Project Risk Score Project Risk Score: weighted blend of vulnerability (40%), trust (30%), and pipeline (30%) subscores. Useful for at-a-glance triage. Click for more →
70 /100
Critical

128 findings across 18 packages · 610 packages clean

Candidates: 13 auto-merge · 8 review · 0 decline · 0 no fix

Scanned motdotla/dotenv @ master Scan · Completed 215 hrs ago Download SBOM
Total Findings
128
All detected issues
KEV Findings
0
Known exploited
High EPSS
1
Likely to be exploited
Auto-merge ready
13
Remediation candidates
Affected pkgs
18
with remediation paths
KEV catalog CISA's Known Exploited Vulnerabilities catalog. Documented active exploitation in the wild; the strongest 'this is happening now' signal. Click for more →
0
actively exploited CVEs
Highest EPSS Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
22.4%
CVE-2021-23337
Active vetos
9
lens blocks on candidates

Findings

lodash @ 4.17.21
root → standard-version → conventional-changelog-conventionalcommits → lodash
3 findings high–medium
Trust 0/100 EPSS 22.4% ↑
AUTO-MERGE Verdict tier: the fix passes all three lenses cleanly. In Mode C, Arguss opens a pull request for the upgrade; it does not merge PRs on GitHub. Click for more →
GHSA-r5fr-rjxr-66jc high CVSS 8.1 EPSS 22.4%
lodash vulnerable to Code Injection via `_.template` imports key names
GHSA-f23m-r3pf-42rh medium CVSS 6.5 EPSS 1.5%
lodash vulnerable to Prototype Pollution via array path bypass in `_.unset` and `_.omit`
GHSA-xxjr-mmjv-4gpg medium CVSS 6.5 EPSS 1.5%
Lodash has Prototype Pollution Vulnerability in `_.unset` and `_.omit` functions
4.17.21 → 4.18.0 minor
auto-merge Verdict tier: the fix passes all three lenses cleanly. In Mode C, Arguss opens a pull request for the upgrade; it does not merge PRs on GitHub. Click for more → Score 100
Max CVSS 8.1 · 3 findings Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → Max EPSS 22.4% · 97th percentile Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
  • minor-level upgrade; trust signals unchanged; CI verifies tests
GHSA-r5fr-rjxr-66jc: lodash vulnerable to Code Injection via `_.template` imports key names

Upgrade lodash from 4.17.21 to 4.18.0 or later

View advisory
root → standard-version → conventional-changelog-conventionalcommits → lodash

Blast radius

Paths from project root to lodash - which dependencies pulled this package in?

glob @ 10.4.5
root → tap → @tapjs/run → pacote → cacache → glob
10 findings high
Trust 30/100 EPSS 3.1%
AUTO-MERGE Verdict tier: the fix passes all three lenses cleanly. In Mode C, Arguss opens a pull request for the upgrade; it does not merge PRs on GitHub. Click for more →
GHSA-5j98-mcp5-4vw2 high CVSS 7.5 EPSS 3.1%
glob CLI: Command injection via -c/--cmd executes matches with shell:true

Affects 10 install paths

10.4.5 → 10.5.0 minor
auto-merge Verdict tier: the fix passes all three lenses cleanly. In Mode C, Arguss opens a pull request for the upgrade; it does not merge PRs on GitHub. Click for more → Score 100
Max CVSS 7.5 · 10 findings Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → Max EPSS 3.1% · 86th percentile Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
  • minor-level upgrade; trust signals unchanged; CI verifies tests
GHSA-5j98-mcp5-4vw2: glob CLI: Command injection via -c/--cmd executes matches with shell:true

Upgrade glob from 10.4.5 to 10.5.0 or later

View advisory
root → tap → @tapjs/run → pacote → cacache → glob

Blast radius

Paths from project root to glob - which dependencies pulled this package in?

handlebars @ 4.7.7
root → standard-version → conventional-changelog → conventional-changelog-core → conventional-changelog-writer → handlebars
8 findings critical–low
Trust 0/100 EPSS 1.8% ⚠ new maintainer
REVIEW Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more →
GHSA-2w6w-674q-4c4q critical CVSS 9.8 EPSS 1.8%
Handlebars.js has JavaScript Injection via AST Type Confusion
GHSA-xjpj-3mr7-gcpf high CVSS 8.8 EPSS 0.3%
Handlebars.js has JavaScript Injection in CLI Precompiler via Unescaped Names and Options
GHSA-3mfm-83xf-c92r high CVSS 8.1 EPSS 0.7%
Handlebars.js has JavaScript Injection via AST Type Confusion by tampering @partial-block
GHSA-xhpv-hc6g-r9c6 high CVSS 8.1 EPSS 0.7%
Handlebars.js has JavaScript Injection via AST Type Confusion when passing an object as dynamic partial
GHSA-9cx6-37pm-9jff high CVSS 7.5 EPSS 0.6%
Handlebars.js has Denial of Service via Malformed Decorator Syntax in Template Compilation
GHSA-7rx3-28cr-v5wh medium CVSS 4.8 EPSS n/a
Handlebars.js has a Prototype Method Access Control Gap via Missing __lookupSetter__ Blocklist Entry
GHSA-2qvq-rjwj-gvw9 medium CVSS 4.7 EPSS 0.3%
Handlebars.js has Prototype Pollution Leading to XSS through Partial Template Injection
GHSA-442j-39wm-28r2 low CVSS 3.7 EPSS n/a
Handlebars.js has a Property Access Validation Bypass in container.lookup
4.7.7 → 4.7.9 patch
review-required Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more → Score 85
Max CVSS 9.8 · 8 findings Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → Max EPSS 1.8% · 75th percentile Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
trust.new_maintainer Veto: a new publishing identity was added between your current version and the upgrade target. A well-documented supply chain attack vector. Click for more →
  • trust veto: new maintainer added
GHSA-2w6w-674q-4c4q: Handlebars.js has JavaScript Injection via AST Type Confusion

Upgrade handlebars from 4.7.7 to 4.7.9 or later

View advisory
root → standard-version → conventional-changelog → conventional-changelog-core → conventional-changelog-writer → handlebars

Blast radius

Paths from project root to handlebars - which dependencies pulled this package in?

flatted @ 3.2.7
root → standard → eslint → file-entry-cache → flat-cache → flatted
2 findings high
Trust 30/100 EPSS 0.8%
AUTO-MERGE Verdict tier: the fix passes all three lenses cleanly. In Mode C, Arguss opens a pull request for the upgrade; it does not merge PRs on GitHub. Click for more →
GHSA-25h7-pfq9-p65f high CVSS 7.5 EPSS 0.8%
flatted vulnerable to unbounded recursion DoS in parse() revive phase
GHSA-rf6f-7fwh-wjgh high CVSS 7.5 EPSS 0.8%
Prototype Pollution via parse() in NodeJS flatted
3.2.7 → 3.4.2 minor
auto-merge Verdict tier: the fix passes all three lenses cleanly. In Mode C, Arguss opens a pull request for the upgrade; it does not merge PRs on GitHub. Click for more → Score 100
Max CVSS 7.5 · 2 findings Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → Max EPSS 0.8% · 52nd percentile Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
  • minor-level upgrade; trust signals unchanged; CI verifies tests
GHSA-25h7-pfq9-p65f: flatted vulnerable to unbounded recursion DoS in parse() revive phase

Upgrade flatted from 3.2.7 to 3.4.0 or later

View advisory
root → standard → eslint → file-entry-cache → flat-cache → flatted

Blast radius

Paths from project root to flatted - which dependencies pulled this package in?

ws @ 8.18.0
root → tap → @tapjs/run → @tapjs/reporter → ink → ws
2 findings high–medium
Trust 0/100 EPSS 0.8%
AUTO-MERGE Verdict tier: the fix passes all three lenses cleanly. In Mode C, Arguss opens a pull request for the upgrade; it does not merge PRs on GitHub. Click for more →
GHSA-96hv-2xvq-fx4p high CVSS 7.5 EPSS 0.8%
ws: Memory exhaustion DoS from tiny fragments and data chunks
8.18.0 → 8.21.0 minor
auto-merge Verdict tier: the fix passes all three lenses cleanly. In Mode C, Arguss opens a pull request for the upgrade; it does not merge PRs on GitHub. Click for more → Score 100
Max CVSS 7.5 · 2 findings Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → Max EPSS 0.8% · 51st percentile Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
  • minor-level upgrade; trust signals unchanged; CI verifies tests
GHSA-96hv-2xvq-fx4p: ws: Memory exhaustion DoS from tiny fragments and data chunks

Upgrade ws from 8.18.0 to 8.21.0 or later

View advisory
root → tap → @tapjs/run → @tapjs/reporter → ink → ws

Blast radius

Paths from project root to ws - which dependencies pulled this package in?

diff @ 4.0.2
root → tap → @tapjs/test → @isaacs/ts-node-temp-fork-for-pr-2009 → diff
2 findings low
Trust 30/100 EPSS 0.6% ⚠ new maintainer
MIXED
GHSA-73rr-hh4g-fpgx low CVSS 2.5 EPSS 0.6%
jsdiff has a Denial of Service vulnerability in parsePatch and applyPatch

Affects 2 install paths

4.0.2 → 4.0.4 patch
review-required Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more → Score 85
Max CVSS 2.5 · 1 finding Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → Max EPSS 0.6% · 43rd percentile Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
trust.new_maintainer Veto: a new publishing identity was added between your current version and the upgrade target. A well-documented supply chain attack vector. Click for more →
  • trust veto: new maintainer added
GHSA-73rr-hh4g-fpgx: jsdiff has a Denial of Service vulnerability in parsePatch and applyPatch

Upgrade diff from 4.0.2 to 4.0.4 or later

View advisory
root → tap → @tapjs/test → @isaacs/ts-node-temp-fork-for-pr-2009 → diff
5.2.0 → 5.2.2 patch
auto-merge Verdict tier: the fix passes all three lenses cleanly. In Mode C, Arguss opens a pull request for the upgrade; it does not merge PRs on GitHub. Click for more → Score 100
Max CVSS 2.5 · 1 finding Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → Max EPSS 0.6% · 43rd percentile Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
  • patch-level upgrade; trust signals unchanged; CI verifies tests
GHSA-73rr-hh4g-fpgx: jsdiff has a Denial of Service vulnerability in parsePatch and applyPatch

Upgrade diff from 5.2.0 to 5.2.2 or later

View advisory
root → tap → @tapjs/core → diff

Blast radius

Paths from project root to diff - which dependencies pulled this package in?

tar @ 6.2.1 An upgrade Arguss blocked despite the newer version being available, because trust signals like ownership transfer or new maintainer fired during the upgrade window. Click for more →
root → tap → @tapjs/run → pacote → cacache → tar
11 findings high–medium
Trust 0/100 EPSS 0.5% ⚠ ownership transferred
REVIEW Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more →
GHSA-r6q2-hw4h-h46w high CVSS 8.8 EPSS 0.2%
Race Condition in node-tar Path Reservations via Unicode Ligature Collisions on macOS APFS
GHSA-34x7-hfp2-rc4v high CVSS 8.2 EPSS 0.5%
node-tar Vulnerable to Arbitrary File Creation/Overwrite via Hardlink Path Traversal
GHSA-23hp-3jrh-7fpw high CVSS 7.5 EPSS 0.4%
node-tar: Decompression/parse DoS via unlimited input
GHSA-8qq5-rm4j-mr97 high CVSS 7.5 EPSS 0.3%
node-tar is Vulnerable to Arbitrary File Overwrite and Symlink Poisoning via Insufficient Path Sanitization
GHSA-8x88-c5mf-7j5w high CVSS 7.5 EPSS 0.4%
node-tar: Negative tar entry size causes infinite loop in archive replace
GHSA-9ppj-qmqm-q256 high CVSS 7.5 EPSS 0.3%
node-tar Symlink Path Traversal via Drive-Relative Linkpath
GHSA-qffp-2rhf-9h96 high CVSS 7.5 EPSS 0.4%
tar has Hardlink Path Traversal via Drive-Relative Linkpath
GHSA-83g3-92jg-28cx high CVSS 7.1 EPSS 0.3%
Arbitrary File Read/Write via Hardlink Target Escape Through Symlink Chain in node-tar Extraction
GHSA-gvwx-54wh-qm9j medium CVSS 5.3 EPSS 0.3%
node-tar: Uncaught Exception DoS via NUL byte in PAX path/linkpath records
GHSA-w8wr-v893-vjvp medium CVSS 5.3 EPSS 0.4%
node-tar: Process crash via PAX numeric path type confusion
GHSA-vmf3-w455-68vh medium CVSS 5.0 EPSS 0.1%
node-tar applies PAX size override to intermediary GNU long-name/long-link headers, causing tar parser interpretation differential (file smuggling)
6.2.1 → 7.5.19 major
review-required Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more → Score 35
Max CVSS 8.8 · 11 findings Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → Max EPSS 0.5% · 41st percentile Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
fix_kind.major Veto: the available fix requires a major version bump (1.x → 2.x), which implies potential breaking changes outside the auto-merge envelope. Click for more → trust.ownership_transferred Veto: the package's primary maintainer changed during the upgrade window. Combined with new-maintainer, this is the highest-risk trust combination. Click for more →
  • major version bump requires human review (never auto-merge)
  • trust veto: package ownership transferred between versions
GHSA-r6q2-hw4h-h46w: Race Condition in node-tar Path Reservations via Unicode Ligature Collisions on macOS APFS

Upgrade tar from 6.2.1 to 7.5.4 or later

View advisory
root → tap → @tapjs/run → pacote → cacache → tar

Blast radius

Paths from project root to tar - which dependencies pulled this package in?

minimatch @ 3.1.2
root → standard → eslint → @eslint/eslintrc → minimatch
39 findings high
Trust 30/100 EPSS 0.5%
AUTO-MERGE Verdict tier: the fix passes all three lenses cleanly. In Mode C, Arguss opens a pull request for the upgrade; it does not merge PRs on GitHub. Click for more →
GHSA-23c5-xmqv-rm74 high CVSS 7.5 EPSS 0.5%
minimatch ReDoS: nested *() extglobs generate catastrophically backtracking regular expressions

Affects 13 install paths

GHSA-3ppc-4f35-3m26 high CVSS 7.5 EPSS 0.5%
minimatch has a ReDoS via repeated wildcards with non-matching literal in pattern

Affects 13 install paths

GHSA-7r86-cg39-jmmj high CVSS 7.5 EPSS 0.5%
minimatch has ReDoS: matchOne() combinatorial backtracking via multiple non-adjacent GLOBSTAR segments

Affects 13 install paths

3.1.2 → 3.1.4 patch
auto-merge Verdict tier: the fix passes all three lenses cleanly. In Mode C, Arguss opens a pull request for the upgrade; it does not merge PRs on GitHub. Click for more → Score 100
Max CVSS 7.5 · 3 findings Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → Max EPSS 0.5% · 40th percentile Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
  • patch-level upgrade; trust signals unchanged; CI verifies tests
GHSA-23c5-xmqv-rm74: minimatch ReDoS: nested *() extglobs generate catastrophically backtracking regular expressions

Upgrade minimatch from 3.1.2 to 3.1.4 or later

View advisory
root → standard → eslint → @eslint/eslintrc → minimatch
9.0.5 → 9.0.7 patch
auto-merge Verdict tier: the fix passes all three lenses cleanly. In Mode C, Arguss opens a pull request for the upgrade; it does not merge PRs on GitHub. Click for more → Score 100
Max CVSS 7.5 · 36 findings Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → Max EPSS 0.5% · 40th percentile Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
  • patch-level upgrade; trust signals unchanged; CI verifies tests
GHSA-23c5-xmqv-rm74: minimatch ReDoS: nested *() extglobs generate catastrophically backtracking regular expressions

Upgrade minimatch from 9.0.5 to 9.0.7 or later

View advisory
root → tap → @tapjs/run → glob → minimatch

Blast radius

Paths from project root to minimatch - which dependencies pulled this package in?

ajv @ 6.12.6
root → standard → eslint → @eslint/eslintrc → ajv
1 finding medium
Trust 0/100 EPSS 0.5%
AUTO-MERGE Verdict tier: the fix passes all three lenses cleanly. In Mode C, Arguss opens a pull request for the upgrade; it does not merge PRs on GitHub. Click for more →
6.12.6 → 6.14.0 minor
auto-merge Verdict tier: the fix passes all three lenses cleanly. In Mode C, Arguss opens a pull request for the upgrade; it does not merge PRs on GitHub. Click for more → Score 100
Max CVSS 5.0 · 1 finding Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → Max EPSS 0.5% · 39th percentile Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
  • minor-level upgrade; trust signals unchanged; CI verifies tests
GHSA-2g4f-4pwh-qvx6: ajv has ReDoS when using `$data` option

Upgrade ajv from 6.12.6 to 6.14.0 or later

View advisory
root → standard → eslint → @eslint/eslintrc → ajv

Blast radius

Paths from project root to ajv - which dependencies pulled this package in?

ip-address @ 9.0.5
root → tap → @tapjs/run → pacote → npm-registry-fetch → make-fetch-happen → @npmcli/agent → socks-proxy-agent → socks → ip-address
1 finding medium
Trust 30/100 EPSS 0.5%
REVIEW Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more →
GHSA-v2v4-37r5-5v8g medium CVSS 5.0 EPSS 0.5%
ip-address has XSS in Address6 HTML-emitting methods
9.0.5 → 10.1.1 major
review-required Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more → Score 50
Max CVSS 5.0 · 1 finding Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → Max EPSS 0.5% · 37th percentile Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
fix_kind.major Veto: the available fix requires a major version bump (1.x → 2.x), which implies potential breaking changes outside the auto-merge envelope. Click for more →
  • major version bump requires human review (never auto-merge)
GHSA-v2v4-37r5-5v8g: ip-address has XSS in Address6 HTML-emitting methods

Upgrade ip-address from 9.0.5 to 10.1.1 or later

View advisory
root → tap → @tapjs/run → pacote → npm-registry-fetch → make-fetch-happen → @npmcli/agent → socks-proxy-agent → socks → ip-address

Blast radius

Paths from project root to ip-address - which dependencies pulled this package in?

yaml @ 2.6.1
root → tap → @tapjs/core → tap-yaml → yaml
1 finding medium
Trust 30/100 EPSS 0.5%
AUTO-MERGE Verdict tier: the fix passes all three lenses cleanly. In Mode C, Arguss opens a pull request for the upgrade; it does not merge PRs on GitHub. Click for more →
GHSA-48c2-rrv3-qjmp medium CVSS 4.3 EPSS 0.5%
yaml is vulnerable to Stack Overflow via deeply nested YAML collections
2.6.1 → 2.8.3 minor
auto-merge Verdict tier: the fix passes all three lenses cleanly. In Mode C, Arguss opens a pull request for the upgrade; it does not merge PRs on GitHub. Click for more → Score 100
Max CVSS 4.3 · 1 finding Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → Max EPSS 0.5% · 37th percentile Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
  • minor-level upgrade; trust signals unchanged; CI verifies tests
GHSA-48c2-rrv3-qjmp: yaml is vulnerable to Stack Overflow via deeply nested YAML collections

Upgrade yaml from 2.6.1 to 2.8.3 or later

View advisory
root → tap → @tapjs/core → tap-yaml → yaml

Blast radius

Paths from project root to yaml - which dependencies pulled this package in?

brace-expansion @ 1.1.11
root → standard-version → dotgitignore → minimatch → brace-expansion
39 findings medium–low
Trust 0/100 EPSS 0.5%
AUTO-MERGE Verdict tier: the fix passes all three lenses cleanly. In Mode C, Arguss opens a pull request for the upgrade; it does not merge PRs on GitHub. Click for more →
GHSA-f886-m6hf-6m8v medium CVSS 6.5 EPSS 0.4%
brace-expansion: Zero-step sequence causes process hang and memory exhaustion

Affects 13 install paths

GHSA-3jxr-9vmj-r5cp medium CVSS 5.3 EPSS 0.4%
brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups

Affects 13 install paths

GHSA-v6h2-p8h4-qcjw low CVSS 3.1 EPSS 0.5%
brace-expansion Regular Expression Denial of Service vulnerability

Affects 13 install paths

1.1.11 → 1.1.16 patch
auto-merge Verdict tier: the fix passes all three lenses cleanly. In Mode C, Arguss opens a pull request for the upgrade; it does not merge PRs on GitHub. Click for more → Score 100
Max CVSS 6.5 · 3 findings Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → Max EPSS 0.5% · 37th percentile Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
  • patch-level upgrade; trust signals unchanged; CI verifies tests
GHSA-f886-m6hf-6m8v: brace-expansion: Zero-step sequence causes process hang and memory exhaustion

Upgrade brace-expansion from 1.1.11 to 1.1.13 or later

View advisory
root → standard-version → dotgitignore → minimatch → brace-expansion
2.0.1 → 2.1.2 minor
auto-merge Verdict tier: the fix passes all three lenses cleanly. In Mode C, Arguss opens a pull request for the upgrade; it does not merge PRs on GitHub. Click for more → Score 100
Max CVSS 6.5 · 36 findings Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → Max EPSS 0.5% · 37th percentile Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
  • minor-level upgrade; trust signals unchanged; CI verifies tests
GHSA-f886-m6hf-6m8v: brace-expansion: Zero-step sequence causes process hang and memory exhaustion

Upgrade brace-expansion from 2.0.1 to 2.0.3 or later

View advisory
root → standard-version → dotgitignore → minimatch → brace-expansion

Blast radius

Paths from project root to brace-expansion - which dependencies pulled this package in?

js-yaml @ 4.1.0
root → standard → eslint → @eslint/eslintrc → js-yaml
3 findings high–medium
Trust 30/100 EPSS 0.4%
AUTO-MERGE Verdict tier: the fix passes all three lenses cleanly. In Mode C, Arguss opens a pull request for the upgrade; it does not merge PRs on GitHub. Click for more →
GHSA-52cp-r559-cp3m high CVSS 7.5 EPSS 0.4%
js-yaml: YAML merge-key chains can force quadratic CPU consumption
GHSA-h67p-54hq-rp68 medium CVSS 5.3 EPSS 0.3%
JS-YAML: Quadratic-complexity DoS in merge key handling via repeated aliases
4.1.0 → 4.3.0 minor
auto-merge Verdict tier: the fix passes all three lenses cleanly. In Mode C, Arguss opens a pull request for the upgrade; it does not merge PRs on GitHub. Click for more → Score 100
Max CVSS 7.5 · 3 findings Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → Max EPSS 0.4% · 33rd percentile Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
  • minor-level upgrade; trust signals unchanged; CI verifies tests
GHSA-52cp-r559-cp3m: js-yaml: YAML merge-key chains can force quadratic CPU consumption

Upgrade js-yaml from 4.1.0 to 4.3.0 or later

View advisory
root → standard → eslint → @eslint/eslintrc → js-yaml

Blast radius

Paths from project root to js-yaml - which dependencies pulled this package in?

picomatch @ 2.3.1
root → tap → @tapjs/run → chokidar → anymatch → picomatch
2 findings high–medium
Trust 0/100 EPSS 0.4%
AUTO-MERGE Verdict tier: the fix passes all three lenses cleanly. In Mode C, Arguss opens a pull request for the upgrade; it does not merge PRs on GitHub. Click for more →
GHSA-c2c7-rcm5-vvqj high CVSS 7.5 EPSS 0.4%
Picomatch has a ReDoS vulnerability via extglob quantifiers
GHSA-3v7f-55p6-f55p medium CVSS 5.3 EPSS 0.4%
Picomatch: Method Injection in POSIX Character Classes causes incorrect Glob Matching
2.3.1 → 2.3.2 patch
auto-merge Verdict tier: the fix passes all three lenses cleanly. In Mode C, Arguss opens a pull request for the upgrade; it does not merge PRs on GitHub. Click for more → Score 100
Max CVSS 7.5 · 2 findings Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → Max EPSS 0.4% · 33rd percentile Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
  • patch-level upgrade; trust signals unchanged; CI verifies tests
GHSA-c2c7-rcm5-vvqj: Picomatch has a ReDoS vulnerability via extglob quantifiers

Upgrade picomatch from 2.3.1 to 2.3.2 or later

View advisory
root → tap → @tapjs/run → chokidar → anymatch → picomatch

Blast radius

Paths from project root to picomatch - which dependencies pulled this package in?

uuid @ 8.3.2
root → tap → @tapjs/core → @tapjs/processinfo → uuid
1 finding high
Trust 0/100 EPSS 0.3%
REVIEW Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more →
GHSA-w5hq-g745-h8pq high CVSS 7.5 EPSS 0.3%
uuid: Missing buffer bounds check in v3/v5/v6 when buf is provided
8.3.2 → 11.1.1 major
review-required Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more → Score 50
Max CVSS 7.5 · 1 finding Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → Max EPSS 0.3% · 25th percentile Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
fix_kind.major Veto: the available fix requires a major version bump (1.x → 2.x), which implies potential breaking changes outside the auto-merge envelope. Click for more →
  • major version bump requires human review (never auto-merge)
GHSA-w5hq-g745-h8pq: uuid: Missing buffer bounds check in v3/v5/v6 when buf is provided

Upgrade uuid from 8.3.2 to 11.1.1 or later

View advisory
root → tap → @tapjs/core → @tapjs/processinfo → uuid

Blast radius

Paths from project root to uuid - which dependencies pulled this package in?

prismjs @ 1.29.0
root → tap → @tapjs/run → @tapjs/reporter → prismjs-terminal → prismjs
1 finding medium
Trust 0/100 EPSS 0.3% ⚠ new maintainer
REVIEW Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more →
1.29.0 → 1.30.0 minor
review-required Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more → Score 85
Max CVSS 4.9 · 1 finding Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → Max EPSS 0.3% · 22nd percentile Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
trust.new_maintainer Veto: a new publishing identity was added between your current version and the upgrade target. A well-documented supply chain attack vector. Click for more →
  • trust veto: new maintainer added
GHSA-x7hr-w5r2-h6wg: PrismJS DOM Clobbering vulnerability

Upgrade prismjs from 1.29.0 to 1.30.0 or later

View advisory
root → tap → @tapjs/run → @tapjs/reporter → prismjs-terminal → prismjs

Blast radius

Paths from project root to prismjs - which dependencies pulled this package in?

@sigstore/core @ 1.1.0
root → tap → @tapjs/run → pacote → sigstore → @sigstore/sign → @sigstore/core
1 finding medium
Trust 0/100 EPSS 0.3%
REVIEW Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more →
GHSA-jfc7-64v2-mr8c medium CVSS 5.4 EPSS 0.3%
@sigstore/core has DSSE payloadType type-binding failure
1.1.0 → 3.2.1 major
review-required Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more → Score 50
Max CVSS 5.4 · 1 finding Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → Max EPSS 0.3% · 18th percentile Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
fix_kind.major Veto: the available fix requires a major version bump (1.x → 2.x), which implies potential breaking changes outside the auto-merge envelope. Click for more →
  • major version bump requires human review (never auto-merge)
GHSA-jfc7-64v2-mr8c: @sigstore/core has DSSE payloadType type-binding failure

Upgrade @sigstore/core from 1.1.0 to 3.2.1 or later

View advisory
root → tap → @tapjs/run → pacote → sigstore → @sigstore/sign → @sigstore/core

Blast radius

Paths from project root to @sigstore/core - which dependencies pulled this package in?

sigstore @ 2.3.1
root → tap → @tapjs/run → pacote → sigstore
1 finding high
Trust 0/100 EPSS 0.2%
REVIEW Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more →
GHSA-52v5-jr5w-gjxr high CVSS 7.5 EPSS 0.2%
sigstore's `certificateOIDs` verification constraints are silently dropped and never enforced
2.3.1 → 4.1.1 major
review-required Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more → Score 50
Max CVSS 7.5 · 1 finding Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → Max EPSS 0.2% · 8th percentile Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
fix_kind.major Veto: the available fix requires a major version bump (1.x → 2.x), which implies potential breaking changes outside the auto-merge envelope. Click for more →
  • major version bump requires human review (never auto-merge)
GHSA-52v5-jr5w-gjxr: sigstore's `certificateOIDs` verification constraints are silently dropped and never enforced

Upgrade sigstore from 2.3.1 to 4.1.1 or later

View advisory
root → tap → @tapjs/run → pacote → sigstore

Blast radius

Paths from project root to sigstore - which dependencies pulled this package in?

Package status

631 packages scanned.

  • 8 Review-required candidates Arguss flagged these for a human decision - nothing merges until you review them.
  • 13 Auto-merge candidates

Review auto-merge candidates and open PRs in a guided flow.

Glossary

What the labels and signals mean.

Trust Save
A package upgrade Arguss would have blocked despite the new version being available, because trust signals, like ownership transfer or a new maintainer, fired during the upgrade window. The name reflects what the agent did for the user: saved them from a potentially malicious update that a version-only auto-PR tool would have merged.
AUTO-MERGE
Verdict tier indicating the fix passes all three lenses cleanly. After you confirm action from a Scan assessment, Arguss opens a pull request for the upgrade; it does not merge PRs on GitHub. The envelope is conservative on purpose: patch or minor version bump, trust signals unchanged, blast radius bounded, real tests pass.
REVIEW
Verdict tier requiring a human decision. At least one veto fired during fix-confidence evaluation, trust signals shifted, the pipeline can't verify post-upgrade behavior, or the upgrade is a major version bump. The agent surfaces the reasons; the developer decides.
DECLINE
Verdict tier indicating no remediation is recommended. Typically applies when no fix version exists for the finding, or when multiple critical vetoes make even human review unproductive.
fix_kind.major
Veto signal that fires when the available fix requires a major version bump (1.x → 2.x). Major bumps imply potential breaking changes and fall outside the auto-merge envelope by default, even when the upgrade is the only available fix.
trust.new_maintainer
Veto signal that fires when a package added a new maintainer during the upgrade window, meaning between the user's current version and the proposed upgrade. New publishing identities are a well-documented attack vector for typosquats and supply chain takeovers.
trust.ownership_transferred
Veto signal that fires when a package's primary maintainer changed during the upgrade window. Combined with trust.new_maintainer, this is the highest-risk trust combination, typical of the xz-utils style attacks and historical npm credential theft incidents.
pipeline.test_reality
Veto signal that fires when Arguss can't verify tests will run on the upgraded code. Four conditions must hold: a test script exists in package.json, it isn't a no-op, real test files exist, and a workflow actually invokes them. If any fail, the fix cannot qualify for AUTO_MERGE because there's no way to verify the upgrade didn't break the user's project.
CVSS
Common Vulnerability Scoring System. A numeric score (0.0–10.0) representing how damaging a vulnerability could be if exploited. Sourced from NIST's National Vulnerability Database via OSV.dev. Severity, not urgency.
EPSS
Exploit Prediction Scoring System. A daily-updated probability (0.0–1.0, displayed as percent) that a CVE will be exploited in the next 30 days. Sourced from FIRST.org. Probability, not severity.
KEV
CISA's Known Exploited Vulnerabilities catalog. A federal list of CVEs with documented active exploitation in the wild. Federal agencies have a binding patching deadline; for everyone else, presence on KEV is the strongest "this is being used right now" signal available. Sourced directly from CISA.
Project Risk Score (PRS)
A weighted blend of the three lens subscores (40% vulnerability, 30% trust, 30% pipeline) producing an overall 0–100 indicator of the project's dependency health. Useful for at-a-glance triage; the per-finding fix-confidence verdicts are what drive automated decisions.

Dependency graph

Full-project map of transitive dependencies. Severity colors reflect vulnerabilities; trust rings apply only to direct dependencies analyzed by OpenSSF Scorecard (higher = riskier).