Skip to content

Update webpack to version 5.99.6

b1d0e8b
Select commit
Loading
Failed to load commit list.
Closed

🚨 [security] [js] Update webpack 5.70.0 → 5.99.6 (minor) #779

Update webpack to version 5.99.6
b1d0e8b
Select commit
Loading
Failed to load commit list.
Mend Bolt for GitHub / WhiteSource Security Check failed Apr 25, 2025 in 1m 14s

Security Report

You have successfully remediated 2 vulnerabilities, but introduced 3 new vulnerabilities in this branch.

❌ New vulnerabilities:

CVE Severity CVSS Score Vulnerable Library Suggested Fix Issue
CVE-2023-29198

Vulnerable Source Files:

❌ /shell/renderer/api/electron_api_context_bridge.cc

Medium 6.0 electronv12.0.0-nightly.20201028 Upgrade to version: electron - 22.3.6,23.2.3,24.1.0 #734
CVE-2020-26272

Vulnerable Source Files:

❌ /shell/common/gin_helper/event_emitter.cc

Medium 5.4 electronv12.0.0-nightly.20201028 Upgrade to version: electron - 9.4.0,10.2.0,11.1.0,12.0.0-beta.9 #109
CVE-2022-33987

Path to dependency file: /npm/package.json

Path to vulnerable library: /npm/node_modules/got/package.json

Dependency Hierarchy:

-> get-1.12.4.tgz (Root Library)

   -> ❌ got-9.6.0.tgz (Vulnerable Library)

Medium 5.3 got-9.6.0.tgz None

✔️ Remediated vulnerabilities:

CVE Vulnerable Library
CVE-2020-26272 electron-v12.0.0-nightly.20201005
CVE-2023-29198 electron-v12.0.0-nightly.20201005

Base branch total remaining vulnerabilities: 15
Base branch commit: null


Total libraries scanned: 159

Scan token: 7dcae14d98d64e068c224f9d59fe61b8