Findings
serialize-javascript
@ 6.0.2
2 findings
high–medium
Trust 0/100
EPSS 0.5%
REVIEW
Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk.
Click for more →
Serialize JavaScript has CPU Exhaustion Denial of Service via crafted array-like objects
- major version bump requires human review (never auto-merge)
Upgrade serialize-javascript from 6.0.2 to 7.0.3 or later
View advisoryBlast radius
Paths from project root to serialize-javascript - which dependencies pulled this package in?
brace-expansion
@ 2.0.2
6 findings
medium
Trust 0/100
EPSS 0.4%
AUTO-MERGE
Verdict tier: the fix passes all three lenses cleanly. In Mode C, Arguss opens a pull request for the upgrade; it does not merge PRs on GitHub.
Click for more →
brace-expansion: Zero-step sequence causes process hang and memory exhaustion
Affects 2 install paths
brace-expansion: Large numeric range defeats documented `max` DoS protection
brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups
Affects 3 install paths
- minor-level upgrade; trust signals unchanged; CI verifies tests
Upgrade brace-expansion from 2.0.2 to 2.0.3 or later
View advisory- patch-level upgrade; trust signals unchanged; CI verifies tests
Upgrade brace-expansion from 5.0.5 to 5.0.6 or later
View advisoryBlast radius
Paths from project root to brace-expansion - which dependencies pulled this package in?
js-yaml
@ 4.1.1
2 findings
high–medium
Trust 30/100
EPSS 0.4%
AUTO-MERGE
Verdict tier: the fix passes all three lenses cleanly. In Mode C, Arguss opens a pull request for the upgrade; it does not merge PRs on GitHub.
Click for more →
js-yaml: YAML merge-key chains can force quadratic CPU consumption
JS-YAML: Quadratic-complexity DoS in merge key handling via repeated aliases
- minor-level upgrade; trust signals unchanged; CI verifies tests
Upgrade js-yaml from 4.1.1 to 4.3.0 or later
View advisoryBlast radius
Paths from project root to js-yaml - which dependencies pulled this package in?
qs
@ 6.15.0
1 finding
medium
Trust 0/100
EPSS 0.4%
AUTO-MERGE
Verdict tier: the fix passes all three lenses cleanly. In Mode C, Arguss opens a pull request for the upgrade; it does not merge PRs on GitHub.
Click for more →
qs has a remotely triggerable DoS: qs.stringify crashes with TypeError on null/undefined entries in comma-format arrays when encodeValuesOnly is set
- patch-level upgrade; trust signals unchanged; CI verifies tests
Upgrade qs from 6.15.0 to 6.15.2 or later
View advisoryBlast radius
Paths from project root to qs - which dependencies pulled this package in?
fast-xml-parser
@ 5.5.9
1 finding
medium
Trust 30/100
EPSS 0.2%
AUTO-MERGE
Verdict tier: the fix passes all three lenses cleanly. In Mode C, Arguss opens a pull request for the upgrade; it does not merge PRs on GitHub.
Click for more →
fast-xml-parser XMLBuilder: XML Comment and CDATA Injection via Unescaped Delimiters
- minor-level upgrade; trust signals unchanged; CI verifies tests
Upgrade fast-xml-parser from 5.5.9 to 5.7.0 or later
View advisoryBlast radius
Paths from project root to fast-xml-parser - which dependencies pulled this package in?
fast-xml-builder
@ 1.1.4
1 finding
medium
Trust 30/100
EPSS 0.2%
AUTO-MERGE
Verdict tier: the fix passes all three lenses cleanly. In Mode C, Arguss opens a pull request for the upgrade; it does not merge PRs on GitHub.
Click for more →
fast-xml-builder allows attribute values with unwanted quotes to bypass malicious or unwanted attributes
- patch-level upgrade; trust signals unchanged; CI verifies tests
Upgrade fast-xml-builder from 1.1.4 to 1.1.7 or later
View advisoryBlast radius
Paths from project root to fast-xml-builder - which dependencies pulled this package in?
esbuild
@ 0.27.4
1 finding
low
Trust 30/100
AUTO-MERGE
Verdict tier: the fix passes all three lenses cleanly. In Mode C, Arguss opens a pull request for the upgrade; it does not merge PRs on GitHub.
Click for more →
esbuild allows arbitrary file read when running the development server on Windows
- minor-level upgrade; trust signals unchanged; CI verifies tests
Upgrade esbuild from 0.27.4 to 0.28.1 or later
View advisoryBlast radius
Paths from project root to esbuild - which dependencies pulled this package in?
Package status
370 packages scanned.
- 1 Review-required candidate Arguss flagged these for a human decision - nothing merges until you review them.
- 7 Auto-merge candidates
-
- @dprint/formatter 0.4.1 direct
- @dprint/typescript 0.93.4 direct
- @esfx/canceltoken 1.0.0 direct
- @eslint/js 10.0.1 direct
- @octokit/rest 22.0.1 direct
- @types/chai 4.3.20 direct
- @types/minimist 1.2.5 direct
- @types/mocha 10.0.10 direct
- @types/ms 2.1.0 direct
- @types/node 25.5.0 direct
- @types/source-map-support 0.5.10 direct
- @types/which 3.0.4 direct
- @typescript-eslint/rule-tester 8.57.2 direct
- @typescript-eslint/type-utils 8.57.2 direct
- @typescript-eslint/utils 8.57.2 direct
- azure-devops-node-api 15.1.3 direct
- c8 10.1.3 direct
- chai 4.5.0 direct
- chokidar 3.6.0 direct
- chokidar 4.0.3 direct
- diff 5.2.2 direct
- diff 8.0.4 direct
- dprint 0.49.1 direct
- eslint 10.1.0 direct
- eslint-plugin-regexp 3.1.0 direct
- glob 10.5.0 direct
- glob 8.1.0 direct
- globals 17.4.0 direct
- hereby 1.14.0 direct
- jsonc-parser 3.3.1 direct
- knip 5.88.1 direct
- minimist 1.2.8 direct
- mocha 10.8.2 direct
- mocha-fivemat-progress-reporter 0.1.0 direct
- monocart-coverage-reports 2.12.9 direct
- ms 2.1.3 direct
- picocolors 1.1.1 direct
- playwright 1.58.2 direct
- source-map-support 0.5.21 direct
- tslib 2.8.1 direct
- typescript 6.0.2 direct
- typescript-eslint 8.57.2 direct
- which 2.0.2 direct
- which 3.0.1 direct
- @bcoe/v8-coverage 1.0.2
- @dprint/darwin-arm64 0.49.1
- @dprint/darwin-x64 0.49.1
- @dprint/linux-arm64-glibc 0.49.1
- @dprint/linux-arm64-musl 0.49.1
- @dprint/linux-riscv64-glibc 0.49.1
- @dprint/linux-x64-glibc 0.49.1
- @dprint/linux-x64-musl 0.49.1
- @dprint/win32-arm64 0.49.1
- @dprint/win32-x64 0.49.1
- @emnapi/core 1.9.1
- @emnapi/runtime 1.9.1
- @emnapi/wasi-threads 1.2.0
- @esbuild/aix-ppc64 0.27.4
- @esbuild/android-arm 0.27.4
- @esbuild/android-arm64 0.27.4
- @esbuild/android-x64 0.27.4
- @esbuild/darwin-arm64 0.27.4
- @esbuild/darwin-x64 0.27.4
- @esbuild/freebsd-arm64 0.27.4
- @esbuild/freebsd-x64 0.27.4
- @esbuild/linux-arm 0.27.4
- @esbuild/linux-arm64 0.27.4
- @esbuild/linux-ia32 0.27.4
- @esbuild/linux-loong64 0.27.4
- @esbuild/linux-mips64el 0.27.4
- @esbuild/linux-ppc64 0.27.4
- @esbuild/linux-riscv64 0.27.4
- @esbuild/linux-s390x 0.27.4
- @esbuild/linux-x64 0.27.4
- @esbuild/netbsd-arm64 0.27.4
- @esbuild/netbsd-x64 0.27.4
- @esbuild/openbsd-arm64 0.27.4
- @esbuild/openbsd-x64 0.27.4
- @esbuild/openharmony-arm64 0.27.4
- @esbuild/sunos-x64 0.27.4
- @esbuild/win32-arm64 0.27.4
- @esbuild/win32-ia32 0.27.4
- @esbuild/win32-x64 0.27.4
- @esfx/cancelable 1.0.0
- @esfx/disposable 1.0.0
- @eslint-community/eslint-utils 4.9.1
- @eslint-community/regexpp 4.12.2
- @eslint/config-array 0.23.3
- @eslint/config-helpers 0.5.3
- @eslint/core 1.1.1
- @eslint/object-schema 3.0.3
- @eslint/plugin-kit 0.6.1
- @humanfs/core 0.19.1
- @humanfs/node 0.16.7
- @humanwhocodes/module-importer 1.0.1
- @humanwhocodes/retry 0.4.3
- @isaacs/cliui 8.0.2
- @istanbuljs/schema 0.1.3
- @jridgewell/resolve-uri 3.1.2
- @jridgewell/sourcemap-codec 1.5.5
- @jridgewell/trace-mapping 0.3.31
- @napi-rs/wasm-runtime 1.1.1
- @nodelib/fs.scandir 2.1.5
- @nodelib/fs.stat 2.0.5
- @nodelib/fs.walk 1.2.8
- @octokit/auth-token 6.0.0
- @octokit/core 7.0.6
- @octokit/endpoint 11.0.3
- @octokit/graphql 9.0.3
- @octokit/openapi-types 27.0.0
- @octokit/plugin-paginate-rest 14.0.0
- @octokit/plugin-request-log 6.0.0
- @octokit/plugin-rest-endpoint-methods 17.0.0
- @octokit/request 10.0.8
- @octokit/request-error 7.1.0
- @octokit/types 16.0.0
- @oxc-resolver/binding-android-arm-eabi 11.19.1
- @oxc-resolver/binding-android-arm64 11.19.1
- @oxc-resolver/binding-darwin-arm64 11.19.1
- @oxc-resolver/binding-darwin-x64 11.19.1
- @oxc-resolver/binding-freebsd-x64 11.19.1
- @oxc-resolver/binding-linux-arm-gnueabihf 11.19.1
- @oxc-resolver/binding-linux-arm-musleabihf 11.19.1
- @oxc-resolver/binding-linux-arm64-gnu 11.19.1
- @oxc-resolver/binding-linux-arm64-musl 11.19.1
- @oxc-resolver/binding-linux-ppc64-gnu 11.19.1
- @oxc-resolver/binding-linux-riscv64-gnu 11.19.1
- @oxc-resolver/binding-linux-riscv64-musl 11.19.1
- @oxc-resolver/binding-linux-s390x-gnu 11.19.1
- @oxc-resolver/binding-linux-x64-gnu 11.19.1
- @oxc-resolver/binding-linux-x64-musl 11.19.1
- @oxc-resolver/binding-openharmony-arm64 11.19.1
- @oxc-resolver/binding-wasm32-wasi 11.19.1
- @oxc-resolver/binding-win32-arm64-msvc 11.19.1
- @oxc-resolver/binding-win32-ia32-msvc 11.19.1
- @oxc-resolver/binding-win32-x64-msvc 11.19.1
- @pkgjs/parseargs 0.11.0
- @tybys/wasm-util 0.10.1
- @types/esrecurse 4.3.1
- @types/estree 1.0.8
- @types/istanbul-lib-coverage 2.0.6
- @types/json-schema 7.0.15
- @typescript-eslint/eslint-plugin 8.57.2
- @typescript-eslint/parser 8.57.2
- @typescript-eslint/project-service 8.57.2
- @typescript-eslint/scope-manager 8.57.2
- @typescript-eslint/tsconfig-utils 8.57.2
- @typescript-eslint/types 8.57.2
- @typescript-eslint/typescript-estree 8.57.2
- @typescript-eslint/visitor-keys 8.57.2
- acorn 8.16.0
- acorn-jsx 5.3.2
- acorn-loose 8.5.2
- acorn-walk 8.3.5
- ajv 6.14.0
- ansi-colors 4.1.3
- ansi-regex 5.0.1
- ansi-regex 6.2.2
- ansi-styles 4.3.0
- ansi-styles 6.2.3
- anymatch 3.1.3
- argparse 2.0.1
- assertion-error 1.1.0
- balanced-match 1.0.2
- balanced-match 4.0.4
- before-after-hook 4.0.0
- binary-extensions 2.3.0
- braces 3.0.3
- browser-stdout 1.3.1
- buffer-from 1.1.2
- call-bind-apply-helpers 1.0.2
- call-bound 1.0.4
- camelcase 6.3.0
- chalk 4.1.2
- check-error 1.0.3
- cliui 7.0.4
- cliui 8.0.1
- color-convert 2.0.1
- color-name 1.1.4
- commander 14.0.3
- comment-parser 1.4.5
- console-grid 2.2.3
- convert-source-map 2.0.0
- cross-spawn 7.0.6
- debug 4.4.3
- decamelize 4.0.0
- deep-eql 4.1.4
- deep-is 0.1.4
- des.js 1.1.0
- dunder-proto 1.0.1
- eastasianwidth 0.2.0
- eight-colors 1.3.1
- emoji-regex 8.0.0
- emoji-regex 9.2.2
- es-define-property 1.0.1
- es-errors 1.3.0
- es-object-atoms 1.1.1
- escalade 3.2.0
- escape-string-regexp 4.0.0
- eslint-scope 9.1.2
- eslint-visitor-keys 3.4.3
- eslint-visitor-keys 5.0.1
- espree 11.2.0
- esquery 1.7.0
- esrecurse 4.3.0
- estraverse 5.3.0
- esutils 2.0.3
- fast-content-type-parse 3.0.0
- fast-deep-equal 3.1.3
- fast-glob 3.3.3
- fast-json-stable-stringify 2.1.0
- fast-levenshtein 2.0.6
- fastest-levenshtein 1.0.16
- fastq 1.20.1
- fd-package-json 2.0.0
- fdir 6.5.0
- file-entry-cache 8.0.0
- fill-range 7.1.1
- find-up 5.0.0
- flat 5.0.2
- flat-cache 4.0.1
- flatted 3.4.2
- foreground-child 3.3.1
- formatly 0.3.0
- fs.realpath 1.0.0
- fsevents 2.3.2
- function-bind 1.1.2
- get-caller-file 2.0.5
- get-func-name 2.0.2
- get-intrinsic 1.3.0
- get-proto 1.0.1
- glob-parent 5.1.2
- glob-parent 6.0.2
- gopd 1.2.0
- has-flag 4.0.0
- has-symbols 1.1.0
- hasown 2.0.2
- he 1.2.0
- html-escaper 2.0.2
- ignore 5.3.2
- ignore 7.0.5
- imurmurhash 0.1.4
- inflight 1.0.6
- inherits 2.0.4
- is-binary-path 2.1.0
- is-extglob 2.1.1
- is-fullwidth-code-point 3.0.0
- is-glob 4.0.3
- is-number 7.0.0
- is-plain-obj 2.1.0
- is-unicode-supported 0.1.0
- isexe 2.0.0
- istanbul-lib-coverage 3.2.2
- istanbul-lib-report 3.0.1
- istanbul-reports 3.2.0
- jackspeak 3.4.3
- jiti 2.6.1
- js-md4 0.3.2
- jsdoc-type-pratt-parser 7.1.1
- json-buffer 3.0.1
- json-schema-traverse 0.4.1
- json-stable-stringify-without-jsonify 1.0.1
- json-with-bigint 3.5.8
- keyv 4.5.4
- levn 0.4.1
- locate-path 6.0.0
- lodash.merge 4.6.2
- log-symbols 4.1.0
- loupe 2.3.7
- lru-cache 10.4.3
- lz-utils 2.1.0
- make-dir 4.0.0
- math-intrinsics 1.1.0
- merge2 1.4.1
- micromatch 4.0.8
- minimalistic-assert 1.0.1
- minimatch 10.2.4
- minimatch 5.1.9
- minimatch 9.0.9
- minipass 7.1.3
- monocart-locator 1.0.2
- natural-compare 1.4.0
- normalize-path 3.0.0
- object-inspect 1.13.4
- once 1.4.0
- optionator 0.9.4
- oxc-resolver 11.19.1
- p-limit 3.1.0
- p-locate 5.0.0
- package-json-from-dist 1.0.1
- path-exists 4.0.0
- path-expression-matcher 1.2.0
- path-key 3.1.1
- path-scurry 1.11.1
- pathval 1.1.1
- picomatch 2.3.2
- picomatch 4.0.4
- playwright-core 1.58.2
- prelude-ls 1.2.1
- punycode 2.3.1
- queue-microtask 1.2.3
- randombytes 2.1.0
- readdirp 3.6.0
- readdirp 4.1.2
- refa 0.12.1
- regexp-ast-analysis 0.7.1
- require-directory 2.1.1
- reusify 1.1.0
- run-parallel 1.2.0
- safe-buffer 5.2.1
- scslre 0.3.0
- semver 7.7.4
- shebang-command 2.0.0
- shebang-regex 3.0.0
- side-channel 1.1.0
- side-channel-list 1.0.0
- side-channel-map 1.0.1
- side-channel-weakmap 1.0.2
- signal-exit 4.1.0
- smol-toml 1.6.1
- source-map 0.6.1
- string-width 4.2.3
- string-width 5.1.2
- string-width-cjs 4.2.3
- strip-ansi 6.0.1
- strip-ansi 7.2.0
- strip-ansi-cjs 6.0.1
- strip-json-comments 3.1.1
- strip-json-comments 5.0.3
- strnum 2.2.2
- supports-color 7.2.0
- supports-color 8.1.1
- test-exclude 7.0.2
- tinyglobby 0.2.15
- to-regex-range 5.0.1
- ts-api-utils 2.5.0
- tunnel 0.0.6
- type-check 0.4.0
- type-detect 4.1.0
- typed-rest-client 2.1.0
- unbash 2.2.0
- underscore 1.13.8
- undici-types 7.18.2
- universal-user-agent 7.0.3
- uri-js 4.4.1
- v8-to-istanbul 9.3.0
- walk-up-path 4.0.0
- word-wrap 1.2.5
- workerpool 6.5.1
- wrap-ansi 7.0.0
- wrap-ansi 8.1.0
- wrap-ansi-cjs 7.0.0
- wrappy 1.0.2
- y18n 5.0.8
- yaml 2.8.3
- yargs 16.2.0
- yargs 17.7.2
- yargs-parser 20.2.9
- yargs-parser 21.1.1
- yargs-unparser 2.0.0
- yocto-queue 0.1.0
- zod 4.3.6
Review auto-merge candidates and open PRs in a guided flow.
Glossary
What the labels and signals mean.
Glossary
What the labels and signals mean.
- Trust Save
- A package upgrade Arguss would have blocked despite the new version being available, because trust signals, like ownership transfer or a new maintainer, fired during the upgrade window. The name reflects what the agent did for the user: saved them from a potentially malicious update that a version-only auto-PR tool would have merged.
- AUTO-MERGE
- Verdict tier indicating the fix passes all three lenses cleanly. After you confirm action from a Scan assessment, Arguss opens a pull request for the upgrade; it does not merge PRs on GitHub. The envelope is conservative on purpose: patch or minor version bump, trust signals unchanged, blast radius bounded, real tests pass.
- REVIEW
- Verdict tier requiring a human decision. At least one veto fired during fix-confidence evaluation, trust signals shifted, the pipeline can't verify post-upgrade behavior, or the upgrade is a major version bump. The agent surfaces the reasons; the developer decides.
- DECLINE
- Verdict tier indicating no remediation is recommended. Typically applies when no fix version exists for the finding, or when multiple critical vetoes make even human review unproductive.
fix_kind.major- Veto signal that fires when the available fix requires a major version bump (1.x → 2.x). Major bumps imply potential breaking changes and fall outside the auto-merge envelope by default, even when the upgrade is the only available fix.
trust.new_maintainer- Veto signal that fires when a package added a new maintainer during the upgrade window, meaning between the user's current version and the proposed upgrade. New publishing identities are a well-documented attack vector for typosquats and supply chain takeovers.
trust.ownership_transferred- Veto signal that fires when a package's primary maintainer changed during the upgrade window. Combined with
trust.new_maintainer, this is the highest-risk trust combination, typical of the xz-utils style attacks and historical npm credential theft incidents. pipeline.test_reality- Veto signal that fires when Arguss can't verify tests will run on the upgraded code. Four conditions must hold: a test script exists in
package.json, it isn't a no-op, real test files exist, and a workflow actually invokes them. If any fail, the fix cannot qualify for AUTO_MERGE because there's no way to verify the upgrade didn't break the user's project. - CVSS
- Common Vulnerability Scoring System. A numeric score (0.0–10.0) representing how damaging a vulnerability could be if exploited. Sourced from NIST's National Vulnerability Database via OSV.dev. Severity, not urgency.
- EPSS
- Exploit Prediction Scoring System. A daily-updated probability (0.0–1.0, displayed as percent) that a CVE will be exploited in the next 30 days. Sourced from FIRST.org. Probability, not severity.
- KEV
- CISA's Known Exploited Vulnerabilities catalog. A federal list of CVEs with documented active exploitation in the wild. Federal agencies have a binding patching deadline; for everyone else, presence on KEV is the strongest "this is being used right now" signal available. Sourced directly from CISA.
- Project Risk Score (PRS)
- A weighted blend of the three lens subscores (40% vulnerability, 30% trust, 30% pipeline) producing an overall 0–100 indicator of the project's dependency health. Useful for at-a-glance triage; the per-finding fix-confidence verdicts are what drive automated decisions.
Dependency graph
Full-project map of transitive dependencies. Severity colors reflect vulnerabilities; trust rings apply only to direct dependencies analyzed by OpenSSF Scorecard (higher = riskier).