebars-4.6.0.tgz Upgrade to version handlebars - 4.7.9 or greater #3

Reachable

CVE-2026-33532

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> snyk-1.434.3.tgz (Root Library)

   -> snyk-nodejs-lockfile-parser-1.30.1.tgz

     -> ❌ yaml-1.10.0.tgz (Vulnerable Library)

Medium 4.3 Transitive yaml-1.10.0.tgz snyk-1.434.3.tgz Transitive Upgrade to version yaml - 2.8.3 or greater #2

Unreachable

CVE-2026-26996

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> bunyan-1.8.15.tgz (Root Library)

   -> mv-2.1.1.tgz

     -> rimraf-2.4.5.tgz

       -> glob-6.0.4.tgz

         -> ❌ minimatch-3.1.5.tgz (Vulnerable Library)

High 7.5 Transitive minimatch-3.1.5.tgz bunyan-1.8.15.tgz Transitive 10.2.1 None

✔️ Remediated vulnerabilities:

Vulnerability Vulnerable Library
CVE-2022-24785 moment-2.29.1.tgz
GHSA-8x6c-cv3v-vp6g cacheable-request-6.1.0.tgz
CVE-2025-5889 brace-expansion-1.1.8.tgz
CVE-2022-31129 moment-2.29.1.tgz
GHSA-35jh-r3h4-6jhm lodash-4.17.20.tgz
CVE-2022-25881 http-cache-semantics-4.1.0.tgz
GHSA-7fhm-mqm4-2wp7 minimist-1.2.0.tgz
GHSA-8x6c-cv3v-vp6g cacheable-request-7.0.1.tgz
GHSA-7fhm-mqm4-2wp7 minimist-0.0.8.tgz

Base branch total remaining vulnerabilities: 113
Base branch commit: 9c63f80602d19103529ef153178d231f027b8634


Total libraries scanned: 555

Scan token: 09064cd1d67b4c2a87ef2a4a1a691bcf