Skip to content

Update dependency async to ^2.6.4 - #8

Open
ghost wants to merge 1 commit into
masterfrom
whitesource-remediate/async-2.x
Open

Update dependency async to ^2.6.4#8
ghost wants to merge 1 commit into
masterfrom
whitesource-remediate/async-2.x

Update dependency async to ^2.6.4

4f6304f
Select commit
Loading
Failed to load commit list.
Deleted GitHub App / Mend Security Check failed Jan 29, 2026 in 32s

Security Report

The Security Check found 2 vulnerabilities.

Vulnerability Severity CVSS Score Exploit Maturity EPSS Vulnerable Library Direct Library Suggested Fix Issue
CVE-2022-25883

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> ❌ semver-5.6.0.tgz (Vulnerable Library)

Medium 5.3 Proof of concept 0.6% Direct semver-5.6.0.tgz semver-5.6.0.tgz 5.7.2 None
CVE-2017-16137

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> ❌ debug-3.2.6.tgz (Vulnerable Library)

Low 3.7 Not Defined 0.1% Direct debug-3.2.6.tgz debug-3.2.6.tgz 3.2.7 None

Total libraries scanned: 8
Scan token: 462e863648e34f84be0ff19c657311e1