Update dependency async to ^2.6.4 - #8
Open
ghost wants to merge 1 commit into
Open
Deleted GitHub App / Mend Security Check
failed
Jan 29, 2026 in 32s
Security Report
The Security Check found 2 vulnerabilities.
| Vulnerability | Severity | Exploit Maturity | EPSS | Vulnerable Library | Direct Library | Suggested Fix | Issue | |
|---|---|---|---|---|---|---|---|---|
CVE-2022-25883Path to dependency file: /package.json Path to vulnerable library: /package.json Dependency Hierarchy: -> ❌ semver-5.6.0.tgz (Vulnerable Library) |
5.3 | Proof of concept | 0.6% | Direct semver-5.6.0.tgz |
semver-5.6.0.tgz | 5.7.2 | None | |
CVE-2017-16137Path to dependency file: /package.json Path to vulnerable library: /package.json Dependency Hierarchy: -> ❌ debug-3.2.6.tgz (Vulnerable Library) |
3.7 | Not Defined | 0.1% | Direct debug-3.2.6.tgz |
debug-3.2.6.tgz | 3.2.7 | None |
Total libraries scanned: 8
Scan token: 462e863648e34f84be0ff19c657311e1
Loading