🚨 [security] [js] Update webpack 5.70.0 → 5.99.7 (minor) #780
Mend Bolt for GitHub / WhiteSource Security Check
failed
Apr 26, 2025 in 2m 24s
Security Report
You have successfully remediated 2 vulnerabilities, but introduced 3 new vulnerabilities in this branch.
❌ New vulnerabilities:
| CVE | Severity | Vulnerable Library | Suggested Fix | Issue | |
|---|---|---|---|---|---|
| 6.0 | electronv12.0.0-nightly.20201028 | Upgrade to version: electron - 22.3.6,23.2.3,24.1.0 | #734 | ||
| 5.4 | electronv12.0.0-nightly.20201028 | Upgrade to version: electron - 9.4.0,10.2.0,11.1.0,12.0.0-beta.9 | #109 | ||
CVE-2022-33987Path to dependency file: /npm/package.json Path to vulnerable library: /npm/node_modules/got/package.json Dependency Hierarchy: -> get-1.12.4.tgz (Root Library) -> ❌ got-9.6.0.tgz (Vulnerable Library) |
5.3 | got-9.6.0.tgz | None |
✔️ Remediated vulnerabilities:
| CVE | Vulnerable Library |
|---|---|
| CVE-2020-26272 | electron-v12.0.0-nightly.20201005 |
| CVE-2023-29198 | electron-v12.0.0-nightly.20201005 |
Base branch total remaining vulnerabilities: 15
Base branch commit: null
Total libraries scanned: 159
Scan token: 34ec14f46b13484785174db98731b65d
Loading