Update dependency underscore to v1.12.1 #19
Security Report
You have successfully remediated 1 vulnerabilities, but introduced 4 new vulnerabilities in this branch.
❌ New vulnerabilities:
| Vulnerability | Severity | Vulnerable Library | Direct Library | Suggested Fix | Issue | |
|---|---|---|---|---|---|---|
CVE-398484-724968Path to dependency file: /package.json Path to vulnerable library: /package.json Dependency Hierarchy: -> core-7.23.2.tgz (Root Library) -> traverse-7.29.0.tgz -> debug-4.4.3.tgz -> ❌ ms-2.1.3.tgz (Vulnerable Library) |
9.8 | Transitive ms-2.1.3.tgz |
core-7.23.2.tgz | None | ||
CVE-2026-41239Path to dependency file: /package.json Path to vulnerable library: /package.json Dependency Hierarchy: -> ❌ dompurify-2.5.9.tgz (Vulnerable Library) |
6.8 | Direct dompurify-2.5.9.tgz |
dompurify-2.5.9.tgz | 3.4.0 | None | |
CVE-2026-41240Path to dependency file: /package.json Path to vulnerable library: /package.json Dependency Hierarchy: -> ❌ dompurify-2.5.9.tgz (Vulnerable Library) |
6.5 | Direct dompurify-2.5.9.tgz |
dompurify-2.5.9.tgz | 3.4.0 | None | |
CVE-2025-27789Path to dependency file: /package.json Path to vulnerable library: /package.json Dependency Hierarchy: -> core-7.23.2.tgz (Root Library) -> ❌ helpers-7.29.2.tgz (Vulnerable Library) |
6.2 | Transitive helpers-7.29.2.tgz |
core-7.23.2.tgz | Transitive @babel/runtime - 8.0.0-alpha.17,@babel/helpers - 8.0.0-alpha.17,@babel/runtime-corejs2 - 8.0.0-alpha.17,@babel/runtime - 7.26.10,@babel/helpers - 7.26.10,@babel/runtime-corejs2 - 7.26.10,@babel/runtime-corejs3 - 8.0.0-alpha.17,https://github.com/babel/babel.git - v7.26.10,@babel/runtime-corejs3 - 7.26.10 |
None |
✔️ Remediated vulnerabilities:
| Vulnerability | Vulnerable Library |
|---|---|
| CVE-2021-23358 | underscore-1.9.1.tgz |
Base branch total remaining vulnerabilities: 80
Base branch commit: 716fe17b8d26ad794de274101da05107a712797c
Total libraries scanned: 420
Scan token: bd8d6d2f1d384f1f9795a295890033c9