Skip to content

Update webpack to version 5.105.2

3efcb5d
Select commit
Loading
Failed to load commit list.
Closed

🚨 [security] [js] Update webpack 5.70.0 → 5.105.2 (minor) #800

Update webpack to version 5.105.2
3efcb5d
Select commit
Loading
Failed to load commit list.
Mend Bolt for GitHub / WhiteSource Security Check failed Feb 13, 2026 in 10m 44s

Security Report

You have successfully remediated 2 vulnerabilities, but introduced 4 new vulnerabilities in this branch.

❌ New vulnerabilities:

Vulnerability Severity CVSS Score Vulnerable Library Direct Library Suggested Fix Issue
CVE-2025-69873

Path to dependency file: /spec/package.json

Path to vulnerable library: /spec/node_modules/ajv/package.json,/spec-main/node_modules/ajv/package.json

Dependency Hierarchy:

-> mocha-appveyor-reporter-0.4.2.tgz (Root Library)

   -> request-json-0.6.4.tgz

     -> request-2.88.0.tgz

       -> har-validator-5.1.3.tgz

         -> ❌ ajv-6.12.6.tgz (Vulnerable Library)

High 7.5 Transitive ajv-6.12.6.tgz mocha-appveyor-reporter-0.4.2.tgz None
CVE-2023-29198

Vulnerable Source Files:

❌ /shell/renderer/api/electron_api_context_bridge.cc

Medium 6.0 electronv12.0.0-nightly.20201028 #734
CVE-2020-26272

Vulnerable Source Files:

❌ /shell/common/gin_helper/event_emitter.cc

Medium 5.4 electronv12.0.0-nightly.20201028 #109
CVE-2022-33987

Path to dependency file: /npm/package.json

Path to vulnerable library: /npm/node_modules/got/package.json

Dependency Hierarchy:

-> get-1.12.4.tgz (Root Library)

   -> ❌ got-9.6.0.tgz (Vulnerable Library)

Medium 5.3 Transitive got-9.6.0.tgz get-1.12.4.tgz Transitive got - 11.8.5,got - 12.1.0 None

✔️ Remediated vulnerabilities:

Vulnerability Vulnerable Library
CVE-2020-26272 electron-v12.0.0-nightly.20201005
CVE-2023-29198 electron-v12.0.0-nightly.20201005

Base branch total remaining vulnerabilities: 18
Base branch commit: null


Total libraries scanned: 159

Scan token: 9b9c8fab55a0433cafacdda27be9760c