Findings
2 packages with no automated fix · +1 more with unfixable findings alongside fixable ones
These advisories have no fix version Arguss can apply automatically. Review and remediate manually.
babel-traverse@6.26.0
-
babel-traverse@6.26.0EPSS 0.5% CVSS 9.9 critical
Babel vulnerable to arbitrary code execution when compiling specifically crafted malicious code
### Impact Using Babel to compile code that was specifically crafted by an attacker can lead to arbitrary code execution during compilation, when using plugins that rely on the `path.evaluate()`or `path.evaluateTruthy()` internal Babel methods. Known affected plugins are: - `@babel/plugin-transform-runtime` - `@babel/preset-env` when using its [`useBuiltIns`](https://babeljs.io/docs/babel-preset-env#usebuiltins) option - Any "polyfill provider" plugin that depends on `@babel/helper-define-polyfill-provider`, such as `babel-plugin-polyfill-corejs3`, `babel-plugin-polyfill-corejs2`, `babel-plugin-polyfill-es-shims`, `babel-plugin-polyfill-regenerator` No other plugins under the `@babel/` namespace are impacted, but third-party plugins might be. **Users that only compile trusted code are not impacted.** ### Patches The vulnerability has been fixed in `@babel/traverse@7.23.2`. Babel 6 does not receive security fixes anymore (see [Babel's security policy](https://github.com/babel/babel/security/policy)), hence there is no patch planned for `babel-traverse@6`. ### Workarounds - Upgrade `@babel/traverse` to v7.23.2 or higher. You can do this by deleting it from your package manager's lockfile and re-installing the dependencies. `@babel/core` >=7.23.2 will automatically pull in a non-vulnerable version. - If you cannot upgrade `@babel/traverse` and are using one of the affected packages mentioned above, upgrade them to their latest version to avoid triggering the vulnerable code path in affected `@babel/traverse` versions: - `@babel/plugin-transform-runtime` v7.23.2 - `@babel/preset-env` v7.23.2 - `@babel/helper-define-polyfill-provider` v0.4.3 - `babel-plugin-polyfill-corejs2` v0.4.6 - `babel-plugin-polyfill-corejs3` v0.8.5 - `babel-plugin-polyfill-es-shims` v0.10.0 - `babel-plugin-polyfill-regenerator` v0.5.3
Dependency path: root → babel-core → babel-traverse
request@2.88.0
-
request@2.88.0EPSS 0.7% CVSS 6.1 medium
Server-Side Request Forgery in Request
The `request` package through 2.88.2 for Node.js and the `@cypress/request` package prior to 3.0.0 allow a bypass of SSRF mitigations via an attacker-controller server that does a cross-protocol redirect (HTTP to HTTPS, or HTTPS to HTTP). NOTE: The `request` package is no longer supported by the maintainer.
Dependency path: root → jest → jest-cli → jest-config → jest-environment-jsdom → jsdom → request
Also affected - these packages have upgrade candidates for their other findings
lodash.template@4.5.0
-
lodash.template@4.5.0EPSS 22.4% CVSS 7.2 high
Command Injection in lodash
`lodash` versions prior to 4.17.21 are vulnerable to Command Injection via the template function.
Dependency path: root → @commitlint/cli → @commitlint/read → git-raw-commits → lodash.template
y18n
@ 4.0.0
1 finding
high
Trust 0/100
EPSS 69.1% ↑
⚠ new maintainer
REVIEW
Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk.
Click for more →
- trust veto: new maintainer added
Upgrade y18n from 4.0.0 to 4.0.1 or later
View advisoryBlast radius
Paths from project root to y18n - which dependencies pulled this package in?
decode-uri-component
@ 0.2.0
1 finding
high
Trust 30/100
EPSS 24.9% ↑
AUTO-MERGE
Verdict tier: the fix passes all three lenses cleanly. In Mode C, Arguss opens a pull request for the upgrade; it does not merge PRs on GitHub.
Click for more →
decode-uri-component vulnerable to Denial of Service (DoS)
- patch-level upgrade; trust signals unchanged; CI verifies tests
Upgrade decode-uri-component from 0.2.0 to 0.2.1 or later
View advisoryBlast radius
Paths from project root to decode-uri-component - which dependencies pulled this package in?
lodash
@ 4.17.14
24 findings
high–medium
Trust 0/100
EPSS 22.4% ↑
⚠ new maintainer
MIXED
lodash vulnerable to Code Injection via `_.template` imports key names
Affects 6 install paths
Prototype Pollution in lodash
Affects 2 install paths
Command Injection in lodash
Affects 2 install paths
lodash vulnerable to Prototype Pollution via array path bypass in `_.unset` and `_.omit`
Affects 6 install paths
Lodash has Prototype Pollution Vulnerability in `_.unset` and `_.omit` functions
Affects 6 install paths
Regular Expression Denial of Service (ReDoS) in lodash
Affects 2 install paths
- trust veto: new maintainer added
Upgrade lodash from 4.17.14 to 4.18.0 or later
View advisory- trust veto: new maintainer added
Upgrade lodash from 4.17.15 to 4.18.0 or later
View advisory- minor-level upgrade; trust signals unchanged; CI verifies tests
Upgrade lodash from 4.17.21 to 4.18.0 or later
View advisoryBlast radius
Paths from project root to lodash - which dependencies pulled this package in?
lodash.template
@ 4.5.0
2 findings
high
Trust 0/100
EPSS 22.4% ↑
AUTO-MERGE
Verdict tier: the fix passes all three lenses cleanly. In Mode C, Arguss opens a pull request for the upgrade; it does not merge PRs on GitHub.
Click for more →
lodash vulnerable to Code Injection via `_.template` imports key names
Command Injection in lodash
No fixed version published in OSV
GHSA-35jh-r3h4-6jhm- minor-level upgrade; trust signals unchanged; CI verifies tests
Upgrade lodash.template from 4.5.0 to 4.18.0 or later
View advisoryBlast radius
Paths from project root to lodash.template - which dependencies pulled this package in?
17 findings
high–medium
Trust 0/100
EPSS 15.0% ↑
⚠ ownership transferred
REVIEW
Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk.
Click for more →
Race Condition in node-tar Path Reservations via Unicode Ligature Collisions on macOS APFS
Arbitrary File Creation/Overwrite due to insufficient absolute path sanitization
Arbitrary File Creation/Overwrite on Windows via insufficient relative path sanitization
Arbitrary File Creation/Overwrite via insufficient symlink protection due to directory cache poisoning using symbolic links
Arbitrary File Creation/Overwrite via insufficient symlink protection due to directory cache poisoning using symbolic links
Arbitrary File Creation/Overwrite via insufficient symlink protection due to directory cache poisoning
node-tar Vulnerable to Arbitrary File Creation/Overwrite via Hardlink Path Traversal
node-tar: Decompression/parse DoS via unlimited input
node-tar is Vulnerable to Arbitrary File Overwrite and Symlink Poisoning via Insufficient Path Sanitization
node-tar: Negative tar entry size causes infinite loop in archive replace
node-tar Symlink Path Traversal via Drive-Relative Linkpath
tar has Hardlink Path Traversal via Drive-Relative Linkpath
Arbitrary File Read/Write via Hardlink Target Escape Through Symlink Chain in node-tar Extraction
Denial of service while parsing a tar file due to lack of folders count validation
node-tar: Uncaught Exception DoS via NUL byte in PAX path/linkpath records
node-tar: Process crash via PAX numeric path type confusion
node-tar applies PAX size override to intermediary GNU long-name/long-link headers, causing tar parser interpretation differential (file smuggling)
- major version bump requires human review (never auto-merge)
- trust veto: package ownership transferred between versions
Upgrade tar from 4.4.8 to 7.5.4 or later
View advisoryBlast radius
Paths from project root to tar - which dependencies pulled this package in?
qs
@ 6.5.2
2 findings
high–low
Trust 0/100
EPSS 14.7% ↑
AUTO-MERGE
Verdict tier: the fix passes all three lenses cleanly. In Mode C, Arguss opens a pull request for the upgrade; it does not merge PRs on GitHub.
Click for more →
qs vulnerable to Prototype Pollution
qs's arrayLimit bypass in its bracket notation allows DoS via memory exhaustion
- minor-level upgrade; trust signals unchanged; CI verifies tests
Upgrade qs from 6.5.2 to 6.5.3 or later
View advisoryBlast radius
Paths from project root to qs - which dependencies pulled this package in?
json5
@ 0.5.1
2 findings
high
Trust 0/100
EPSS 9.3%
MIXED
Prototype Pollution in JSON5 via Parse Method
Affects 2 install paths
- major version bump requires human review (never auto-merge)
Upgrade json5 from 0.5.1 to 1.0.2 or later
View advisory- minor-level upgrade; trust signals unchanged; CI verifies tests
Upgrade json5 from 2.1.1 to 2.2.2 or later
View advisoryBlast radius
Paths from project root to json5 - which dependencies pulled this package in?
5 findings
critical–medium
Trust 30/100
EPSS 4.6%
⚠ ownership transferred
MIXED
Prototype Pollution in minimist
Affects 3 install paths
Prototype Pollution in minimist
Affects 2 install paths
- trust veto: new maintainer added
- trust veto: package ownership transferred between versions
Upgrade minimist from 0.0.8 to 0.2.4 or later
View advisory- trust veto: new maintainer added
Upgrade minimist from 1.2.0 to 1.2.6 or later
View advisory- patch-level upgrade; trust signals unchanged; CI verifies tests
Upgrade minimist from 1.2.5 to 1.2.6 or later
View advisoryBlast radius
Paths from project root to minimist - which dependencies pulled this package in?
glob-parent
@ 5.1.0
1 finding
high
Trust 0/100
EPSS 4.6%
AUTO-MERGE
Verdict tier: the fix passes all three lenses cleanly. In Mode C, Arguss opens a pull request for the upgrade; it does not merge PRs on GitHub.
Click for more →
glob-parent vulnerable to Regular Expression Denial of Service in enclosure regex
- patch-level upgrade; trust signals unchanged; CI verifies tests
Upgrade glob-parent from 5.1.0 to 5.1.2 or later
View advisoryBlast radius
Paths from project root to glob-parent - which dependencies pulled this package in?
1 finding
medium
Trust 0/100
EPSS 3.6%
⚠ ownership transferred
REVIEW
Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk.
Click for more →
Regular Expression Denial of Service in hosted-git-info
- trust veto: new maintainer added
- trust veto: package ownership transferred between versions
Upgrade hosted-git-info from 2.8.5 to 2.8.9 or later
View advisoryBlast radius
Paths from project root to hosted-git-info - which dependencies pulled this package in?
ini
@ 1.3.5
2 findings
high
Trust 30/100
EPSS 3.6%
AUTO-MERGE
Verdict tier: the fix passes all three lenses cleanly. In Mode C, Arguss opens a pull request for the upgrade; it does not merge PRs on GitHub.
Click for more →
ini before 1.3.6 vulnerable to Prototype Pollution via ini.parse
Affects 2 install paths
- patch-level upgrade; trust signals unchanged; CI verifies tests
Upgrade ini from 1.3.5 to 1.3.6 or later
View advisoryBlast radius
Paths from project root to ini - which dependencies pulled this package in?
json-schema
@ 0.2.3
1 finding
critical
Trust 30/100
EPSS 3.6%
AUTO-MERGE
Verdict tier: the fix passes all three lenses cleanly. In Mode C, Arguss opens a pull request for the upgrade; it does not merge PRs on GitHub.
Click for more →
json-schema is vulnerable to Prototype Pollution
- minor-level upgrade; trust signals unchanged; CI verifies tests
Upgrade json-schema from 0.2.3 to 0.4.0 or later
View advisoryBlast radius
Paths from project root to json-schema - which dependencies pulled this package in?
ansi-regex
@ 3.0.0
11 findings
high
Trust 0/100
EPSS 3.6%
AUTO-MERGE
Verdict tier: the fix passes all three lenses cleanly. In Mode C, Arguss opens a pull request for the upgrade; it does not merge PRs on GitHub.
Click for more →
Inefficient Regular Expression Complexity in chalk/ansi-regex
Affects 11 install paths
- patch-level upgrade; trust signals unchanged; CI verifies tests
Upgrade ansi-regex from 3.0.0 to 3.0.1 or later
View advisory- patch-level upgrade; trust signals unchanged; CI verifies tests
Upgrade ansi-regex from 4.1.0 to 4.1.1 or later
View advisoryBlast radius
Paths from project root to ansi-regex - which dependencies pulled this package in?
dot-prop
@ 3.0.0
1 finding
high
Trust 30/100
EPSS 3.1%
REVIEW
Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk.
Click for more →
dot-prop Prototype Pollution vulnerability
- major version bump requires human review (never auto-merge)
Upgrade dot-prop from 3.0.0 to 4.2.1 or later
View advisoryBlast radius
Paths from project root to dot-prop - which dependencies pulled this package in?
trim-newlines
@ 2.0.0
1 finding
high
Trust 30/100
EPSS 2.9%
REVIEW
Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk.
Click for more →
Uncontrolled Resource Consumption in trim-newlines
- major version bump requires human review (never auto-merge)
Upgrade trim-newlines from 2.0.0 to 3.0.1 or later
View advisoryBlast radius
Paths from project root to trim-newlines - which dependencies pulled this package in?
ws
@ 5.2.2
3 findings
high–medium
Trust 0/100
EPSS 2.8%
AUTO-MERGE
Verdict tier: the fix passes all three lenses cleanly. In Mode C, Arguss opens a pull request for the upgrade; it does not merge PRs on GitHub.
Click for more →
ws affected by a DoS when handling a request with many HTTP headers
ws: Memory exhaustion DoS from tiny fragments and data chunks
ReDoS in Sec-Websocket-Protocol header
- patch-level upgrade; trust signals unchanged; CI verifies tests
Upgrade ws from 5.2.2 to 5.2.4 or later
View advisoryBlast radius
Paths from project root to ws - which dependencies pulled this package in?
debug
@ 4.1.1
6 findings
low
Trust 0/100
EPSS 2.8%
AUTO-MERGE
Verdict tier: the fix passes all three lenses cleanly. In Mode C, Arguss opens a pull request for the upgrade; it does not merge PRs on GitHub.
Click for more →
Regular Expression Denial of Service in debug
Affects 6 install paths
- minor-level upgrade; trust signals unchanged; CI verifies tests
Upgrade debug from 4.1.1 to 4.3.1 or later
View advisoryBlast radius
Paths from project root to debug - which dependencies pulled this package in?
14 findings
high
Trust 0/100
EPSS 2.8%
⚠ ownership transferred
REVIEW
Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk.
Click for more →
semver vulnerable to Regular Expression Denial of Service
Affects 14 install paths
- trust veto: new maintainer added
- trust veto: package ownership transferred between versions
Upgrade semver from 5.5.0 to 5.7.2 or later
View advisory- trust veto: new maintainer added
- trust veto: package ownership transferred between versions
Upgrade semver from 5.7.0 to 5.7.2 or later
View advisory- trust veto: new maintainer added
- trust veto: package ownership transferred between versions
Upgrade semver from 5.7.1 to 5.7.2 or later
View advisory- trust veto: new maintainer added
- trust veto: package ownership transferred between versions
Upgrade semver from 6.2.0 to 6.3.1 or later
View advisory- trust veto: new maintainer added
- trust veto: package ownership transferred between versions
Upgrade semver from 6.3.0 to 6.3.1 or later
View advisoryBlast radius
Paths from project root to semver - which dependencies pulled this package in?
browserslist
@ 4.7.3
1 finding
medium
Trust 0/100
EPSS 2.4%
AUTO-MERGE
Verdict tier: the fix passes all three lenses cleanly. In Mode C, Arguss opens a pull request for the upgrade; it does not merge PRs on GitHub.
Click for more →
Regular Expression Denial of Service in browserslist
- minor-level upgrade; trust signals unchanged; CI verifies tests
Upgrade browserslist from 4.7.3 to 4.16.5 or later
View advisoryBlast radius
Paths from project root to browserslist - which dependencies pulled this package in?
ajv
@ 6.10.2
2 findings
medium
Trust 0/100
EPSS 2.3%
AUTO-MERGE
Verdict tier: the fix passes all three lenses cleanly. In Mode C, Arguss opens a pull request for the upgrade; it does not merge PRs on GitHub.
Click for more →
Prototype Pollution in Ajv
ajv has ReDoS when using `$data` option
- minor-level upgrade; trust signals unchanged; CI verifies tests
Upgrade ajv from 6.10.2 to 6.12.3 or later
View advisoryBlast radius
Paths from project root to ajv - which dependencies pulled this package in?
path-parse
@ 1.0.6
1 finding
medium
Trust 30/100
EPSS 2.2%
AUTO-MERGE
Verdict tier: the fix passes all three lenses cleanly. In Mode C, Arguss opens a pull request for the upgrade; it does not merge PRs on GitHub.
Click for more →
Regular Expression Denial of Service in path-parse
- patch-level upgrade; trust signals unchanged; CI verifies tests
Upgrade path-parse from 1.0.6 to 1.0.7 or later
View advisoryBlast radius
Paths from project root to path-parse - which dependencies pulled this package in?
trim-off-newlines
@ 1.0.1
1 finding
medium
Trust 30/100
EPSS 1.9%
⚠ new maintainer
REVIEW
Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk.
Click for more →
Uncontrolled Resource Consumption in trim-off-newlines
- trust veto: new maintainer added
Upgrade trim-off-newlines from 1.0.1 to 1.0.3 or later
View advisoryBlast radius
Paths from project root to trim-off-newlines - which dependencies pulled this package in?
handlebars
@ 4.7.8
8 findings
critical–low
Trust 0/100
EPSS 1.8%
AUTO-MERGE
Verdict tier: the fix passes all three lenses cleanly. In Mode C, Arguss opens a pull request for the upgrade; it does not merge PRs on GitHub.
Click for more →
Handlebars.js has JavaScript Injection via AST Type Confusion
Handlebars.js has JavaScript Injection in CLI Precompiler via Unescaped Names and Options
Handlebars.js has JavaScript Injection via AST Type Confusion by tampering @partial-block
Handlebars.js has JavaScript Injection via AST Type Confusion when passing an object as dynamic partial
Handlebars.js has Denial of Service via Malformed Decorator Syntax in Template Compilation
Handlebars.js has a Prototype Method Access Control Gap via Missing __lookupSetter__ Blocklist Entry
Handlebars.js has Prototype Pollution Leading to XSS through Partial Template Injection
Handlebars.js has a Property Access Validation Bypass in container.lookup
- patch-level upgrade; trust signals unchanged; CI verifies tests
Upgrade handlebars from 4.7.8 to 4.7.9 or later
View advisoryBlast radius
Paths from project root to handlebars - which dependencies pulled this package in?
form-data
@ 2.3.3
2 findings
critical–high
Trust 0/100
EPSS 1.7%
⚠ new maintainer
REVIEW
Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk.
Click for more →
form-data uses unsafe random function in form-data for choosing boundary
form-data: CRLF injection in form-data via unescaped multipart field names and filenames
- trust veto: new maintainer added
Upgrade form-data from 2.3.3 to 2.5.4 or later
View advisoryBlast radius
Paths from project root to form-data - which dependencies pulled this package in?
word-wrap
@ 1.2.3
1 finding
medium
Trust 0/100
EPSS 1.7%
AUTO-MERGE
Verdict tier: the fix passes all three lenses cleanly. In Mode C, Arguss opens a pull request for the upgrade; it does not merge PRs on GitHub.
Click for more →
word-wrap vulnerable to Regular Expression Denial of Service
- patch-level upgrade; trust signals unchanged; CI verifies tests
Upgrade word-wrap from 1.2.3 to 1.2.4 or later
View advisoryBlast radius
Paths from project root to word-wrap - which dependencies pulled this package in?
minimatch
@ 3.0.4
8 findings
high
Trust 30/100
EPSS 1.7%
AUTO-MERGE
Verdict tier: the fix passes all three lenses cleanly. In Mode C, Arguss opens a pull request for the upgrade; it does not merge PRs on GitHub.
Click for more →
minimatch ReDoS: nested *() extglobs generate catastrophically backtracking regular expressions
Affects 2 install paths
minimatch has a ReDoS via repeated wildcards with non-matching literal in pattern
Affects 2 install paths
minimatch has ReDoS: matchOne() combinatorial backtracking via multiple non-adjacent GLOBSTAR segments
Affects 2 install paths
minimatch ReDoS vulnerability
Affects 2 install paths
- minor-level upgrade; trust signals unchanged; CI verifies tests
Upgrade minimatch from 3.0.4 to 3.1.4 or later
View advisoryBlast radius
Paths from project root to minimatch - which dependencies pulled this package in?
node-notifier
@ 5.4.3
1 finding
medium
Trust 30/100
EPSS 1.6%
REVIEW
Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk.
Click for more →
OS Command Injection in node-notifier
- major version bump requires human review (never auto-merge)
Upgrade node-notifier from 5.4.3 to 8.0.1 or later
View advisoryBlast radius
Paths from project root to node-notifier - which dependencies pulled this package in?
fsevents
@ 1.2.9
2 findings
critical–medium
Trust 15/100
EPSS 1.5%
AUTO-MERGE
Verdict tier: the fix passes all three lenses cleanly. In Mode C, Arguss opens a pull request for the upgrade; it does not merge PRs on GitHub.
Click for more →
Code injection in fsevents
MAL-2023-462: Malicious code in fsevents (npm)
- patch-level upgrade; trust signals unchanged; CI verifies tests
Upgrade fsevents from 1.2.9 to 1.2.11 or later
View advisoryBlast radius
Paths from project root to fsevents - which dependencies pulled this package in?
braces
@ 2.3.2
3 findings
high
Trust 0/100
EPSS 1.5%
⚠ new maintainer
REVIEW
Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk.
Click for more →
Uncontrolled resource consumption in braces
Affects 3 install paths
- major version bump requires human review (never auto-merge)
- trust veto: new maintainer added
Upgrade braces from 2.3.2 to 3.0.3 or later
View advisory- trust veto: new maintainer added
Upgrade braces from 3.0.2 to 3.0.3 or later
View advisoryBlast radius
Paths from project root to braces - which dependencies pulled this package in?
micromatch
@ 3.1.10
3 findings
medium
Trust 0/100
EPSS 1.4%
⚠ new maintainer
REVIEW
Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk.
Click for more →
Regular Expression Denial of Service (ReDoS) in micromatch
Affects 3 install paths
- major version bump requires human review (never auto-merge)
- trust veto: new maintainer added
Upgrade micromatch from 3.1.10 to 4.0.8 or later
View advisory- trust veto: new maintainer added
Upgrade micromatch from 4.0.2 to 4.0.8 or later
View advisoryBlast radius
Paths from project root to micromatch - which dependencies pulled this package in?
tmpl
@ 1.0.4
1 finding
high
Trust 55/100
EPSS 1.3%
AUTO-MERGE
Verdict tier: the fix passes all three lenses cleanly. In Mode C, Arguss opens a pull request for the upgrade; it does not merge PRs on GitHub.
Click for more →
tmpl vulnerable to Inefficient Regular Expression Complexity which may lead to resource exhaustion
- patch-level upgrade; trust signals unchanged; CI verifies tests
Upgrade tmpl from 1.0.4 to 1.0.5 or later
View advisoryBlast radius
Paths from project root to tmpl - which dependencies pulled this package in?
cross-spawn
@ 6.0.5
2 findings
high
Trust 30/100
EPSS 0.9%
AUTO-MERGE
Verdict tier: the fix passes all three lenses cleanly. In Mode C, Arguss opens a pull request for the upgrade; it does not merge PRs on GitHub.
Click for more →
Regular Expression Denial of Service (ReDoS) in cross-spawn
Affects 2 install paths
- patch-level upgrade; trust signals unchanged; CI verifies tests
Upgrade cross-spawn from 6.0.5 to 6.0.6 or later
View advisory- patch-level upgrade; trust signals unchanged; CI verifies tests
Upgrade cross-spawn from 7.0.1 to 7.0.5 or later
View advisoryBlast radius
Paths from project root to cross-spawn - which dependencies pulled this package in?
flatted
@ 2.0.1
2 findings
high
Trust 30/100
EPSS 0.8%
REVIEW
Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk.
Click for more →
flatted vulnerable to unbounded recursion DoS in parse() revive phase
Prototype Pollution via parse() in NodeJS flatted
- major version bump requires human review (never auto-merge)
Upgrade flatted from 2.0.1 to 3.4.0 or later
View advisoryBlast radius
Paths from project root to flatted - which dependencies pulled this package in?
@babel/traverse
@ 7.7.4
1 finding
critical
Trust 0/100
EPSS 0.5%
⚠ new maintainer
REVIEW
Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk.
Click for more →
Babel vulnerable to arbitrary code execution when compiling specifically crafted malicious code
- trust veto: new maintainer added
Upgrade @babel/traverse from 7.7.4 to 7.23.2 or later
View advisoryBlast radius
Paths from project root to @babel/traverse - which dependencies pulled this package in?
yargs-parser
@ 10.1.0
2 findings
medium
Trust 0/100
EPSS 0.5%
⚠ new maintainer
REVIEW
Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk.
Click for more →
yargs-parser Vulnerable to Prototype Pollution
Affects 2 install paths
- major version bump requires human review (never auto-merge)
- trust veto: new maintainer added
Upgrade yargs-parser from 10.1.0 to 13.1.2 or later
View advisory- trust veto: new maintainer added
Upgrade yargs-parser from 13.1.1 to 13.1.2 or later
View advisoryBlast radius
Paths from project root to yargs-parser - which dependencies pulled this package in?
@babel/helpers
@ 7.7.4
1 finding
medium
Trust 0/100
EPSS 0.5%
⚠ new maintainer
REVIEW
Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk.
Click for more →
Babel has inefficient RegExp complexity in generated code with .replace when transpiling named capturing groups
- trust veto: new maintainer added
Upgrade @babel/helpers from 7.7.4 to 7.26.10 or later
View advisoryBlast radius
Paths from project root to @babel/helpers - which dependencies pulled this package in?
@babel/runtime
@ 7.7.4
1 finding
medium
Trust 0/100
EPSS 0.5%
⚠ new maintainer
REVIEW
Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk.
Click for more →
Babel has inefficient RegExp complexity in generated code with .replace when transpiling named capturing groups
- trust veto: new maintainer added
Upgrade @babel/runtime from 7.7.4 to 7.26.10 or later
View advisoryBlast radius
Paths from project root to @babel/runtime - which dependencies pulled this package in?
brace-expansion
@ 1.1.11
6 findings
medium–low
Trust 0/100
EPSS 0.5%
AUTO-MERGE
Verdict tier: the fix passes all three lenses cleanly. In Mode C, Arguss opens a pull request for the upgrade; it does not merge PRs on GitHub.
Click for more →
brace-expansion: Zero-step sequence causes process hang and memory exhaustion
Affects 2 install paths
brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups
Affects 2 install paths
brace-expansion Regular Expression Denial of Service vulnerability
Affects 2 install paths
- patch-level upgrade; trust signals unchanged; CI verifies tests
Upgrade brace-expansion from 1.1.11 to 1.1.13 or later
View advisoryBlast radius
Paths from project root to brace-expansion - which dependencies pulled this package in?
js-yaml
@ 3.13.1
3 findings
high–medium
Trust 30/100
EPSS 0.4%
AUTO-MERGE
Verdict tier: the fix passes all three lenses cleanly. In Mode C, Arguss opens a pull request for the upgrade; it does not merge PRs on GitHub.
Click for more →
js-yaml: YAML merge-key chains can force quadratic CPU consumption
JS-YAML: Quadratic-complexity DoS in merge key handling via repeated aliases
js-yaml has prototype pollution in merge (<<)
- minor-level upgrade; trust signals unchanged; CI verifies tests
Upgrade js-yaml from 3.13.1 to 3.15.0 or later
View advisoryBlast radius
Paths from project root to js-yaml - which dependencies pulled this package in?
picomatch
@ 2.1.1
2 findings
high–medium
Trust 0/100
EPSS 0.4%
⚠ new maintainer
REVIEW
Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk.
Click for more →
Picomatch has a ReDoS vulnerability via extglob quantifiers
Picomatch: Method Injection in POSIX Character Classes causes incorrect Glob Matching
- trust veto: new maintainer added
Upgrade picomatch from 2.1.1 to 2.3.2 or later
View advisoryBlast radius
Paths from project root to picomatch - which dependencies pulled this package in?
tmp
@ 0.0.33
2 findings
high–low
Trust 30/100
EPSS 0.4%
AUTO-MERGE
Verdict tier: the fix passes all three lenses cleanly. In Mode C, Arguss opens a pull request for the upgrade; it does not merge PRs on GitHub.
Click for more →
tmp has Path Traversal via unsanitized prefix/postfix that enables directory escape
tmp allows arbitrary temporary file / directory write via symbolic link `dir` parameter
- minor-level upgrade; trust signals unchanged; CI verifies tests
Upgrade tmp from 0.0.33 to 0.2.6 or later
View advisoryBlast radius
Paths from project root to tmp - which dependencies pulled this package in?
1 finding
high
Trust 0/100
EPSS 0.3%
⚠ ownership transferred
REVIEW
Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk.
Click for more →
uuid: Missing buffer bounds check in v3/v5/v6 when buf is provided
- major version bump requires human review (never auto-merge)
- trust veto: new maintainer added
- trust veto: package ownership transferred between versions
Upgrade uuid from 3.3.3 to 11.1.1 or later
View advisoryBlast radius
Paths from project root to uuid - which dependencies pulled this package in?
@babel/core
@ 7.7.4
1 finding
low
Trust 0/100
EPSS 0.1%
⚠ new maintainer
REVIEW
Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk.
Click for more →
@babel/core: Arbitrary File Read via sourceMappingURL Comment
- trust veto: new maintainer added
Upgrade @babel/core from 7.7.4 to 7.29.6 or later
View advisoryBlast radius
Paths from project root to @babel/core - which dependencies pulled this package in?
acorn
@ 5.7.3
1 finding
high
Trust 0/100
AUTO-MERGE
Verdict tier: the fix passes all three lenses cleanly. In Mode C, Arguss opens a pull request for the upgrade; it does not merge PRs on GitHub.
Click for more →
Regular Expression Denial of Service in Acorn
- patch-level upgrade; trust signals unchanged; CI verifies tests
Upgrade acorn from 5.7.3 to 5.7.4 or later
View advisoryBlast radius
Paths from project root to acorn - which dependencies pulled this package in?
Package status
937 packages scanned.
- 33 Review-required candidates Arguss flagged these for a human decision - nothing merges until you review them.
- 2 Packages with no automated fix +1 More with unfixable findings alongside fixable ones
- 27 Auto-merge candidates
-
- @commitlint/cli 8.2.0 direct
- @commitlint/config-conventional 8.2.0 direct
- babel-core 6.26.3 direct
- babel-jest 24.9.0 direct
- babel-preset-moxy 3.2.0 direct
- eslint 5.16.0 direct
- eslint-config-moxy 7.1.0 direct
- husky 3.1.0 direct
- jest 24.9.0 direct
- lint-staged 9.4.3 direct
- mkdirp 0.5.1 direct
- mkdirp 0.5.5 direct
- path-key 2.0.1 direct
- path-key 3.1.1 direct
- rimraf 2.6.3 direct
- rimraf 2.7.1 direct
- rimraf 3.0.0 direct
- shebang-command 1.2.0 direct
- shebang-command 2.0.0 direct
- standard-version 9.5.0 direct
- which 1.3.1 direct
- which 2.0.2 direct
- @babel/code-frame 7.5.5
- @babel/generator 7.7.4
- @babel/helper-annotate-as-pure 7.7.4
- @babel/helper-builder-binary-assignment-operator-visitor 7.7.4
- @babel/helper-builder-react-jsx 7.7.4
- @babel/helper-call-delegate 7.7.4
- @babel/helper-create-class-features-plugin 7.7.4
- @babel/helper-create-regexp-features-plugin 7.7.4
- @babel/helper-define-map 7.7.4
- @babel/helper-explode-assignable-expression 7.7.4
- @babel/helper-function-name 7.7.4
- @babel/helper-get-function-arity 7.7.4
- @babel/helper-hoist-variables 7.7.4
- @babel/helper-member-expression-to-functions 7.7.4
- @babel/helper-module-imports 7.7.4
- @babel/helper-module-transforms 7.7.4
- @babel/helper-optimise-call-expression 7.7.4
- @babel/helper-plugin-utils 7.0.0
- @babel/helper-regex 7.5.5
- @babel/helper-remap-async-to-generator 7.7.4
- @babel/helper-replace-supers 7.7.4
- @babel/helper-simple-access 7.7.4
- @babel/helper-split-export-declaration 7.7.4
- @babel/helper-wrap-function 7.7.4
- @babel/highlight 7.5.0
- @babel/parser 7.7.4
- @babel/plugin-proposal-async-generator-functions 7.7.4
- @babel/plugin-proposal-class-properties 7.7.4
- @babel/plugin-proposal-dynamic-import 7.7.4
- @babel/plugin-proposal-json-strings 7.7.4
- @babel/plugin-proposal-nullish-coalescing-operator 7.7.4
- @babel/plugin-proposal-object-rest-spread 7.7.4
- @babel/plugin-proposal-optional-catch-binding 7.7.4
- @babel/plugin-proposal-optional-chaining 7.7.4
- @babel/plugin-proposal-unicode-property-regex 7.7.4
- @babel/plugin-syntax-async-generators 7.7.4
- @babel/plugin-syntax-dynamic-import 7.7.4
- @babel/plugin-syntax-json-strings 7.7.4
- @babel/plugin-syntax-jsx 7.7.4
- @babel/plugin-syntax-nullish-coalescing-operator 7.7.4
- @babel/plugin-syntax-object-rest-spread 7.7.4
- @babel/plugin-syntax-optional-catch-binding 7.7.4
- @babel/plugin-syntax-optional-chaining 7.7.4
- @babel/plugin-syntax-top-level-await 7.7.4
- @babel/plugin-transform-arrow-functions 7.7.4
- @babel/plugin-transform-async-to-generator 7.7.4
- @babel/plugin-transform-block-scoped-functions 7.7.4
- @babel/plugin-transform-block-scoping 7.7.4
- @babel/plugin-transform-classes 7.7.4
- @babel/plugin-transform-computed-properties 7.7.4
- @babel/plugin-transform-destructuring 7.7.4
- @babel/plugin-transform-dotall-regex 7.7.4
- @babel/plugin-transform-duplicate-keys 7.7.4
- @babel/plugin-transform-exponentiation-operator 7.7.4
- @babel/plugin-transform-for-of 7.7.4
- @babel/plugin-transform-function-name 7.7.4
- @babel/plugin-transform-literals 7.7.4
- @babel/plugin-transform-member-expression-literals 7.7.4
- @babel/plugin-transform-modules-amd 7.7.4
- @babel/plugin-transform-modules-commonjs 7.7.4
- @babel/plugin-transform-modules-systemjs 7.7.4
- @babel/plugin-transform-modules-umd 7.7.4
- @babel/plugin-transform-named-capturing-groups-regex 7.7.4
- @babel/plugin-transform-new-target 7.7.4
- @babel/plugin-transform-object-super 7.7.4
- @babel/plugin-transform-parameters 7.7.4
- @babel/plugin-transform-property-literals 7.7.4
- @babel/plugin-transform-react-display-name 7.7.4
- @babel/plugin-transform-react-jsx 7.7.4
- @babel/plugin-transform-react-jsx-self 7.7.4
- @babel/plugin-transform-react-jsx-source 7.7.4
- @babel/plugin-transform-regenerator 7.7.4
- @babel/plugin-transform-reserved-words 7.7.4
- @babel/plugin-transform-runtime 7.7.4
- @babel/plugin-transform-shorthand-properties 7.7.4
- @babel/plugin-transform-spread 7.7.4
- @babel/plugin-transform-sticky-regex 7.7.4
- @babel/plugin-transform-template-literals 7.7.4
- @babel/plugin-transform-typeof-symbol 7.7.4
- @babel/plugin-transform-unicode-regex 7.7.4
- @babel/preset-env 7.7.4
- @babel/template 7.7.4
- @babel/types 7.7.4
- @cnakazawa/watch 1.0.3
- @commitlint/ensure 8.2.0
- @commitlint/execute-rule 8.2.0
- @commitlint/format 8.2.0
- @commitlint/is-ignored 8.2.0
- @commitlint/lint 8.2.0
- @commitlint/load 8.2.0
- @commitlint/message 8.2.0
- @commitlint/parse 8.2.0
- @commitlint/read 8.2.0
- @commitlint/resolve-extends 8.2.0
- @commitlint/rules 8.2.0
- @commitlint/to-lines 8.2.0
- @commitlint/top-level 8.2.0
- @hutson/parse-repository-url 3.0.2
- @jest/console 24.9.0
- @jest/core 24.9.0
- @jest/environment 24.9.0
- @jest/fake-timers 24.9.0
- @jest/reporters 24.9.0
- @jest/source-map 24.9.0
- @jest/test-result 24.9.0
- @jest/test-sequencer 24.9.0
- @jest/transform 24.9.0
- @jest/types 24.9.0
- @marionebl/sander 0.6.1
- @nodelib/fs.scandir 2.1.3
- @nodelib/fs.stat 2.0.3
- @nodelib/fs.walk 1.2.4
- @samverschueren/stream-to-observable 0.3.0
- @types/babel__core 7.1.3
- @types/babel__generator 7.6.0
- @types/babel__template 7.0.2
- @types/babel__traverse 7.0.8
- @types/events 3.0.0
- @types/glob 7.1.1
- @types/istanbul-lib-coverage 2.0.1
- @types/istanbul-lib-report 1.1.1
- @types/istanbul-reports 1.1.1
- @types/json-schema 7.0.3
- @types/minimatch 3.0.3
- @types/minimist 1.2.5
- @types/node 12.12.12
- @types/normalize-package-data 2.4.0
- @types/semver 6.2.0
- @types/stack-utils 1.0.1
- @types/yargs 13.0.3
- @types/yargs-parser 13.1.0
- @typescript-eslint/experimental-utils 1.13.0
- @typescript-eslint/typescript-estree 1.13.0
- abab 2.0.3
- abbrev 1.1.1
- acorn 6.4.1
- acorn-globals 4.3.4
- acorn-jsx 5.1.0
- acorn-walk 6.2.0
- add-stream 1.0.0
- aggregate-error 3.0.1
- ansi-escapes 3.2.0
- ansi-regex 2.1.1
- ansi-regex 5.0.1
- ansi-styles 2.2.1
- ansi-styles 3.2.1
- ansi-styles 4.3.0
- any-observable 0.3.0
- anymatch 2.0.0
- aproba 1.2.0
- are-we-there-yet 1.1.5
- argparse 1.0.10
- arr-diff 4.0.0
- arr-flatten 1.1.0
- arr-union 3.1.0
- array-equal 1.0.0
- array-find-index 1.0.2
- array-ify 1.0.0
- array-includes 3.0.3
- array-union 2.1.0
- array-unique 0.3.2
- arrify 1.0.1
- asn1 0.2.4
- assert-plus 1.0.0
- assign-symbols 1.0.0
- astral-regex 1.0.0
- async-each 1.0.3
- async-limiter 1.0.1
- asynckit 0.4.0
- atob 2.1.2
- aws-sign2 0.7.0
- aws4 1.8.0
- babel-code-frame 6.26.0
- babel-eslint 11.0.0-beta.1
- babel-generator 6.26.1
- babel-helpers 6.24.1
- babel-messages 6.23.0
- babel-plugin-add-module-exports 1.0.2
- babel-plugin-dynamic-import-node 2.3.0
- babel-plugin-istanbul 5.2.0
- babel-plugin-jest-hoist 24.9.0
- babel-plugin-lodash 3.3.4
- babel-plugin-transform-react-remove-prop-types 0.4.24
- babel-polyfill 6.26.0
- babel-preset-jest 24.9.0
- babel-register 6.26.0
- babel-runtime 6.26.0
- babel-template 6.26.0
- babel-types 6.26.0
- babylon 6.18.0
- balanced-match 1.0.0
- base 0.11.2
- bcrypt-pbkdf 1.0.2
- binary-extensions 1.13.1
- browser-process-hrtime 0.1.3
- browser-resolve 1.11.3
- browserslist-config-google 1.5.0
- bser 2.1.1
- buffer-from 1.1.1
- cache-base 1.0.1
- caller-callsite 2.0.0
- caller-path 2.0.0
- callsites 2.0.0
- callsites 3.1.0
- camelcase 4.1.0
- camelcase 5.3.1
- camelcase-keys 4.2.0
- camelcase-keys 6.2.2
- caniuse-lite 1.0.30001011
- capture-exit 2.0.0
- caseless 0.12.0
- chalk 1.1.3
- chalk 2.4.2
- chardet 0.7.0
- chokidar 2.1.8
- chownr 1.1.1
- ci-info 2.0.0
- class-utils 0.3.6
- clean-stack 2.2.0
- cli-cursor 2.1.0
- cli-truncate 0.2.1
- cli-width 2.2.0
- cliui 5.0.0
- cliui 7.0.4
- co 4.6.0
- code-point-at 1.1.0
- collection-visit 1.0.0
- color-convert 1.9.3
- color-convert 2.0.1
- color-name 1.1.3
- color-name 1.1.4
- combined-stream 1.0.8
- commander 2.20.3
- comment-parser 0.5.5
- compare-func 1.3.2
- compare-func 2.0.0
- component-emitter 1.3.0
- concat-map 0.0.1
- concat-stream 2.0.0
- console-control-strings 1.1.0
- conventional-changelog 3.1.25
- conventional-changelog-angular 1.6.6
- conventional-changelog-angular 5.0.13
- conventional-changelog-atom 2.0.8
- conventional-changelog-codemirror 2.0.8
- conventional-changelog-config-spec 2.1.0
- conventional-changelog-conventionalcommits 4.6.3
- conventional-changelog-core 4.2.4
- conventional-changelog-ember 2.0.9
- conventional-changelog-eslint 3.0.9
- conventional-changelog-express 2.0.6
- conventional-changelog-jquery 3.0.11
- conventional-changelog-jshint 2.0.9
- conventional-changelog-preset-loader 2.3.4
- conventional-changelog-writer 5.0.1
- conventional-commits-filter 2.0.7
- conventional-commits-parser 2.1.7
- conventional-commits-parser 3.2.4
- conventional-recommended-bump 6.1.0
- convert-source-map 1.7.0
- copy-descriptor 0.1.1
- core-js 2.6.10
- core-js-compat 3.4.2
- core-util-is 1.0.2
- cosmiconfig 5.2.1
- cssom 0.3.8
- cssstyle 1.4.0
- currently-unhandled 0.4.1
- dargs 4.1.0
- dargs 7.0.0
- dashdash 1.14.1
- data-urls 1.1.0
- date-fns 1.30.1
- dateformat 3.0.3
- debug 2.6.9
- decamelize 1.2.0
- decamelize-keys 1.1.0
- dedent 0.7.0
- deep-extend 0.6.0
- deep-is 0.1.3
- define-properties 1.1.3
- define-property 0.2.5
- define-property 1.0.0
- define-property 2.0.2
- del 5.1.0
- delayed-stream 1.0.0
- delegates 1.0.0
- detect-indent 4.0.0
- detect-indent 6.0.0
- detect-libc 1.0.3
- detect-newline 2.1.0
- detect-newline 3.1.0
- diff-sequences 24.9.0
- dir-glob 3.0.1
- doctrine 2.1.0
- doctrine 3.0.0
- domexception 1.0.1
- dot-prop 5.3.0
- dotgitignore 2.1.0
- ecc-jsbn 0.1.2
- electron-to-chromium 1.3.312
- elegant-spinner 1.0.1
- emoji-regex 7.0.3
- emoji-regex 8.0.0
- end-of-stream 1.4.4
- error-ex 1.3.2
- es-abstract 1.16.0
- es-to-primitive 1.2.1
- escalade 3.2.0
- escape-string-regexp 1.0.5
- escodegen 1.12.0
- eslint-plugin-babel 5.3.0
- eslint-plugin-jest 22.21.0
- eslint-plugin-jsdoc 4.8.4
- eslint-plugin-prefer-import 0.0.1
- eslint-plugin-react 7.16.0
- eslint-rule-composer 0.3.0
- eslint-scope 3.7.1
- eslint-scope 4.0.3
- eslint-utils 1.4.3
- eslint-visitor-keys 1.1.0
- espree 5.0.1
- esprima 3.1.3
- esprima 4.0.1
- esquery 1.0.1
- esrecurse 4.2.1
- estraverse 4.3.0
- esutils 2.0.3
- exec-sh 0.3.4
- execa 1.0.0
- execa 2.1.0
- exit 0.1.2
- expand-brackets 2.1.4
- expect 24.9.0
- extend 3.0.2
- extend-shallow 2.0.1
- extend-shallow 3.0.2
- external-editor 3.1.0
- extglob 2.0.4
- extsprintf 1.3.0
- fast-deep-equal 2.0.1
- fast-glob 3.1.0
- fast-json-stable-stringify 2.0.0
- fast-levenshtein 2.0.6
- fastq 1.6.0
- fb-watchman 2.0.0
- figures 1.7.0
- figures 2.0.0
- figures 3.2.0
- file-entry-cache 5.0.1
- fill-range 4.0.0
- fill-range 7.0.1
- find-up 2.1.0
- find-up 3.0.0
- find-up 4.1.0
- find-up 5.0.0
- flat-cache 2.0.1
- for-in 1.0.2
- forever-agent 0.6.1
- fragment-cache 0.2.1
- fs-minipass 1.2.5
- fs.realpath 1.0.0
- function-bind 1.1.2
- functional-red-black-tree 1.0.1
- gauge 2.7.4
- get-caller-file 2.0.5
- get-own-enumerable-property-symbols 3.0.1
- get-pkg-repo 4.2.1
- get-stdin 7.0.0
- get-stream 4.1.0
- get-stream 5.1.0
- get-value 2.0.6
- getpass 0.1.7
- git-raw-commits 1.3.6
- git-raw-commits 2.0.11
- git-remote-origin-url 2.0.0
- git-semver-tags 4.1.1
- gitconfiglocal 1.0.0
- glob 7.1.3
- glob 7.1.6
- glob-parent 3.1.0
- global-dirs 0.1.1
- globals 11.12.0
- globals 9.18.0
- globby 10.0.1
- graceful-fs 4.2.3
- growly 1.3.0
- har-schema 2.0.0
- har-validator 5.1.3
- hard-rejection 2.1.0
- has 1.0.3
- has-ansi 2.0.0
- has-flag 3.0.0
- has-symbols 1.0.1
- has-unicode 2.0.1
- has-value 0.3.1
- has-value 1.0.0
- has-values 0.1.4
- has-values 1.0.0
- hasown 2.0.2
- home-or-tmp 2.0.0
- hosted-git-info 2.8.9
- hosted-git-info 4.1.0
- html-encoding-sniffer 1.0.2
- html-escaper 2.0.2
- http-signature 1.2.0
- iconv-lite 0.4.24
- ignore 4.0.6
- ignore 5.1.4
- ignore-walk 3.0.1
- import-fresh 2.0.0
- import-fresh 3.2.1
- import-local 2.0.0
- imurmurhash 0.1.4
- indent-string 3.2.0
- indent-string 4.0.0
- inflight 1.0.6
- inherits 2.0.3
- inherits 2.0.4
- inquirer 6.5.2
- invariant 2.2.4
- is-accessor-descriptor 0.1.6
- is-accessor-descriptor 1.0.0
- is-arrayish 0.2.1
- is-binary-path 1.0.1
- is-buffer 1.1.6
- is-callable 1.1.4
- is-ci 2.0.0
- is-core-module 2.15.1
- is-data-descriptor 0.1.4
- is-data-descriptor 1.0.0
- is-date-object 1.0.1
- is-descriptor 0.1.6
- is-descriptor 1.0.2
- is-directory 0.3.1
- is-extendable 0.1.1
- is-extendable 1.0.1
- is-extglob 2.1.1
- is-finite 1.0.2
- is-fullwidth-code-point 1.0.0
- is-fullwidth-code-point 2.0.0
- is-fullwidth-code-point 3.0.0
- is-generator-fn 2.1.0
- is-glob 3.1.0
- is-glob 4.0.1
- is-number 3.0.0
- is-number 7.0.0
- is-obj 1.0.1
- is-obj 2.0.0
- is-observable 1.1.0
- is-path-cwd 2.2.0
- is-path-inside 3.0.2
- is-plain-obj 1.1.0
- is-plain-object 2.0.4
- is-promise 2.1.0
- is-regex 1.0.4
- is-regexp 1.0.0
- is-stream 1.1.0
- is-stream 2.0.0
- is-symbol 1.0.3
- is-text-path 1.0.1
- is-typedarray 1.0.0
- is-windows 1.0.2
- is-wsl 1.1.0
- isarray 1.0.0
- isexe 2.0.0
- isobject 2.1.0
- isobject 3.0.1
- isstream 0.1.2
- istanbul-lib-coverage 2.0.5
- istanbul-lib-instrument 3.3.0
- istanbul-lib-report 2.0.8
- istanbul-lib-source-maps 3.0.6
- istanbul-reports 2.2.7
- jest-changed-files 24.9.0
- jest-cli 24.9.0
- jest-config 24.9.0
- jest-diff 24.9.0
- jest-docblock 24.9.0
- jest-each 24.9.0
- jest-environment-jsdom 24.9.0
- jest-environment-node 24.9.0
- jest-get-type 24.9.0
- jest-haste-map 24.9.0
- jest-jasmine2 24.9.0
- jest-leak-detector 24.9.0
- jest-matcher-utils 24.9.0
- jest-message-util 24.9.0
- jest-mock 24.9.0
- jest-pnp-resolver 1.2.1
- jest-regex-util 24.9.0
- jest-resolve 24.9.0
- jest-resolve-dependencies 24.9.0
- jest-runner 24.9.0
- jest-runtime 24.9.0
- jest-serializer 24.9.0
- jest-snapshot 24.9.0
- jest-util 24.9.0
- jest-validate 24.9.0
- jest-watcher 24.9.0
- jest-worker 24.9.0
- js-levenshtein 1.1.6
- js-tokens 3.0.2
- js-tokens 4.0.0
- jsbn 0.1.1
- jsdoctypeparser 3.1.0
- jsdom 11.12.0
- jsesc 0.5.0
- jsesc 1.3.0
- jsesc 2.5.2
- json-parse-better-errors 1.0.2
- json-parse-even-better-errors 2.3.1
- json-schema-traverse 0.4.1
- json-stable-stringify-without-jsonify 1.0.1
- json-stringify-safe 5.0.1
- jsonparse 1.3.1
- JSONStream 1.3.5
- jsprim 1.4.1
- jsx-ast-utils 2.2.3
- kind-of 3.2.2
- kind-of 4.0.0
- kind-of 5.1.0
- kind-of 6.0.3
- kleur 3.0.3
- left-pad 1.3.0
- leven 3.1.0
- levn 0.3.0
- lines-and-columns 1.1.6
- listr 0.14.3
- listr-silent-renderer 1.1.1
- listr-update-renderer 0.5.0
- listr-verbose-renderer 0.5.0
- load-json-file 4.0.0
- locate-path 2.0.0
- locate-path 3.0.0
- locate-path 5.0.0
- locate-path 6.0.0
- lodash._reinterpolate 3.0.0
- lodash.ismatch 4.4.0
- lodash.sortby 4.7.0
- lodash.templatesettings 4.2.0
- lodash.unescape 4.0.1
- log-symbols 1.0.2
- log-symbols 3.0.0
- log-update 2.3.0
- loose-envify 1.4.0
- loud-rejection 1.6.0
- lru-cache 6.0.0
- make-dir 2.1.0
- makeerror 1.0.11
- map-cache 0.2.2
- map-obj 1.0.1
- map-obj 2.0.0
- map-obj 4.3.0
- map-visit 1.0.0
- meow 4.0.1
- meow 5.0.0
- meow 8.1.2
- merge-stream 2.0.0
- merge2 1.3.0
- mime-db 1.42.0
- mime-types 2.1.25
- mimic-fn 1.2.0
- mimic-fn 2.1.0
- min-indent 1.0.1
- minimist-options 3.0.2
- minimist-options 4.1.0
- minipass 2.3.5
- minizlib 1.2.1
- mixin-deep 1.3.2
- modify-values 1.0.1
- ms 2.0.0
- ms 2.1.1
- ms 2.1.2
- mute-stream 0.0.7
- nan 2.14.0
- nanomatch 1.2.13
- natural-compare 1.4.0
- needle 2.3.0
- neo-async 2.6.2
- nice-try 1.0.5
- node-int64 0.4.0
- node-modules-regexp 1.0.0
- node-pre-gyp 0.12.0
- node-releases 1.1.41
- nopt 4.0.1
- normalize-package-data 2.5.0
- normalize-package-data 3.0.3
- normalize-path 2.1.1
- normalize-path 3.0.0
- npm-bundled 1.0.6
- npm-packlist 1.4.1
- npm-run-path 2.0.2
- npm-run-path 3.1.0
- npmlog 4.1.2
- number-is-nan 1.0.1
- nwsapi 2.2.0
- oauth-sign 0.9.0
- object-assign 4.1.1
- object-copy 0.1.0
- object-inspect 1.7.0
- object-keys 1.1.1
- object-visit 1.0.1
- object.assign 4.1.0
- object.entries 1.1.0
- object.fromentries 2.0.1
- object.getownpropertydescriptors 2.0.3
- object.pick 1.3.0
- object.values 1.1.0
- once 1.4.0
- onetime 2.0.1
- onetime 5.1.0
- opencollective-postinstall 2.0.2
- optionator 0.8.3
- os-homedir 1.0.2
- os-tmpdir 1.0.2
- osenv 0.1.5
- p-each-series 1.0.0
- p-finally 1.0.0
- p-finally 2.0.1
- p-limit 1.3.0
- p-limit 2.2.1
- p-limit 2.3.0
- p-limit 3.1.0
- p-locate 2.0.0
- p-locate 3.0.0
- p-locate 4.1.0
- p-locate 5.0.0
- p-map 2.1.0
- p-map 3.0.0
- p-reduce 1.0.0
- p-try 1.0.0
- p-try 2.2.0
- parent-module 1.0.1
- parse-json 4.0.0
- parse-json 5.0.0
- parse-json 5.2.0
- parse5 4.0.0
- pascalcase 0.1.1
- path-dirname 1.0.2
- path-exists 3.0.0
- path-exists 4.0.0
- path-is-absolute 1.0.1
- path-is-inside 1.0.2
- path-type 3.0.0
- path-type 4.0.0
- performance-now 2.1.0
- pify 2.3.0
- pify 3.0.0
- pify 4.0.1
- pirates 4.0.1
- pkg-dir 3.0.0
- pkg-dir 4.2.0
- please-upgrade-node 3.2.0
- pn 1.1.0
- posix-character-classes 0.1.1
- prelude-ls 1.1.2
- pretty-format 24.9.0
- private 0.1.8
- process-nextick-args 2.0.0
- process-nextick-args 2.0.1
- progress 2.0.3
- prompts 2.3.0
- prop-types 15.7.2
- psl 1.4.0
- pump 3.0.0
- punycode 1.4.1
- punycode 2.1.1
- q 1.5.1
- quick-lru 1.1.0
- quick-lru 4.0.1
- rc 1.2.8
- react-is 16.12.0
- read-pkg 3.0.0
- read-pkg 5.2.0
- read-pkg-up 3.0.0
- read-pkg-up 4.0.0
- read-pkg-up 7.0.1
- readable-stream 2.3.6
- readable-stream 3.6.2
- readdirp 2.2.1
- realpath-native 1.1.0
- redent 2.0.0
- redent 3.0.0
- regenerate 1.4.0
- regenerate-unicode-properties 8.1.0
- regenerator-runtime 0.10.5
- regenerator-runtime 0.11.1
- regenerator-runtime 0.13.3
- regenerator-transform 0.14.1
- regex-not 1.0.2
- regexpp 2.0.1
- regexpu-core 4.6.0
- regjsgen 0.5.1
- regjsparser 0.6.0
- remove-trailing-separator 1.1.0
- repeat-element 1.1.3
- repeat-string 1.6.1
- repeating 2.0.1
- request-promise-core 1.1.3
- request-promise-native 1.0.8
- require-directory 2.1.1
- require-main-filename 2.0.0
- require-package-name 2.0.1
- resolve 1.1.7
- resolve 1.12.2
- resolve-cwd 2.0.0
- resolve-from 3.0.0
- resolve-from 4.0.0
- resolve-from 5.0.0
- resolve-global 1.0.0
- resolve-url 0.2.1
- restore-cursor 2.0.0
- ret 0.1.15
- reusify 1.0.4
- rsvp 4.8.5
- run-async 2.3.0
- run-node 1.0.0
- run-parallel 1.1.9
- rxjs 6.5.3
- safe-buffer 5.1.2
- safe-regex 1.1.0
- safer-buffer 2.1.2
- sane 4.1.0
- sax 1.2.4
- semver 5.7.2
- semver 7.6.3
- semver-compare 1.0.0
- set-blocking 2.0.0
- set-value 2.0.1
- shebang-regex 1.0.0
- shebang-regex 3.0.0
- shellwords 0.1.1
- signal-exit 3.0.2
- sisteransi 1.0.4
- slash 1.0.0
- slash 2.0.0
- slash 3.0.0
- slice-ansi 0.0.4
- slice-ansi 2.1.0
- snapdragon 0.8.2
- snapdragon-node 2.1.1
- snapdragon-util 3.0.1
- source-map 0.5.7
- source-map 0.6.1
- source-map-resolve 0.5.2
- source-map-support 0.4.18
- source-map-support 0.5.16
- source-map-url 0.4.0
- spdx-correct 3.1.0
- spdx-exceptions 2.2.0
- spdx-expression-parse 3.0.0
- spdx-license-ids 3.0.5
- split 1.0.1
- split-string 3.1.0
- split2 2.2.0
- split2 3.2.2
- sprintf-js 1.0.3
- sshpk 1.16.1
- stack-utils 1.0.2
- static-extend 0.1.2
- stealthy-require 1.1.1
- string-argv 0.3.1
- string-length 2.0.0
- string-width 1.0.2
- string-width 2.1.1
- string-width 3.1.0
- string-width 4.2.3
- string.prototype.trimleft 2.1.0
- string.prototype.trimright 2.1.0
- string_decoder 1.1.1
- stringify-object 3.3.0
- stringify-package 1.0.1
- strip-ansi 3.0.1
- strip-ansi 4.0.0
- strip-ansi 5.2.0
- strip-ansi 6.0.1
- strip-bom 3.0.0
- strip-eof 1.0.0
- strip-final-newline 2.0.0
- strip-indent 2.0.0
- strip-indent 3.0.0
- strip-json-comments 2.0.1
- supports-color 2.0.0
- supports-color 5.5.0
- supports-color 6.1.0
- symbol-observable 1.2.0
- symbol-tree 3.2.4
- table 5.4.6
- test-exclude 5.2.3
- text-extensions 1.9.0
- text-table 0.2.0
- throat 4.1.0
- through 2.3.8
- through2 2.0.5
- through2 4.0.2
- to-fast-properties 1.0.3
- to-fast-properties 2.0.0
- to-object-path 0.3.0
- to-regex 3.0.2
- to-regex-range 2.1.1
- to-regex-range 5.0.1
- tr46 1.0.1
- trim-newlines 3.0.1
- trim-right 1.0.1
- tslib 1.10.0
- tunnel-agent 0.6.0
- tweetnacl 0.14.5
- type-check 0.3.2
- type-fest 0.18.1
- type-fest 0.6.0
- type-fest 0.8.1
- typedarray 0.0.6
- uglify-js 3.19.3
- unicode-canonical-property-names-ecmascript 1.0.4
- unicode-match-property-ecmascript 1.0.4
- unicode-match-property-value-ecmascript 1.1.0
- unicode-property-aliases-ecmascript 1.0.5
- union-value 1.0.1
- unset-value 1.0.0
- upath 1.2.0
- uri-js 4.2.2
- urix 0.1.0
- use 3.1.1
- util-deprecate 1.0.2
- util.promisify 1.0.0
- validate-npm-package-license 3.0.4
- verror 1.10.0
- w3c-hr-time 1.0.1
- walker 1.0.7
- webidl-conversions 4.0.2
- whatwg-encoding 1.0.5
- whatwg-mimetype 2.3.0
- whatwg-url 6.5.0
- whatwg-url 7.1.0
- which-module 2.0.0
- wide-align 1.1.3
- wordwrap 1.0.0
- wrap-ansi 3.0.1
- wrap-ansi 5.1.0
- wrap-ansi 7.0.0
- wrappy 1.0.2
- write 1.0.3
- write-file-atomic 2.4.1
- xml-name-validator 3.0.0
- xtend 4.0.2
- y18n 5.0.8
- yallist 3.0.3
- yallist 4.0.0
- yargs 13.3.0
- yargs 16.2.0
- yargs-parser 20.2.9
- yocto-queue 0.1.0
Review auto-merge candidates and open PRs in a guided flow.
Glossary
What the labels and signals mean.
Glossary
What the labels and signals mean.
- Trust Save
- A package upgrade Arguss would have blocked despite the new version being available, because trust signals, like ownership transfer or a new maintainer, fired during the upgrade window. The name reflects what the agent did for the user: saved them from a potentially malicious update that a version-only auto-PR tool would have merged.
- AUTO-MERGE
- Verdict tier indicating the fix passes all three lenses cleanly. After you confirm action from a Scan assessment, Arguss opens a pull request for the upgrade; it does not merge PRs on GitHub. The envelope is conservative on purpose: patch or minor version bump, trust signals unchanged, blast radius bounded, real tests pass.
- REVIEW
- Verdict tier requiring a human decision. At least one veto fired during fix-confidence evaluation, trust signals shifted, the pipeline can't verify post-upgrade behavior, or the upgrade is a major version bump. The agent surfaces the reasons; the developer decides.
- DECLINE
- Verdict tier indicating no remediation is recommended. Typically applies when no fix version exists for the finding, or when multiple critical vetoes make even human review unproductive.
fix_kind.major- Veto signal that fires when the available fix requires a major version bump (1.x → 2.x). Major bumps imply potential breaking changes and fall outside the auto-merge envelope by default, even when the upgrade is the only available fix.
trust.new_maintainer- Veto signal that fires when a package added a new maintainer during the upgrade window, meaning between the user's current version and the proposed upgrade. New publishing identities are a well-documented attack vector for typosquats and supply chain takeovers.
trust.ownership_transferred- Veto signal that fires when a package's primary maintainer changed during the upgrade window. Combined with
trust.new_maintainer, this is the highest-risk trust combination, typical of the xz-utils style attacks and historical npm credential theft incidents. pipeline.test_reality- Veto signal that fires when Arguss can't verify tests will run on the upgraded code. Four conditions must hold: a test script exists in
package.json, it isn't a no-op, real test files exist, and a workflow actually invokes them. If any fail, the fix cannot qualify for AUTO_MERGE because there's no way to verify the upgrade didn't break the user's project. - CVSS
- Common Vulnerability Scoring System. A numeric score (0.0–10.0) representing how damaging a vulnerability could be if exploited. Sourced from NIST's National Vulnerability Database via OSV.dev. Severity, not urgency.
- EPSS
- Exploit Prediction Scoring System. A daily-updated probability (0.0–1.0, displayed as percent) that a CVE will be exploited in the next 30 days. Sourced from FIRST.org. Probability, not severity.
- KEV
- CISA's Known Exploited Vulnerabilities catalog. A federal list of CVEs with documented active exploitation in the wild. Federal agencies have a binding patching deadline; for everyone else, presence on KEV is the strongest "this is being used right now" signal available. Sourced directly from CISA.
- Project Risk Score (PRS)
- A weighted blend of the three lens subscores (40% vulnerability, 30% trust, 30% pipeline) producing an overall 0–100 indicator of the project's dependency health. Useful for at-a-glance triage; the per-finding fix-confidence verdicts are what drive automated decisions.
Dependency graph
Full-project map of transitive dependencies. Severity colors reflect vulnerabilities; trust rings apply only to direct dependencies analyzed by OpenSSF Scorecard (higher = riskier).