Project Risk Score Project Risk Score: weighted blend of vulnerability (40%), trust (30%), and pipeline (30%) subscores. Useful for at-a-glance triage. Click for more →
77 /100
Critical

40 findings across 3 packages · 692 packages clean

Candidates: 1 auto-merge · 2 review · 0 decline · 0 no fix

Scanned chalk/chalk @ main Scan · Completed 215 hrs ago Download SBOM
Total Findings
40
All detected issues
KEV Findings
1
Known exploited
High EPSS
1
Likely to be exploited
Auto-merge ready
1
Remediation candidates
Affected pkgs
3
with remediation paths
KEV catalog CISA's Known Exploited Vulnerabilities catalog. Documented active exploitation in the wild; the strongest 'this is happening now' signal. Click for more →
1
actively exploited CVEs
Highest EPSS Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
49.0%
CVE-2023-5217
Active vetos
5
lens blocks on candidates

Findings

electron @ 0.4.1 An upgrade Arguss blocked despite the newer version being available, because trust signals like ownership transfer or new maintainer fired during the upgrade window. Click for more →
root → matcha → electron
36 findings critical–low
Trust 30/100 EPSS 49.0% ↑ ⚠ ownership transferred
REVIEW Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more →
GHSA-fjqr-fx3f-g4rv high CVSS 8.8 EPSS 2.4%
Electron protocol handler browser vulnerable to Command Injection
GHSA-qqvq-6xgj-jw8g high CVSS 8.8 EPSS 49.0%
Electron affected by libvpx's heap buffer overflow in vp8 encoding
GHSA-9wfr-w7mm-pc7f high CVSS 8.3 EPSS 0.3%
Electron: Renderer command-line switch injection via undocumented commandLineSwitches webPreference
GHSA-532v-xpq5-8h95 high CVSS 8.1 EPSS 0.4%
Electron: Use-after-free in offscreen child window paint callback
GHSA-m93v-9qjc-3g79 high CVSS 7.9 EPSS 0.4%
Context isolation bypass via leaked cross-context objects in Electron
GHSA-gvcj-pfq2-wxj7 high CVSS 7.8 EPSS 0.4%
High severity vulnerability that affects electron
GHSA-h9jc-284h-533g high CVSS 7.7 EPSS 1.0%
Context isolation bypass via contextBridge in Electron
GHSA-8337-3p73-46f4 high CVSS 7.5 EPSS 0.3%
Electron: Use-after-free in WebContents fullscreen, pointer-lock, and keyboard-lock permission callbacks
GHSA-jjp3-mq3x-295m high CVSS 7.0 EPSS 0.2%
Electron: Use-after-free in PowerMonitor on Windows and macOS
GHSA-6vrv-94jv-crrg medium CVSS 6.8 EPSS 0.8%
Context isolation bypass via Promise in Electron
GHSA-f9mq-jph6-9mhm medium CVSS 6.8 EPSS 1.2%
Arbitrary file read via window-open IPC in Electron
GHSA-mpjm-v997-c4h4 medium CVSS 6.8 EPSS 1.0%
Electron's sandboxed renderers can obtain thumbnails of arbitrary files through the nativeImage API
GHSA-xwr5-m59h-vwqr medium CVSS 6.8 EPSS 0.3%
Electron: nodeIntegrationInWorker not correctly scoped in shared renderer processes
GHSA-77xc-hjv8-ww97 medium CVSS 6.6 EPSS 0.9%
AutoUpdater module fails to validate certain nested components of the bundle
GHSA-5rqw-r77c-jp79 medium CVSS 6.5 EPSS 0.2%
Electron: AppleScript injection in app.moveToApplicationsFolder on macOS
GHSA-7m48-wc93-9g85 medium CVSS 6.1 EPSS 0.2%
ASAR Integrity bypass via filetype confusion in electron
GHSA-7x97-j373-85x5 medium CVSS 6.1 EPSS 0.6%
Electron vulnerable to out-of-package code execution when launched with arbitrary cwd
GHSA-vmqv-hx8q-j7mg medium CVSS 6.1 EPSS 0.3%
Electron has ASAR Integrity Bypass via resource modification
GHSA-f3pv-wv63-48x8 medium CVSS 6.0 EPSS 0.3%
Electron: Named window.open targets not scoped to the opener's browsing context
GHSA-p7v2-p9m8-qqg7 medium CVSS 6.0 EPSS 0.5%
Electron context isolation bypass via nested unserializable return value
GHSA-4p4r-m79c-wq3v medium CVSS 5.9 EPSS 0.2%
Electron: HTTP Response Header Injection in custom protocol handlers and webRequest
GHSA-xj5x-m3f3-5x3h medium CVSS 5.9 EPSS 0.1%
Electron: Service worker can spoof executeJavaScript IPC replies
GHSA-9w97-2464-8783 medium CVSS 5.8 EPSS 0.2%
Electron: Use-after-free in download save dialog callback
GHSA-hvf8-h2qh-37m9 medium CVSS 5.4 EPSS 1.7%
IPC messages delivered to the wrong frame in Electron
GHSA-p2jh-44qj-pf2v medium CVSS 5.4 EPSS 0.5%
Exfiltration of hashed SMB credentials on Windows via file:// redirect
GHSA-r5p7-gp4j-qhrx medium CVSS 5.4 EPSS 0.1%
Electron: Incorrect origin passed to permission request handler for iframe requests
GHSA-3c8v-cfp5-9885 medium CVSS 5.3 EPSS 0.2%
Electron: Out-of-bounds read in second-instance IPC on macOS and Linux
GHSA-6r2x-8pq8-9489 medium CVSS 5.0 EPSS 0.1%
Electron vulnerable to Heap Buffer Overflow in NativeImage
GHSA-mwmh-mq4g-g6gr medium CVSS 4.7 EPSS 0.2%
Electron: Registry key path injection in app.setAsDefaultProtocolClient on Windows
GHSA-jfqx-fxh3-c62j low CVSS 3.9 EPSS 0.1%
Electron: Unquoted executable path in app.setLoginItemSettings on Windows
GHSA-3p22-ghq8-v749 low CVSS 3.4 EPSS 0.9%
Renderers can obtain access to random bluetooth device without permission in Electron
GHSA-9899-m83m-qhpj low CVSS 3.3 EPSS 0.2%
Electron: USB device selection not validated against filtered device list
GHSA-f37v-82c4-4x64 low CVSS 2.8 EPSS 0.1%
Electron: Crash in clipboard.readImage() on malformed clipboard image data
GHSA-mq8j-3h7h-p8g7 low CVSS 2.2 EPSS 1.0%
Compromised child renderer processes could obtain IPC access without nodeIntegrationInSubFrames being enabled
0.4.1 → 39.8.5 major
review-required Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more → Score 20
Max CVSS 9.8 · 36 findings Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → CISA KEV CISA's Known Exploited Vulnerabilities catalog. Documented active exploitation in the wild; the strongest 'this is happening now' signal. Click for more → Max EPSS 49.0% · 98th percentile Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
fix_kind.major Veto: the available fix requires a major version bump (1.x → 2.x), which implies potential breaking changes outside the auto-merge envelope. Click for more → trust.new_maintainer Veto: a new publishing identity was added between your current version and the upgrade target. A well-documented supply chain attack vector. Click for more → trust.ownership_transferred Veto: the package's primary maintainer changed during the upgrade window. Combined with new-maintainer, this is the highest-risk trust combination. Click for more →
  • major version bump requires human review (never auto-merge)
  • trust veto: new maintainer added
  • trust veto: package ownership transferred between versions
GHSA-4w88-rjj3-x7wp: Chromium Remote Code Execution in electron

Upgrade electron from 0.4.1 to 1.6.14 or later

View advisory
root → matcha → electron

Blast radius

Paths from project root to electron - which dependencies pulled this package in?

got @ 9.6.0
root → ava → update-notifier → latest-version → package-json → got
1 finding medium
Trust 45/100 EPSS 2.2% ⚠ new maintainer
REVIEW Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more →
9.6.0 → 11.8.5 major
review-required Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more → Score 35
Max CVSS 5.3 · 1 finding Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → Max EPSS 2.2% · 80th percentile Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
fix_kind.major Veto: the available fix requires a major version bump (1.x → 2.x), which implies potential breaking changes outside the auto-merge envelope. Click for more → trust.new_maintainer Veto: a new publishing identity was added between your current version and the upgrade target. A well-documented supply chain attack vector. Click for more →
  • major version bump requires human review (never auto-merge)
  • trust veto: new maintainer added
GHSA-pfrx-2q88-qq97: Got allows a redirect to a UNIX socket

Upgrade got from 9.6.0 to 11.8.5 or later

View advisory
root → ava → update-notifier → latest-version → package-json → got

Blast radius

Paths from project root to got - which dependencies pulled this package in?

minimatch @ 9.0.3
root → xo → @typescript-eslint/parser → @typescript-eslint/typescript-estree → minimatch
3 findings high
Trust 30/100 EPSS 0.5%
AUTO-MERGE Verdict tier: the fix passes all three lenses cleanly. In Mode C, Arguss opens a pull request for the upgrade; it does not merge PRs on GitHub. Click for more →
GHSA-23c5-xmqv-rm74 high CVSS 7.5 EPSS 0.5%
minimatch ReDoS: nested *() extglobs generate catastrophically backtracking regular expressions
GHSA-3ppc-4f35-3m26 high CVSS 7.5 EPSS 0.5%
minimatch has a ReDoS via repeated wildcards with non-matching literal in pattern
GHSA-7r86-cg39-jmmj high CVSS 7.5 EPSS 0.5%
minimatch has ReDoS: matchOne() combinatorial backtracking via multiple non-adjacent GLOBSTAR segments
9.0.3 → 9.0.7 patch
auto-merge Verdict tier: the fix passes all three lenses cleanly. In Mode C, Arguss opens a pull request for the upgrade; it does not merge PRs on GitHub. Click for more → Score 100
Max CVSS 7.5 · 3 findings Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → Max EPSS 0.5% · 40th percentile Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
  • patch-level upgrade; trust signals unchanged; CI verifies tests
GHSA-23c5-xmqv-rm74: minimatch ReDoS: nested *() extglobs generate catastrophically backtracking regular expressions

Upgrade minimatch from 9.0.3 to 9.0.7 or later

View advisory
root → xo → @typescript-eslint/parser → @typescript-eslint/typescript-estree → minimatch

Blast radius

Paths from project root to minimatch - which dependencies pulled this package in?

Package status

695 packages scanned.

  • 2 Review-required candidates Arguss flagged these for a human decision - nothing merges until you review them.
  • 1 Auto-merge candidate

Review auto-merge candidates and open PRs in a guided flow.

Glossary

What the labels and signals mean.

Trust Save
A package upgrade Arguss would have blocked despite the new version being available, because trust signals, like ownership transfer or a new maintainer, fired during the upgrade window. The name reflects what the agent did for the user: saved them from a potentially malicious update that a version-only auto-PR tool would have merged.
AUTO-MERGE
Verdict tier indicating the fix passes all three lenses cleanly. After you confirm action from a Scan assessment, Arguss opens a pull request for the upgrade; it does not merge PRs on GitHub. The envelope is conservative on purpose: patch or minor version bump, trust signals unchanged, blast radius bounded, real tests pass.
REVIEW
Verdict tier requiring a human decision. At least one veto fired during fix-confidence evaluation, trust signals shifted, the pipeline can't verify post-upgrade behavior, or the upgrade is a major version bump. The agent surfaces the reasons; the developer decides.
DECLINE
Verdict tier indicating no remediation is recommended. Typically applies when no fix version exists for the finding, or when multiple critical vetoes make even human review unproductive.
fix_kind.major
Veto signal that fires when the available fix requires a major version bump (1.x → 2.x). Major bumps imply potential breaking changes and fall outside the auto-merge envelope by default, even when the upgrade is the only available fix.
trust.new_maintainer
Veto signal that fires when a package added a new maintainer during the upgrade window, meaning between the user's current version and the proposed upgrade. New publishing identities are a well-documented attack vector for typosquats and supply chain takeovers.
trust.ownership_transferred
Veto signal that fires when a package's primary maintainer changed during the upgrade window. Combined with trust.new_maintainer, this is the highest-risk trust combination, typical of the xz-utils style attacks and historical npm credential theft incidents.
pipeline.test_reality
Veto signal that fires when Arguss can't verify tests will run on the upgraded code. Four conditions must hold: a test script exists in package.json, it isn't a no-op, real test files exist, and a workflow actually invokes them. If any fail, the fix cannot qualify for AUTO_MERGE because there's no way to verify the upgrade didn't break the user's project.
CVSS
Common Vulnerability Scoring System. A numeric score (0.0–10.0) representing how damaging a vulnerability could be if exploited. Sourced from NIST's National Vulnerability Database via OSV.dev. Severity, not urgency.
EPSS
Exploit Prediction Scoring System. A daily-updated probability (0.0–1.0, displayed as percent) that a CVE will be exploited in the next 30 days. Sourced from FIRST.org. Probability, not severity.
KEV
CISA's Known Exploited Vulnerabilities catalog. A federal list of CVEs with documented active exploitation in the wild. Federal agencies have a binding patching deadline; for everyone else, presence on KEV is the strongest "this is being used right now" signal available. Sourced directly from CISA.
Project Risk Score (PRS)
A weighted blend of the three lens subscores (40% vulnerability, 30% trust, 30% pipeline) producing an overall 0–100 indicator of the project's dependency health. Useful for at-a-glance triage; the per-finding fix-confidence verdicts are what drive automated decisions.

Dependency graph

Full-project map of transitive dependencies. Severity colors reflect vulnerabilities; trust rings apply only to direct dependencies analyzed by OpenSSF Scorecard (higher = riskier).