Update dependency flow-typed to v3 #20
Security Report
You have successfully remediated 8 vulnerabilities, but introduced 4 new vulnerabilities in this branch.
❌ New vulnerabilities:
| Vulnerability | Severity | Vulnerable Library | Direct Library | Suggested Fix | Issue | Reachability | |
|---|---|---|---|---|---|---|---|
CVE-2025-25290Path to dependency file: /package.json Path to vulnerable library: /package.json,/api/package.json Dependency Hierarchy: -> flow-typed-3.9.0.tgz (Root Library) -> rest-18.12.0.tgz -> core-3.6.0.tgz -> ❌ request-5.6.3.tgz (Vulnerable Library) |
5.3 | Transitive request-5.6.3.tgz |
flow-typed-3.9.0.tgz | Transitive 8.4.1 |
None | ||
CVE-2025-25289Path to dependency file: /package.json Path to vulnerable library: /package.json,/api/package.json Dependency Hierarchy: -> flow-typed-3.9.0.tgz (Root Library) -> rest-18.12.0.tgz -> core-3.6.0.tgz -> ❌ request-error-2.1.0.tgz (Vulnerable Library) |
5.3 | Transitive request-error-2.1.0.tgz |
flow-typed-3.9.0.tgz | Transitive @octokit/request-error - 5.1.1,6.1.7 |
None | ||
CVE-2025-25288Path to dependency file: /package.json Path to vulnerable library: /package.json,/api/package.json Dependency Hierarchy: -> flow-typed-3.9.0.tgz (Root Library) -> rest-18.12.0.tgz -> ❌ plugin-paginate-rest-2.21.3.tgz (Vulnerable Library) |
5.3 | Transitive plugin-paginate-rest-2.21.3.tgz |
flow-typed-3.9.0.tgz | Transitive 9.2.2 |
None | ||
CVE-2025-25285Path to dependency file: /package.json Path to vulnerable library: /package.json,/api/package.json Dependency Hierarchy: -> flow-typed-3.9.0.tgz (Root Library) -> rest-18.12.0.tgz -> core-3.6.0.tgz -> graphql-4.8.0.tgz -> request-5.6.3.tgz -> ❌ endpoint-6.0.12.tgz (Vulnerable Library) |
5.3 | Transitive endpoint-6.0.12.tgz |
flow-typed-3.9.0.tgz | Transitive @octokit/endpoint - 9.0.6,10.1.3 |
None |
✔️ Remediated vulnerabilities:
| Vulnerability | Vulnerable Library |
|---|---|
| CVE-2021-3807 | ansi-regex-4.1.0.tgz |
| CVE-2020-7608 | yargs-parser-11.1.1.tgz |
| CVE-2025-25285 | endpoint-5.5.1.tgz |
| CVE-2022-0144 | shelljs-0.8.3.tgz |
| CVE-2025-25289 | request-error-1.2.0.tgz |
| CVE-2025-25290 | request-5.3.1.tgz |
| CVE-2022-25881 | http-cache-semantics-3.8.1.tgz |
| CVE-2022-33987 | got-8.3.2.tgz |
Base branch total remaining vulnerabilities: 241
Base branch commit: cf4809401568c63c3c5a5ef5939284d7d5f8f8c3
Total libraries scanned: 1814
Scan token: c90ed96d3b194d639c3a0dcdb8e0aacf