Skip to content

fix: package.json to reduce vulnerabilities

c0ec54f
Select commit
Loading
Failed to load commit list.
Open

[Snyk] Fix for 2 vulnerabilities #49

fix: package.json to reduce vulnerabilities
c0ec54f
Select commit
Loading
Failed to load commit list.
Debricked / Vulnerability analysis completed Jan 10, 2026 in 19s

An automation triggered a pipeline warning

Found 30 vulnerabilities. An additional 0 vulnerabilities have been marked as unaffected.

Output from Automations

4 rules were checked:


If a new dependency is added where the license risk is at least medium

then notify all users in the group admins by email

✔️ The rule did not trigger. Manage rule



If there is a dependency where the license risk is at least high

then send a pipeline warning

✔️ The rule did not trigger. Manage rule



If a dependency contains a vulnerability which has not been marked as unaffected and which has not triggered this rule for this dependency before

then notify all users in the group admins by email

📤 The rule triggered for the following vulnerabilities, causing an email notification. Manage rule

Vulnerability CVSS2 CVSS3 Dependency Dependency Licenses
CVE-2025-12816 N/A 8.6 node-forge (npm) BSD-3-Clause, GPL-2.0-only
CVE-2025-66031 N/A 7.5 node-forge (npm) BSD-3-Clause, GPL-2.0-only
CVE-2025-64718 N/A 5.3 js-yaml (npm) MIT
CVE-2025-66030 N/A 5.3 node-forge (npm) BSD-3-Clause, GPL-2.0-only
CVE-2025-7339 N/A 3.4 on-headers (npm) MIT


If a dependency contains a vulnerability which has not been marked as unaffected

then send a pipeline warning

⚠️ The rule triggered for the following vulnerabilities, causing a pipeline warning. Manage rule

Vulnerability CVSS2 CVSS3 Dependency Dependency Licenses
CVE-2024-57965 N/A 9.8 axios (npm) MIT
CVE-2025-12816 N/A 8.6 node-forge (npm) BSD-3-Clause, GPL-2.0-only
CVE-2024-45296 N/A 7.5 path-to-regexp (npm) MIT
CVE-2024-21536 N/A 7.5 http-proxy-middleware (npm) MIT
CVE-2025-58754 N/A 7.5 axios (npm) MIT
CVE-2024-21538 N/A 7.5 cross-spawn (npm) MIT
CVE-2025-66031 N/A 7.5 node-forge (npm) BSD-3-Clause, GPL-2.0-only
CVE-2024-45590 N/A 7.5 body-parser (npm) MIT
CVE-2025-30360 N/A 6.5 webpack-dev-server (npm) MIT
CVE-2025-27789 N/A 6.2 @babel/helpers (npm) MIT
CVE-2025-27789 N/A 6.2 @babel/runtime-corejs3 (npm) MIT
CVE-2025-27789 N/A 6.2 @babel/runtime (npm) MIT
CVE-2025-30359 N/A 5.9 webpack-dev-server (npm) MIT
CVE-2024-53382 N/A 5.4 prismjs (npm) MIT
CVE-2024-11831 N/A 5.4 serialize-javascript (npm) BSD-3-Clause
CVE-2025-32997 N/A 5.3 http-proxy-middleware (npm) MIT
CVE-2025-66030 N/A 5.3 node-forge (npm) BSD-3-Clause, GPL-2.0-only
CVE-2025-64718 N/A 5.3 js-yaml (npm) MIT
CVE-2025-27152 N/A 5.3 axios (npm) MIT
CVE-2025-32996 N/A 5.3 http-proxy-middleware (npm) MIT
CVE-2024-43800 N/A 4.7 serve-static (npm) MIT
CVE-2024-43799 N/A 4.7 send (npm) MIT
CVE-2024-43796 N/A 4.7 express (npm) MIT
CVE-2024-55565 N/A 4.3 nanoid (npm) MIT
CVE-2025-7339 N/A 3.4 on-headers (npm) MIT
CVE-2025-5889 2.1 3.1 brace-expansion (npm) MIT
debricked-270315 N/A N/A @sentry/browser (npm) BSD-3-Clause, MIT
CVE-2024-52798 N/A N/A path-to-regexp (npm) MIT
CVE-2025-32014 N/A N/A estree-util-value-to-estree (npm) MIT
CVE-2025-7783 N/A N/A form-data (npm) MIT
CVE-2024-47764 N/A N/A cookie (npm) MIT
debricked-97165 N/A N/A lodash.pick (npm) MIT