Skip to content

Update dependency semver to ^5.7.2 - #16

Open
ghost wants to merge 1 commit into
masterfrom
whitesource-remediate/semver-5.x
Open

Update dependency semver to ^5.7.2#16
ghost wants to merge 1 commit into
masterfrom
whitesource-remediate/semver-5.x

Update dependency semver to ^5.7.2

63f812c
Select commit
Loading
Failed to load commit list.
Deleted GitHub App / Mend Security Check failed Jan 29, 2026 in 1m 54s

Security Report

The Security Check found 6 vulnerabilities.

Vulnerability Severity CVSS Score Exploit Maturity EPSS Vulnerable Library Direct Library Suggested Fix Issue
CVE-2025-13465

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> async-2.6.1.tgz (Root Library)

   -> ❌ lodash-4.17.11.tgz (Vulnerable Library)

Critical 9.9 Not Defined 0.1% Transitive lodash-4.17.11.tgz async-2.6.1.tgz Transitive lodash-amd - 4.17.23,lodash - 4.17.23,lodash-es - 4.17.23 None
CVE-2021-43138

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> ❌ async-2.6.1.tgz (Vulnerable Library)

High 7.8 Not Defined 0.70000005% Direct async-2.6.1.tgz async-2.6.1.tgz 2.6.4 None
CVE-2020-8203

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> async-2.6.1.tgz (Root Library)

   -> ❌ lodash-4.17.11.tgz (Vulnerable Library)

High 7.4 Not Defined 2.5% Transitive lodash-4.17.11.tgz async-2.6.1.tgz 2.6.2 None
CVE-2021-23337

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> async-2.6.1.tgz (Root Library)

   -> ❌ lodash-4.17.11.tgz (Vulnerable Library)

High 7.2 Proof of concept 0.70000005% Transitive lodash-4.17.11.tgz async-2.6.1.tgz 2.6.2 None
CVE-2020-28500

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> async-2.6.1.tgz (Root Library)

   -> ❌ lodash-4.17.11.tgz (Vulnerable Library)

Medium 5.3 Proof of concept 0.2% Transitive lodash-4.17.11.tgz async-2.6.1.tgz Transitive lodash - 4.17.21,lodash-es - 4.17.21,lodash-rails - 4.17.21 None
CVE-2017-16137

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> ❌ debug-3.2.6.tgz (Vulnerable Library)

Low 3.7 Not Defined 0.1% Direct debug-3.2.6.tgz debug-3.2.6.tgz 3.2.7 None

Total libraries scanned: 8
Scan token: 4c9f5f4bf03c4ac5a4492272e38a2f19