Findings
lodash
@ 4.17.21
3 findings
high–medium
Trust 0/100
EPSS 22.4% ↑
AUTO-MERGE
Verdict tier: the fix passes all three lenses cleanly. In Mode C, Arguss opens a pull request for the upgrade; it does not merge PRs on GitHub.
Click for more →
lodash vulnerable to Prototype Pollution via array path bypass in `_.unset` and `_.omit`
Lodash has Prototype Pollution Vulnerability in `_.unset` and `_.omit` functions
- minor-level upgrade; trust signals unchanged; CI verifies tests
Upgrade lodash from 4.17.21 to 4.18.0 or later
View advisoryBlast radius
Paths from project root to lodash - which dependencies pulled this package in?
glob
@ 10.4.5
10 findings
high
Trust 30/100
EPSS 3.1%
AUTO-MERGE
Verdict tier: the fix passes all three lenses cleanly. In Mode C, Arguss opens a pull request for the upgrade; it does not merge PRs on GitHub.
Click for more →
glob CLI: Command injection via -c/--cmd executes matches with shell:true
Affects 10 install paths
- minor-level upgrade; trust signals unchanged; CI verifies tests
Upgrade glob from 10.4.5 to 10.5.0 or later
View advisoryBlast radius
Paths from project root to glob - which dependencies pulled this package in?
handlebars
@ 4.7.7
8 findings
critical–low
Trust 0/100
EPSS 1.8%
⚠ new maintainer
REVIEW
Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk.
Click for more →
Handlebars.js has JavaScript Injection via AST Type Confusion
Handlebars.js has JavaScript Injection in CLI Precompiler via Unescaped Names and Options
Handlebars.js has JavaScript Injection via AST Type Confusion by tampering @partial-block
Handlebars.js has JavaScript Injection via AST Type Confusion when passing an object as dynamic partial
Handlebars.js has Denial of Service via Malformed Decorator Syntax in Template Compilation
Handlebars.js has a Prototype Method Access Control Gap via Missing __lookupSetter__ Blocklist Entry
Handlebars.js has Prototype Pollution Leading to XSS through Partial Template Injection
Handlebars.js has a Property Access Validation Bypass in container.lookup
- trust veto: new maintainer added
Upgrade handlebars from 4.7.7 to 4.7.9 or later
View advisoryBlast radius
Paths from project root to handlebars - which dependencies pulled this package in?
flatted
@ 3.2.7
2 findings
high
Trust 30/100
EPSS 0.8%
AUTO-MERGE
Verdict tier: the fix passes all three lenses cleanly. In Mode C, Arguss opens a pull request for the upgrade; it does not merge PRs on GitHub.
Click for more →
flatted vulnerable to unbounded recursion DoS in parse() revive phase
Prototype Pollution via parse() in NodeJS flatted
- minor-level upgrade; trust signals unchanged; CI verifies tests
Upgrade flatted from 3.2.7 to 3.4.0 or later
View advisoryBlast radius
Paths from project root to flatted - which dependencies pulled this package in?
ws
@ 8.18.0
2 findings
high–medium
Trust 0/100
EPSS 0.8%
AUTO-MERGE
Verdict tier: the fix passes all three lenses cleanly. In Mode C, Arguss opens a pull request for the upgrade; it does not merge PRs on GitHub.
Click for more →
ws: Memory exhaustion DoS from tiny fragments and data chunks
ws: Uninitialized memory disclosure
- minor-level upgrade; trust signals unchanged; CI verifies tests
Upgrade ws from 8.18.0 to 8.21.0 or later
View advisoryBlast radius
Paths from project root to ws - which dependencies pulled this package in?
diff
@ 4.0.2
2 findings
low
Trust 30/100
EPSS 0.6%
⚠ new maintainer
MIXED
jsdiff has a Denial of Service vulnerability in parsePatch and applyPatch
Affects 2 install paths
- trust veto: new maintainer added
Upgrade diff from 4.0.2 to 4.0.4 or later
View advisory- patch-level upgrade; trust signals unchanged; CI verifies tests
Upgrade diff from 5.2.0 to 5.2.2 or later
View advisoryBlast radius
Paths from project root to diff - which dependencies pulled this package in?
11 findings
high–medium
Trust 0/100
EPSS 0.5%
⚠ ownership transferred
REVIEW
Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk.
Click for more →
Race Condition in node-tar Path Reservations via Unicode Ligature Collisions on macOS APFS
node-tar Vulnerable to Arbitrary File Creation/Overwrite via Hardlink Path Traversal
node-tar: Decompression/parse DoS via unlimited input
node-tar is Vulnerable to Arbitrary File Overwrite and Symlink Poisoning via Insufficient Path Sanitization
node-tar: Negative tar entry size causes infinite loop in archive replace
node-tar Symlink Path Traversal via Drive-Relative Linkpath
tar has Hardlink Path Traversal via Drive-Relative Linkpath
Arbitrary File Read/Write via Hardlink Target Escape Through Symlink Chain in node-tar Extraction
node-tar: Uncaught Exception DoS via NUL byte in PAX path/linkpath records
node-tar: Process crash via PAX numeric path type confusion
node-tar applies PAX size override to intermediary GNU long-name/long-link headers, causing tar parser interpretation differential (file smuggling)
- major version bump requires human review (never auto-merge)
- trust veto: package ownership transferred between versions
Upgrade tar from 6.2.1 to 7.5.4 or later
View advisoryBlast radius
Paths from project root to tar - which dependencies pulled this package in?
minimatch
@ 3.1.2
39 findings
high
Trust 30/100
EPSS 0.5%
AUTO-MERGE
Verdict tier: the fix passes all three lenses cleanly. In Mode C, Arguss opens a pull request for the upgrade; it does not merge PRs on GitHub.
Click for more →
minimatch ReDoS: nested *() extglobs generate catastrophically backtracking regular expressions
Affects 13 install paths
minimatch has a ReDoS via repeated wildcards with non-matching literal in pattern
Affects 13 install paths
minimatch has ReDoS: matchOne() combinatorial backtracking via multiple non-adjacent GLOBSTAR segments
Affects 13 install paths
- patch-level upgrade; trust signals unchanged; CI verifies tests
Upgrade minimatch from 3.1.2 to 3.1.4 or later
View advisory- patch-level upgrade; trust signals unchanged; CI verifies tests
Upgrade minimatch from 9.0.5 to 9.0.7 or later
View advisoryBlast radius
Paths from project root to minimatch - which dependencies pulled this package in?
ajv
@ 6.12.6
1 finding
medium
Trust 0/100
EPSS 0.5%
AUTO-MERGE
Verdict tier: the fix passes all three lenses cleanly. In Mode C, Arguss opens a pull request for the upgrade; it does not merge PRs on GitHub.
Click for more →
ajv has ReDoS when using `$data` option
- minor-level upgrade; trust signals unchanged; CI verifies tests
Upgrade ajv from 6.12.6 to 6.14.0 or later
View advisoryBlast radius
Paths from project root to ajv - which dependencies pulled this package in?
ip-address
@ 9.0.5
1 finding
medium
Trust 30/100
EPSS 0.5%
REVIEW
Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk.
Click for more →
ip-address has XSS in Address6 HTML-emitting methods
- major version bump requires human review (never auto-merge)
Upgrade ip-address from 9.0.5 to 10.1.1 or later
View advisoryBlast radius
Paths from project root to ip-address - which dependencies pulled this package in?
yaml
@ 2.6.1
1 finding
medium
Trust 30/100
EPSS 0.5%
AUTO-MERGE
Verdict tier: the fix passes all three lenses cleanly. In Mode C, Arguss opens a pull request for the upgrade; it does not merge PRs on GitHub.
Click for more →
yaml is vulnerable to Stack Overflow via deeply nested YAML collections
- minor-level upgrade; trust signals unchanged; CI verifies tests
Upgrade yaml from 2.6.1 to 2.8.3 or later
View advisoryBlast radius
Paths from project root to yaml - which dependencies pulled this package in?
brace-expansion
@ 1.1.11
39 findings
medium–low
Trust 0/100
EPSS 0.5%
AUTO-MERGE
Verdict tier: the fix passes all three lenses cleanly. In Mode C, Arguss opens a pull request for the upgrade; it does not merge PRs on GitHub.
Click for more →
brace-expansion: Zero-step sequence causes process hang and memory exhaustion
Affects 13 install paths
brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups
Affects 13 install paths
brace-expansion Regular Expression Denial of Service vulnerability
Affects 13 install paths
- patch-level upgrade; trust signals unchanged; CI verifies tests
Upgrade brace-expansion from 1.1.11 to 1.1.13 or later
View advisory- minor-level upgrade; trust signals unchanged; CI verifies tests
Upgrade brace-expansion from 2.0.1 to 2.0.3 or later
View advisoryBlast radius
Paths from project root to brace-expansion - which dependencies pulled this package in?
js-yaml
@ 4.1.0
3 findings
high–medium
Trust 30/100
EPSS 0.4%
AUTO-MERGE
Verdict tier: the fix passes all three lenses cleanly. In Mode C, Arguss opens a pull request for the upgrade; it does not merge PRs on GitHub.
Click for more →
js-yaml: YAML merge-key chains can force quadratic CPU consumption
JS-YAML: Quadratic-complexity DoS in merge key handling via repeated aliases
js-yaml has prototype pollution in merge (<<)
- minor-level upgrade; trust signals unchanged; CI verifies tests
Upgrade js-yaml from 4.1.0 to 4.3.0 or later
View advisoryBlast radius
Paths from project root to js-yaml - which dependencies pulled this package in?
picomatch
@ 2.3.1
2 findings
high–medium
Trust 0/100
EPSS 0.4%
AUTO-MERGE
Verdict tier: the fix passes all three lenses cleanly. In Mode C, Arguss opens a pull request for the upgrade; it does not merge PRs on GitHub.
Click for more →
Picomatch has a ReDoS vulnerability via extglob quantifiers
Picomatch: Method Injection in POSIX Character Classes causes incorrect Glob Matching
- patch-level upgrade; trust signals unchanged; CI verifies tests
Upgrade picomatch from 2.3.1 to 2.3.2 or later
View advisoryBlast radius
Paths from project root to picomatch - which dependencies pulled this package in?
uuid
@ 8.3.2
1 finding
high
Trust 0/100
EPSS 0.3%
REVIEW
Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk.
Click for more →
uuid: Missing buffer bounds check in v3/v5/v6 when buf is provided
- major version bump requires human review (never auto-merge)
Upgrade uuid from 8.3.2 to 11.1.1 or later
View advisoryBlast radius
Paths from project root to uuid - which dependencies pulled this package in?
prismjs
@ 1.29.0
1 finding
medium
Trust 0/100
EPSS 0.3%
⚠ new maintainer
REVIEW
Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk.
Click for more →
PrismJS DOM Clobbering vulnerability
- trust veto: new maintainer added
Upgrade prismjs from 1.29.0 to 1.30.0 or later
View advisoryBlast radius
Paths from project root to prismjs - which dependencies pulled this package in?
@sigstore/core
@ 1.1.0
1 finding
medium
Trust 0/100
EPSS 0.3%
REVIEW
Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk.
Click for more →
@sigstore/core has DSSE payloadType type-binding failure
- major version bump requires human review (never auto-merge)
Upgrade @sigstore/core from 1.1.0 to 3.2.1 or later
View advisoryBlast radius
Paths from project root to @sigstore/core - which dependencies pulled this package in?
sigstore
@ 2.3.1
1 finding
high
Trust 0/100
EPSS 0.2%
REVIEW
Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk.
Click for more →
sigstore's `certificateOIDs` verification constraints are silently dropped and never enforced
- major version bump requires human review (never auto-merge)
Upgrade sigstore from 2.3.1 to 4.1.1 or later
View advisoryBlast radius
Paths from project root to sigstore - which dependencies pulled this package in?
Package status
631 packages scanned.
- 8 Review-required candidates Arguss flagged these for a human decision - nothing merges until you review them.
- 13 Auto-merge candidates
-
- @types/node 18.11.3 direct
- decache 4.6.2 direct
- esbuild 0.28.1 direct
- sinon 14.0.1 direct
- standard 17.0.0 direct
- standard-version 9.5.0 direct
- tap 19.2.5 direct
- typescript 4.8.4 direct
- typescript 5.4.5 direct
- typescript 5.7.2 direct
- @alcalzone/ansi-tokenize 0.1.3
- @babel/code-frame 7.26.2
- @babel/helper-validator-identifier 7.25.9
- @base2/pretty-print-object 1.0.1
- @bcoe/v8-coverage 0.2.3
- @cspotcode/source-map-support 0.8.1
- @esbuild/aix-ppc64 0.28.1
- @esbuild/android-arm 0.28.1
- @esbuild/android-arm64 0.28.1
- @esbuild/android-x64 0.28.1
- @esbuild/darwin-arm64 0.28.1
- @esbuild/darwin-x64 0.28.1
- @esbuild/freebsd-arm64 0.28.1
- @esbuild/freebsd-x64 0.28.1
- @esbuild/linux-arm 0.28.1
- @esbuild/linux-arm64 0.28.1
- @esbuild/linux-ia32 0.28.1
- @esbuild/linux-loong64 0.28.1
- @esbuild/linux-mips64el 0.28.1
- @esbuild/linux-ppc64 0.28.1
- @esbuild/linux-riscv64 0.28.1
- @esbuild/linux-s390x 0.28.1
- @esbuild/linux-x64 0.28.1
- @esbuild/netbsd-arm64 0.28.1
- @esbuild/netbsd-x64 0.28.1
- @esbuild/openbsd-arm64 0.28.1
- @esbuild/openbsd-x64 0.28.1
- @esbuild/openharmony-arm64 0.28.1
- @esbuild/sunos-x64 0.28.1
- @esbuild/win32-arm64 0.28.1
- @esbuild/win32-ia32 0.28.1
- @esbuild/win32-x64 0.28.1
- @eslint/eslintrc 1.3.3
- @humanwhocodes/config-array 0.10.7
- @humanwhocodes/module-importer 1.0.1
- @humanwhocodes/object-schema 1.2.1
- @hutson/parse-repository-url 3.0.2
- @isaacs/cliui 8.0.2
- @isaacs/ts-node-temp-fork-for-pr-2009 10.9.7
- @istanbuljs/schema 0.1.3
- @jridgewell/resolve-uri 3.1.2
- @jridgewell/sourcemap-codec 1.5.0
- @jridgewell/trace-mapping 0.3.25
- @jridgewell/trace-mapping 0.3.9
- @nodelib/fs.scandir 2.1.5
- @nodelib/fs.stat 2.0.5
- @nodelib/fs.walk 1.2.8
- @npmcli/agent 2.2.2
- @npmcli/fs 3.1.1
- @npmcli/git 5.0.8
- @npmcli/installed-package-contents 2.1.0
- @npmcli/node-gyp 3.0.0
- @npmcli/package-json 5.2.1
- @npmcli/promise-spawn 7.0.2
- @npmcli/redact 1.1.0
- @npmcli/run-script 7.0.4
- @pkgjs/parseargs 0.11.0
- @sigstore/bundle 2.3.2
- @sigstore/protobuf-specs 0.3.2
- @sigstore/sign 2.3.2
- @sigstore/tuf 2.3.4
- @sigstore/verify 1.2.1
- @sinonjs/commons 1.8.3
- @sinonjs/fake-timers 9.1.2
- @sinonjs/samsam 6.1.1
- @sinonjs/text-encoding 0.7.2
- @tapjs/after 1.1.31
- @tapjs/after-each 2.0.8
- @tapjs/asserts 2.0.8
- @tapjs/before 2.0.8
- @tapjs/before-each 2.0.8
- @tapjs/chdir 1.1.4
- @tapjs/config 3.1.6
- @tapjs/core 2.1.6
- @tapjs/error-serdes 2.0.1
- @tapjs/filter 2.0.8
- @tapjs/fixture 2.0.8
- @tapjs/intercept 2.0.8
- @tapjs/mock 2.1.6
- @tapjs/node-serialize 2.0.8
- @tapjs/processinfo 3.1.8
- @tapjs/reporter 2.0.8
- @tapjs/run 2.1.7
- @tapjs/snapshot 2.0.8
- @tapjs/spawn 2.0.8
- @tapjs/stack 2.0.1
- @tapjs/stdin 2.0.8
- @tapjs/test 2.2.4
- @tapjs/typescript 1.4.13
- @tapjs/worker 2.0.8
- @tsconfig/node14 14.1.2
- @tsconfig/node16 16.1.3
- @tsconfig/node18 18.2.4
- @tsconfig/node20 20.1.4
- @tufjs/canonical-json 2.0.0
- @tufjs/models 2.0.1
- @types/istanbul-lib-coverage 2.0.6
- @types/json5 0.0.29
- @types/minimist 1.2.2
- @types/normalize-package-data 2.4.1
- abbrev 2.0.0
- acorn 8.14.0
- acorn-jsx 5.3.2
- acorn-walk 8.3.4
- add-stream 1.0.0
- agent-base 7.1.1
- aggregate-error 3.1.0
- ansi-escapes 6.2.1
- ansi-regex 5.0.1
- ansi-regex 6.1.0
- ansi-styles 3.2.1
- ansi-styles 4.3.0
- ansi-styles 6.2.1
- anymatch 3.1.3
- arg 4.1.3
- argparse 2.0.1
- array-ify 1.0.0
- array-includes 3.1.5
- array-union 2.1.0
- array.prototype.flat 1.3.0
- array.prototype.flatmap 1.3.0
- arrify 1.0.1
- async-hook-domain 4.0.1
- auto-bind 5.0.1
- balanced-match 1.0.2
- binary-extensions 2.3.0
- braces 3.0.3
- buffer-from 1.1.2
- builtins 5.0.1
- c8 9.1.0
- cacache 18.0.4
- call-bind 1.0.2
- callsite 1.0.0
- callsites 3.1.0
- camelcase 5.3.1
- camelcase-keys 6.2.2
- chalk 2.4.2
- chalk 4.1.2
- chalk 5.3.0
- chokidar 3.6.0
- chownr 2.0.0
- ci-info 3.9.0
- clean-stack 2.2.0
- cli-boxes 3.0.0
- cli-cursor 4.0.0
- cli-truncate 3.1.0
- cliui 7.0.4
- cliui 8.0.1
- code-excerpt 4.0.0
- color-convert 1.9.3
- color-convert 2.0.1
- color-name 1.1.3
- color-name 1.1.4
- compare-func 2.0.0
- concat-map 0.0.1
- concat-stream 2.0.0
- conventional-changelog 3.1.25
- conventional-changelog-angular 5.0.13
- conventional-changelog-atom 2.0.8
- conventional-changelog-codemirror 2.0.8
- conventional-changelog-config-spec 2.1.0
- conventional-changelog-conventionalcommits 4.6.3
- conventional-changelog-core 4.2.4
- conventional-changelog-ember 2.0.9
- conventional-changelog-eslint 3.0.9
- conventional-changelog-express 2.0.6
- conventional-changelog-jquery 3.0.11
- conventional-changelog-jshint 2.0.9
- conventional-changelog-preset-loader 2.3.4
- conventional-changelog-writer 5.0.1
- conventional-commits-filter 2.0.7
- conventional-commits-parser 3.2.4
- conventional-recommended-bump 6.1.0
- convert-source-map 2.0.0
- convert-to-spaces 2.0.1
- core-util-is 1.0.2
- cross-spawn 7.0.6
- dargs 7.0.0
- dateformat 3.0.3
- debug 2.6.9
- debug 3.2.7
- debug 4.3.4
- decamelize 1.2.0
- decamelize-keys 1.1.0
- deep-is 0.1.4
- define-properties 1.1.4
- detect-indent 6.1.0
- detect-newline 3.1.0
- dir-glob 3.0.1
- doctrine 2.1.0
- doctrine 3.0.0
- dot-prop 5.3.0
- dotgitignore 2.1.0
- eastasianwidth 0.2.0
- emoji-regex 8.0.0
- emoji-regex 9.2.2
- encoding 0.1.13
- env-paths 2.2.1
- err-code 2.0.3
- error-ex 1.3.2
- es-abstract 1.20.4
- es-shim-unscopables 1.0.0
- es-to-primitive 1.2.1
- escalade 3.1.1
- escape-string-regexp 1.0.5
- escape-string-regexp 2.0.0
- escape-string-regexp 4.0.0
- eslint 8.25.0
- eslint-config-standard 17.0.0
- eslint-config-standard-jsx 11.0.0
- eslint-import-resolver-node 0.3.6
- eslint-module-utils 2.7.4
- eslint-plugin-es 4.1.0
- eslint-plugin-import 2.26.0
- eslint-plugin-n 15.3.0
- eslint-plugin-promise 6.1.1
- eslint-plugin-react 7.31.10
- eslint-scope 7.1.1
- eslint-utils 2.1.0
- eslint-utils 3.0.0
- eslint-visitor-keys 1.3.0
- eslint-visitor-keys 2.1.0
- eslint-visitor-keys 3.3.0
- espree 9.4.0
- esquery 1.4.0
- esrecurse 4.3.0
- estraverse 5.3.0
- esutils 2.0.3
- events-to-array 2.0.3
- exponential-backoff 3.1.1
- fast-deep-equal 3.1.3
- fast-glob 3.2.12
- fast-json-stable-stringify 2.1.0
- fast-levenshtein 2.0.6
- fastq 1.13.0
- figures 3.2.0
- file-entry-cache 6.0.1
- fill-range 7.1.1
- find-up 2.1.0
- find-up 3.0.0
- find-up 4.1.0
- find-up 5.0.0
- flat-cache 3.0.4
- foreground-child 3.3.0
- fromentries 1.3.2
- fs-minipass 2.1.0
- fs-minipass 3.0.3
- fs.realpath 1.0.0
- fsevents 2.3.3
- function-bind 1.1.1
- function-loop 4.0.0
- function.prototype.name 1.1.5
- functions-have-names 1.2.3
- get-caller-file 2.0.5
- get-intrinsic 1.1.3
- get-pkg-repo 4.2.1
- get-stdin 8.0.0
- get-symbol-description 1.0.0
- git-raw-commits 2.0.11
- git-remote-origin-url 2.0.0
- git-semver-tags 4.1.1
- gitconfiglocal 1.0.0
- glob 7.2.3
- glob-parent 5.1.2
- glob-parent 6.0.2
- globals 13.17.0
- globby 11.1.0
- graceful-fs 4.2.10
- grapheme-splitter 1.0.4
- hard-rejection 2.1.0
- has 1.0.3
- has-bigints 1.0.2
- has-flag 3.0.0
- has-flag 4.0.0
- has-property-descriptors 1.0.0
- has-symbols 1.0.3
- has-tostringtag 1.0.0
- hosted-git-info 2.8.9
- hosted-git-info 4.1.0
- hosted-git-info 7.0.2
- html-escaper 2.0.2
- http-cache-semantics 4.1.1
- http-proxy-agent 7.0.2
- https-proxy-agent 7.0.5
- iconv-lite 0.6.3
- ignore 5.2.0
- ignore-walk 6.0.5
- import-fresh 3.3.0
- imurmurhash 0.1.4
- indent-string 4.0.0
- indent-string 5.0.0
- inflight 1.0.6
- inherits 2.0.4
- ini 1.3.8
- ini 4.1.3
- ink 4.4.1
- internal-slot 1.0.3
- is-actual-promise 1.0.2
- is-arrayish 0.2.1
- is-bigint 1.0.4
- is-binary-path 2.1.0
- is-boolean-object 1.1.2
- is-callable 1.2.7
- is-ci 3.0.1
- is-core-module 2.11.0
- is-date-object 1.0.5
- is-extglob 2.1.1
- is-fullwidth-code-point 3.0.0
- is-fullwidth-code-point 4.0.0
- is-glob 4.0.3
- is-lambda 1.0.1
- is-lower-case 2.0.2
- is-negative-zero 2.0.2
- is-number 7.0.0
- is-number-object 1.0.7
- is-obj 2.0.0
- is-plain-obj 1.1.0
- is-plain-object 5.0.0
- is-regex 1.1.4
- is-shared-array-buffer 1.0.2
- is-string 1.0.7
- is-symbol 1.0.4
- is-text-path 1.0.1
- is-upper-case 2.0.2
- is-weakref 1.0.2
- isarray 0.0.1
- isarray 1.0.0
- isexe 2.0.0
- isexe 3.1.1
- istanbul-lib-coverage 3.2.2
- istanbul-lib-report 3.0.1
- istanbul-reports 3.1.7
- jackspeak 3.4.3
- js-sdsl 4.1.5
- js-tokens 4.0.0
- jsbn 1.1.0
- json-parse-better-errors 1.0.2
- json-parse-even-better-errors 2.3.1
- json-parse-even-better-errors 3.0.2
- json-schema-traverse 0.4.1
- json-stable-stringify-without-jsonify 1.0.1
- json-stringify-safe 5.0.1
- json5 1.0.2
- jsonparse 1.3.1
- JSONStream 1.3.5
- jsx-ast-utils 3.3.3
- just-extend 4.2.1
- kind-of 6.0.3
- levn 0.4.1
- lines-and-columns 1.2.4
- load-json-file 4.0.0
- load-json-file 5.3.0
- locate-path 2.0.0
- locate-path 3.0.0
- locate-path 5.0.0
- locate-path 6.0.0
- lodash.get 4.4.2
- lodash.ismatch 4.4.0
- lodash.merge 4.6.2
- loose-envify 1.4.0
- lru-cache 10.4.3
- lru-cache 6.0.0
- make-dir 4.0.0
- make-error 1.3.6
- make-fetch-happen 13.0.1
- map-obj 1.0.1
- map-obj 4.3.0
- meow 8.1.2
- merge2 1.4.1
- micromatch 4.0.8
- mimic-fn 2.1.0
- min-indent 1.0.1
- minimist 1.2.7
- minimist-options 4.1.0
- minipass 3.3.4
- minipass 5.0.0
- minipass 7.1.2
- minipass-collect 2.0.1
- minipass-fetch 3.0.5
- minipass-flush 1.0.5
- minipass-json-stream 1.0.2
- minipass-pipeline 1.2.4
- minipass-sized 1.0.3
- minizlib 2.1.2
- mkdirp 1.0.4
- mkdirp 3.0.1
- modify-values 1.0.1
- ms 2.0.0
- ms 2.1.2
- ms 2.1.3
- natural-compare 1.4.0
- negotiator 0.6.4
- neo-async 2.6.2
- nise 5.1.1
- node-gyp 10.3.1
- nopt 7.2.1
- normalize-package-data 2.5.0
- normalize-package-data 3.0.3
- normalize-package-data 6.0.2
- normalize-path 3.0.0
- npm-bundled 3.0.1
- npm-install-checks 6.3.0
- npm-normalize-package-bin 3.0.1
- npm-package-arg 11.0.3
- npm-packlist 8.0.2
- npm-pick-manifest 9.1.0
- npm-registry-fetch 16.2.1
- object-assign 4.1.1
- object-inspect 1.12.2
- object-keys 1.1.1
- object.assign 4.1.4
- object.entries 1.1.5
- object.fromentries 2.0.5
- object.hasown 1.1.1
- object.values 1.1.5
- once 1.4.0
- onetime 5.1.2
- opener 1.5.2
- optionator 0.9.1
- p-limit 1.3.0
- p-limit 2.3.0
- p-limit 3.1.0
- p-locate 2.0.0
- p-locate 3.0.0
- p-locate 4.1.0
- p-locate 5.0.0
- p-map 4.0.0
- p-try 1.0.0
- p-try 2.2.0
- package-json-from-dist 1.0.1
- pacote 17.0.7
- parent-module 1.0.1
- parse-json 4.0.0
- parse-json 5.2.0
- patch-console 2.0.0
- path-exists 3.0.0
- path-exists 4.0.0
- path-is-absolute 1.0.1
- path-key 3.1.1
- path-parse 1.0.7
- path-scurry 1.11.1
- path-to-regexp 1.9.0
- path-type 3.0.0
- path-type 4.0.0
- picocolors 1.0.0
- pify 2.3.0
- pify 3.0.0
- pify 4.0.1
- pirates 4.0.6
- pkg-conf 3.1.0
- polite-json 4.0.1
- polite-json 5.0.0
- prelude-ls 1.2.1
- prismjs-terminal 1.2.3
- proc-log 4.2.0
- process-nextick-args 2.0.1
- process-on-spawn 1.1.0
- promise-inflight 1.0.1
- promise-retry 2.0.1
- prop-types 15.8.1
- punycode 2.1.1
- q 1.5.1
- queue-microtask 1.2.3
- quick-lru 4.0.1
- react 18.3.1
- react-dom 18.3.1
- react-element-to-jsx-string 15.0.0
- react-is 16.13.1
- react-is 18.1.0
- react-reconciler 0.29.2
- read-package-json 7.0.1
- read-package-json-fast 3.0.2
- read-pkg 3.0.0
- read-pkg 5.2.0
- read-pkg-up 3.0.0
- read-pkg-up 7.0.1
- readable-stream 2.3.7
- readable-stream 3.6.0
- readdirp 3.6.0
- redent 3.0.0
- regexp.prototype.flags 1.4.3
- regexpp 3.2.0
- require-directory 2.1.1
- resolve 1.22.1
- resolve 2.0.0-next.4
- resolve-from 4.0.0
- resolve-import 1.4.6
- restore-cursor 4.0.0
- retry 0.12.0
- reusify 1.0.4
- rimraf 3.0.2
- rimraf 5.0.10
- run-parallel 1.2.0
- safe-buffer 5.1.2
- safe-buffer 5.2.1
- safe-regex-test 1.0.0
- safer-buffer 2.1.2
- scheduler 0.23.2
- semver 5.7.2
- semver 6.3.1
- semver 7.6.3
- shebang-command 2.0.0
- shebang-regex 3.0.0
- side-channel 1.0.4
- signal-exit 3.0.7
- signal-exit 4.1.0
- slash 3.0.0
- slice-ansi 5.0.0
- slice-ansi 6.0.0
- smart-buffer 4.2.0
- socks 2.8.3
- socks-proxy-agent 8.0.4
- source-map 0.6.1
- spdx-correct 3.1.1
- spdx-exceptions 2.3.0
- spdx-expression-parse 3.0.1
- spdx-license-ids 3.0.12
- split 1.0.1
- split2 3.2.2
- sprintf-js 1.1.3
- ssri 10.0.6
- stack-utils 2.0.6
- standard-engine 15.0.0
- string-length 6.0.0
- string-width 4.2.3
- string-width 5.1.2
- string-width-cjs 4.2.3
- string.prototype.matchall 4.0.7
- string.prototype.trimend 1.0.5
- string.prototype.trimstart 1.0.5
- string_decoder 1.1.1
- string_decoder 1.3.0
- stringify-package 1.0.1
- strip-ansi 6.0.1
- strip-ansi 7.1.0
- strip-ansi-cjs 6.0.1
- strip-bom 3.0.0
- strip-indent 3.0.0
- strip-json-comments 3.1.1
- supports-color 5.5.0
- supports-color 7.2.0
- supports-preserve-symlinks-flag 1.0.0
- sync-content 1.0.2
- tap-parser 16.0.1
- tap-yaml 2.2.2
- tcompare 7.0.1
- test-exclude 6.0.0
- text-extensions 1.9.0
- text-table 0.2.0
- through 2.3.8
- through2 2.0.5
- through2 4.0.2
- to-regex-range 5.0.1
- trim-newlines 3.0.1
- trivial-deferred 2.0.0
- tsconfig-paths 3.14.1
- tshy 1.18.0
- tslib 2.8.1
- tuf-js 2.2.1
- type-check 0.4.0
- type-detect 4.0.8
- type-fest 0.12.0
- type-fest 0.18.1
- type-fest 0.20.2
- type-fest 0.3.1
- type-fest 0.6.0
- type-fest 0.8.1
- typedarray 0.0.6
- uglify-js 3.17.3
- unbox-primitive 1.0.2
- unique-filename 3.0.0
- unique-slug 4.0.0
- uri-js 4.4.1
- util-deprecate 1.0.2
- v8-compile-cache-lib 3.0.1
- v8-to-istanbul 9.3.0
- validate-npm-package-license 3.0.4
- validate-npm-package-name 5.0.1
- walk-up-path 3.0.1
- which 2.0.2
- which 4.0.0
- which-boxed-primitive 1.0.2
- widest-line 4.0.1
- word-wrap 1.2.5
- wordwrap 1.0.0
- wrap-ansi 7.0.0
- wrap-ansi 8.1.0
- wrap-ansi-cjs 7.0.0
- wrappy 1.0.2
- xdg-basedir 4.0.0
- xtend 4.0.2
- y18n 5.0.8
- yallist 4.0.0
- yaml-types 0.3.0
- yargs 16.2.0
- yargs 17.7.2
- yargs-parser 20.2.9
- yargs-parser 21.1.1
- yocto-queue 0.1.0
- yoga-wasm-web 0.3.3
Review auto-merge candidates and open PRs in a guided flow.
Glossary
What the labels and signals mean.
Glossary
What the labels and signals mean.
- Trust Save
- A package upgrade Arguss would have blocked despite the new version being available, because trust signals, like ownership transfer or a new maintainer, fired during the upgrade window. The name reflects what the agent did for the user: saved them from a potentially malicious update that a version-only auto-PR tool would have merged.
- AUTO-MERGE
- Verdict tier indicating the fix passes all three lenses cleanly. After you confirm action from a Scan assessment, Arguss opens a pull request for the upgrade; it does not merge PRs on GitHub. The envelope is conservative on purpose: patch or minor version bump, trust signals unchanged, blast radius bounded, real tests pass.
- REVIEW
- Verdict tier requiring a human decision. At least one veto fired during fix-confidence evaluation, trust signals shifted, the pipeline can't verify post-upgrade behavior, or the upgrade is a major version bump. The agent surfaces the reasons; the developer decides.
- DECLINE
- Verdict tier indicating no remediation is recommended. Typically applies when no fix version exists for the finding, or when multiple critical vetoes make even human review unproductive.
fix_kind.major- Veto signal that fires when the available fix requires a major version bump (1.x → 2.x). Major bumps imply potential breaking changes and fall outside the auto-merge envelope by default, even when the upgrade is the only available fix.
trust.new_maintainer- Veto signal that fires when a package added a new maintainer during the upgrade window, meaning between the user's current version and the proposed upgrade. New publishing identities are a well-documented attack vector for typosquats and supply chain takeovers.
trust.ownership_transferred- Veto signal that fires when a package's primary maintainer changed during the upgrade window. Combined with
trust.new_maintainer, this is the highest-risk trust combination, typical of the xz-utils style attacks and historical npm credential theft incidents. pipeline.test_reality- Veto signal that fires when Arguss can't verify tests will run on the upgraded code. Four conditions must hold: a test script exists in
package.json, it isn't a no-op, real test files exist, and a workflow actually invokes them. If any fail, the fix cannot qualify for AUTO_MERGE because there's no way to verify the upgrade didn't break the user's project. - CVSS
- Common Vulnerability Scoring System. A numeric score (0.0–10.0) representing how damaging a vulnerability could be if exploited. Sourced from NIST's National Vulnerability Database via OSV.dev. Severity, not urgency.
- EPSS
- Exploit Prediction Scoring System. A daily-updated probability (0.0–1.0, displayed as percent) that a CVE will be exploited in the next 30 days. Sourced from FIRST.org. Probability, not severity.
- KEV
- CISA's Known Exploited Vulnerabilities catalog. A federal list of CVEs with documented active exploitation in the wild. Federal agencies have a binding patching deadline; for everyone else, presence on KEV is the strongest "this is being used right now" signal available. Sourced directly from CISA.
- Project Risk Score (PRS)
- A weighted blend of the three lens subscores (40% vulnerability, 30% trust, 30% pipeline) producing an overall 0–100 indicator of the project's dependency health. Useful for at-a-glance triage; the per-finding fix-confidence verdicts are what drive automated decisions.
Dependency graph
Full-project map of transitive dependencies. Severity colors reflect vulnerabilities; trust rings apply only to direct dependencies analyzed by OpenSSF Scorecard (higher = riskier).