Update dependency ejs to v3 #17
Open
Staging - WhiteSource for GitHub.com / Mend Security Check
failed
Feb 6, 2026 in 1m 18s
Security Report
You have successfully remediated 3 vulnerabilities, but introduced 1 new vulnerabilities in this branch.
❌ New vulnerabilities:
| Vulnerability | Severity | Vulnerable Library | Direct Library | Suggested Fix | Issue | Reachability | |
|---|---|---|---|---|---|---|---|
CVE-2025-5889Path to dependency file: /package.json Path to vulnerable library: /node_modules/brace-expansion/package.json Dependency Hierarchy: -> ejs-3.1.10.tgz (Root Library) -> jake-10.9.4.tgz -> filelist-1.0.4.tgz -> minimatch-5.1.6.tgz -> ❌ brace-expansion-2.0.2.tgz (Vulnerable Library) |
3.1 | Transitive brace-expansion-2.0.2.tgz |
ejs-3.1.10.tgz | Transitive brace-expansion - 1.1.12,brace-expansion - 4.0.1,brace-expansion - 2.0.2,brace-expansion - 3.0.1 |
None |
✔️ Remediated vulnerabilities:
| Vulnerability | Vulnerable Library |
|---|---|
| WS-2021-0153 | ejs-2.7.4.tgz |
| CVE-2022-29078 | ejs-2.7.4.tgz |
| CVE-2024-33883 | ejs-2.7.4.tgz |
Base branch total remaining vulnerabilities: 34
Base branch commit: a8c329a3af185a914e5bb0f48e708b10999e5581
Total libraries scanned: 315
Scan token: fe4549ed5ac140db8680b53b6caf3c01
Loading