Added check to events-to-s3 for label canary #40
Security Report
7 new vulnerabilities were introduced in this branch.
❌ New vulnerabilities:
CVE | Severity | Vulnerable Library | Suggested Fix | Issue | |
---|---|---|---|---|---|
CVE-2025-25290Path to dependency file: /package.json Path to vulnerable library: /package.json Dependency Hierarchy: -> rest-21.0.2.tgz (Root Library) -> core-6.1.2.tgz -> ❌ request-9.1.3.tgz (Vulnerable Library) |
5.3 | request-9.1.3.tgz | Upgrade to version: @octokit/request - 9.2.1 | None | |
CVE-2025-25290Path to dependency file: /package.json Path to vulnerable library: /package.json Dependency Hierarchy: -> probot-13.1.2.tgz (Root Library) -> ❌ request-8.2.0.tgz (Vulnerable Library) |
5.3 | request-8.2.0.tgz | Upgrade to version: @octokit/request - 9.2.1 | #25 | |
CVE-2025-25289Path to dependency file: /package.json Path to vulnerable library: /package.json Dependency Hierarchy: -> rest-21.0.2.tgz (Root Library) -> core-6.1.2.tgz -> ❌ request-error-6.1.4.tgz (Vulnerable Library) |
5.3 | request-error-6.1.4.tgz | Upgrade to version: @octokit/request-error - 5.1.1,6.1.7 | None | |
CVE-2025-25289Path to dependency file: /package.json Path to vulnerable library: /package.json Dependency Hierarchy: -> probot-13.1.2.tgz (Root Library) -> webhooks-12.2.0.tgz -> ❌ request-error-5.0.1.tgz (Vulnerable Library) |
5.3 | request-error-5.0.1.tgz | Upgrade to version: @octokit/request-error - 5.1.1,6.1.7 | #25 | |
CVE-2025-25288Path to dependency file: /package.json Path to vulnerable library: /package.json Dependency Hierarchy: -> rest-21.0.2.tgz (Root Library) -> ❌ plugin-paginate-rest-11.3.3.tgz (Vulnerable Library) |
5.3 | plugin-paginate-rest-11.3.3.tgz | Upgrade to version: @octokit/plugin-paginate-rest - 11.4.1 | None | |
CVE-2025-25288Path to dependency file: /package.json Path to vulnerable library: /package.json Dependency Hierarchy: -> probot-13.1.2.tgz (Root Library) -> ❌ plugin-paginate-rest-9.2.1.tgz (Vulnerable Library) |
5.3 | plugin-paginate-rest-9.2.1.tgz | Upgrade to version: @octokit/plugin-paginate-rest - 11.4.1 | #25 | |
CVE-2025-25285Path to dependency file: /package.json Path to vulnerable library: /package.json Dependency Hierarchy: -> probot-13.1.2.tgz (Root Library) -> request-8.2.0.tgz -> ❌ endpoint-9.0.4.tgz (Vulnerable Library) |
5.3 | endpoint-9.0.4.tgz | Upgrade to version: @octokit/endpoint - 9.0.6,10.1.3 | #25 |
Base branch total remaining vulnerabilities: 1
Base branch commit: 3b1ecd9312e846592de500809ec537876facbdd8
Total libraries scanned: 404
Scan token: d7abd2822736487480b891d25f688291