🚨 [security] [js] Update webpack 5.70.0 → 5.105.2 (minor) #800
Security Report
You have successfully remediated 2 vulnerabilities, but introduced 4 new vulnerabilities in this branch.
❌ New vulnerabilities:
| Vulnerability | Severity | Vulnerable Library | Direct Library | Suggested Fix | Issue | |
|---|---|---|---|---|---|---|
CVE-2025-69873Path to dependency file: /spec/package.json Path to vulnerable library: /spec/node_modules/ajv/package.json,/spec-main/node_modules/ajv/package.json Dependency Hierarchy: -> mocha-appveyor-reporter-0.4.2.tgz (Root Library) -> request-json-0.6.4.tgz -> request-2.88.0.tgz -> har-validator-5.1.3.tgz -> ❌ ajv-6.12.6.tgz (Vulnerable Library) |
7.5 | Transitive ajv-6.12.6.tgz |
mocha-appveyor-reporter-0.4.2.tgz | None | ||
| 6.0 | electronv12.0.0-nightly.20201028 | #734 | ||||
| 5.4 | electronv12.0.0-nightly.20201028 | #109 | ||||
CVE-2022-33987Path to dependency file: /npm/package.json Path to vulnerable library: /npm/node_modules/got/package.json Dependency Hierarchy: -> get-1.12.4.tgz (Root Library) -> ❌ got-9.6.0.tgz (Vulnerable Library) |
5.3 | Transitive got-9.6.0.tgz |
get-1.12.4.tgz | Transitive got - 11.8.5,got - 12.1.0 |
None |
✔️ Remediated vulnerabilities:
| Vulnerability | Vulnerable Library |
|---|---|
| CVE-2020-26272 | electron-v12.0.0-nightly.20201005 |
| CVE-2023-29198 | electron-v12.0.0-nightly.20201005 |
Base branch total remaining vulnerabilities: 18
Base branch commit: null
Total libraries scanned: 159
Scan token: 9b9c8fab55a0433cafacdda27be9760c