Total Findings
40
All detected issues
KEV Findings
1
Known exploited
High EPSS
1
Likely to be exploited
Auto-merge ready
1
Remediation candidates
Affected pkgs
3
with remediation paths
KEV catalog
CISA's Known Exploited Vulnerabilities catalog. Documented active exploitation in the wild; the strongest 'this is happening now' signal.
Click for more →
1
actively exploited CVEs
Highest EPSS
Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity.
Click for more →
49.0%
CVE-2023-5217
Active vetos
5
lens blocks on candidates
Findings
36 findings
critical–low
Trust 30/100
EPSS 49.0% ↑
⚠ ownership transferred
REVIEW
Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk.
Click for more →
Electron protocol handler browser vulnerable to Command Injection
Electron affected by libvpx's heap buffer overflow in vp8 encoding
Electron: Renderer command-line switch injection via undocumented commandLineSwitches webPreference
Electron: Use-after-free in offscreen child window paint callback
Electron vulnerable to remote command execution
Context isolation bypass via leaked cross-context objects in Electron
High severity vulnerability that affects electron
Context isolation bypass via contextBridge in Electron
Electron: Use-after-free in WebContents fullscreen, pointer-lock, and keyboard-lock permission callbacks
Electron: Use-after-free in PowerMonitor on Windows and macOS
Context isolation bypass via Promise in Electron
Arbitrary file read via window-open IPC in Electron
Electron's sandboxed renderers can obtain thumbnails of arbitrary files through the nativeImage API
Electron: nodeIntegrationInWorker not correctly scoped in shared renderer processes
AutoUpdater module fails to validate certain nested components of the bundle
Electron: AppleScript injection in app.moveToApplicationsFolder on macOS
ASAR Integrity bypass via filetype confusion in electron
Electron vulnerable to out-of-package code execution when launched with arbitrary cwd
Electron has ASAR Integrity Bypass via resource modification
Electron: Named window.open targets not scoped to the opener's browsing context
Electron context isolation bypass via nested unserializable return value
Electron: HTTP Response Header Injection in custom protocol handlers and webRequest
Electron: Service worker can spoof executeJavaScript IPC replies
Electron: Use-after-free in download save dialog callback
IPC messages delivered to the wrong frame in Electron
Exfiltration of hashed SMB credentials on Windows via file:// redirect
Electron: Incorrect origin passed to permission request handler for iframe requests
Electron: Out-of-bounds read in second-instance IPC on macOS and Linux
Electron vulnerable to Heap Buffer Overflow in NativeImage
Electron: Registry key path injection in app.setAsDefaultProtocolClient on Windows
Electron: Unquoted executable path in app.setLoginItemSettings on Windows
Renderers can obtain access to random bluetooth device without permission in Electron
Electron: USB device selection not validated against filtered device list
Electron: Crash in clipboard.readImage() on malformed clipboard image data
Compromised child renderer processes could obtain IPC access without nodeIntegrationInSubFrames being enabled
0.4.1 → 39.8.5
major
Max CVSS 9.8 · 36 findings
Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency.
Click for more →
CISA KEV
CISA's Known Exploited Vulnerabilities catalog. Documented active exploitation in the wild; the strongest 'this is happening now' signal.
Click for more →
Max EPSS 49.0%
· 98th percentile
Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity.
Click for more →
fix_kind.major
Veto: the available fix requires a major version bump (1.x → 2.x), which implies potential breaking changes outside the auto-merge envelope.
Click for more →
trust.new_maintainer
Veto: a new publishing identity was added between your current version and the upgrade target. A well-documented supply chain attack vector.
Click for more →
trust.ownership_transferred
Veto: the package's primary maintainer changed during the upgrade window. Combined with new-maintainer, this is the highest-risk trust combination.
Click for more →
- major version bump requires human review (never auto-merge)
- trust veto: new maintainer added
- trust veto: package ownership transferred between versions
GHSA-4w88-rjj3-x7wp: Chromium Remote Code Execution in electron
Upgrade electron from 0.4.1 to 1.6.14 or later
View advisory
root →
matcha →
electron
Blast radius
Paths from project root to electron - which dependencies pulled this package in?
got
@ 9.6.0
1 finding
medium
Trust 45/100
EPSS 2.2%
⚠ new maintainer
REVIEW
Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk.
Click for more →
got
@ 9.6.0
Got allows a redirect to a UNIX socket
9.6.0 → 11.8.5
major
Max CVSS 5.3 · 1 finding
Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency.
Click for more →
Max EPSS 2.2%
· 80th percentile
Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity.
Click for more →
fix_kind.major
Veto: the available fix requires a major version bump (1.x → 2.x), which implies potential breaking changes outside the auto-merge envelope.
Click for more →
trust.new_maintainer
Veto: a new publishing identity was added between your current version and the upgrade target. A well-documented supply chain attack vector.
Click for more →
- major version bump requires human review (never auto-merge)
- trust veto: new maintainer added
GHSA-pfrx-2q88-qq97: Got allows a redirect to a UNIX socket
Upgrade got from 9.6.0 to 11.8.5 or later
View advisory
root →
ava →
update-notifier →
latest-version →
package-json →
got
Blast radius
Paths from project root to got - which dependencies pulled this package in?
minimatch
@ 9.0.3
3 findings
high
Trust 30/100
EPSS 0.5%
AUTO-MERGE
Verdict tier: the fix passes all three lenses cleanly. In Mode C, Arguss opens a pull request for the upgrade; it does not merge PRs on GitHub.
Click for more →
minimatch
@ 9.0.3
minimatch ReDoS: nested *() extglobs generate catastrophically backtracking regular expressions
minimatch has a ReDoS via repeated wildcards with non-matching literal in pattern
minimatch has ReDoS: matchOne() combinatorial backtracking via multiple non-adjacent GLOBSTAR segments
9.0.3 → 9.0.7
patch
Max CVSS 7.5 · 3 findings
Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency.
Click for more →
Max EPSS 0.5%
· 40th percentile
Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity.
Click for more →
- patch-level upgrade; trust signals unchanged; CI verifies tests
GHSA-23c5-xmqv-rm74: minimatch ReDoS: nested *() extglobs generate catastrophically backtracking regular expressions
Upgrade minimatch from 9.0.3 to 9.0.7 or later
View advisory
root →
xo →
@typescript-eslint/parser →
@typescript-eslint/typescript-estree →
minimatch
Blast radius
Paths from project root to minimatch - which dependencies pulled this package in?
Package status
695 packages scanned.
- 2 Review-required candidates Arguss flagged these for a human decision - nothing merges until you review them.
- 1 Auto-merge candidate
-
- @types/node 16.18.126 direct
- ava 3.15.0 direct
- c8 7.14.0 direct
- color-convert 2.0.1 direct
- execa 5.1.1 direct
- execa 6.1.0 direct
- log-update 5.0.1 direct
- matcha 0.7.0 direct
- tsd 0.19.1 direct
- xo 0.57.0 direct
- yoctodelay 2.0.0 direct
- @babel/code-frame 7.29.7
- @babel/helper-validator-identifier 7.29.7
- @bcoe/v8-coverage 0.2.3
- @concordance/react 2.0.0
- @eslint-community/eslint-utils 4.9.1
- @eslint-community/regexpp 4.12.2
- @eslint/eslintrc 2.1.4
- @eslint/eslintrc 3.3.6
- @eslint/js 8.57.1
- @humanwhocodes/config-array 0.13.0
- @humanwhocodes/module-importer 1.0.1
- @humanwhocodes/object-schema 2.0.3
- @istanbuljs/schema 0.1.6
- @jridgewell/gen-mapping 0.3.13
- @jridgewell/resolve-uri 3.1.2
- @jridgewell/source-map 0.3.11
- @jridgewell/sourcemap-codec 1.5.5
- @jridgewell/trace-mapping 0.3.31
- @nodelib/fs.scandir 2.1.5
- @nodelib/fs.stat 2.0.5
- @nodelib/fs.walk 1.2.8
- @pkgr/core 0.3.6
- @rtsao/scc 1.1.0
- @sindresorhus/is 0.14.0
- @sindresorhus/merge-streams 2.3.0
- @szmarczak/http-timer 1.1.2
- @tsd/typescript 4.5.5
- @types/eslint 7.29.0
- @types/eslint 8.56.12
- @types/eslint 9.6.1
- @types/estree 1.0.9
- @types/istanbul-lib-coverage 2.0.6
- @types/json-schema 7.0.15
- @types/json5 0.0.29
- @types/minimist 1.2.5
- @types/normalize-package-data 2.4.4
- @types/semver 7.7.1
- @typescript-eslint/eslint-plugin 6.21.0
- @typescript-eslint/parser 6.21.0
- @typescript-eslint/scope-manager 6.21.0
- @typescript-eslint/type-utils 6.21.0
- @typescript-eslint/types 6.21.0
- @typescript-eslint/typescript-estree 6.21.0
- @typescript-eslint/utils 6.21.0
- @typescript-eslint/visitor-keys 6.21.0
- @ungap/structured-clone 1.3.3
- @webassemblyjs/ast 1.14.1
- @webassemblyjs/floating-point-hex-parser 1.13.2
- @webassemblyjs/helper-api-error 1.13.2
- @webassemblyjs/helper-buffer 1.14.1
- @webassemblyjs/helper-numbers 1.13.2
- @webassemblyjs/helper-wasm-bytecode 1.13.2
- @webassemblyjs/helper-wasm-section 1.14.1
- @webassemblyjs/ieee754 1.13.2
- @webassemblyjs/leb128 1.13.2
- @webassemblyjs/utf8 1.13.2
- @webassemblyjs/wasm-edit 1.14.1
- @webassemblyjs/wasm-gen 1.14.1
- @webassemblyjs/wasm-opt 1.14.1
- @webassemblyjs/wasm-parser 1.14.1
- @webassemblyjs/wast-printer 1.14.1
- @xtuc/ieee754 1.2.0
- @xtuc/long 4.2.2
- acorn 8.17.0
- acorn-import-phases 1.0.4
- acorn-jsx 5.3.2
- acorn-walk 8.3.5
- aggregate-error 3.1.0
- ajv 6.15.0
- ajv 8.20.0
- ajv-formats 2.1.1
- ajv-keywords 5.1.0
- ansi-align 3.0.1
- ansi-escapes 4.3.2
- ansi-escapes 5.0.0
- ansi-escapes 6.2.1
- ansi-regex 5.0.1
- ansi-regex 6.2.2
- ansi-styles 4.3.0
- ansi-styles 5.2.0
- ansi-styles 6.2.3
- anymatch 3.1.3
- argparse 1.0.10
- argparse 2.0.1
- array-buffer-byte-length 1.0.2
- array-find-index 1.0.2
- array-includes 3.1.9
- array-union 2.1.0
- array.prototype.findlastindex 1.2.6
- array.prototype.flat 1.3.3
- array.prototype.flatmap 1.3.3
- arraybuffer.prototype.slice 1.0.4
- arrgv 1.0.2
- arrify 1.0.1
- arrify 2.0.1
- arrify 3.0.0
- astral-regex 2.0.0
- async-function 1.0.0
- available-typed-arrays 1.0.7
- balanced-match 1.0.2
- base64-js 1.5.1
- baseline-browser-mapping 2.11.0
- binary-extensions 2.3.0
- bl 4.1.0
- blueimp-md5 2.19.0
- boxen 5.1.2
- brace-expansion 1.1.16
- brace-expansion 2.1.2
- braces 3.0.3
- browserslist 4.28.6
- buffer 5.7.1
- buffer-from 1.1.2
- builtin-modules 3.3.0
- builtins 5.1.0
- cacheable-request 6.1.0
- call-bind 1.0.9
- call-bind-apply-helpers 1.0.2
- call-bound 1.0.4
- callsites 3.1.0
- camelcase 5.3.1
- camelcase 6.3.0
- camelcase-keys 6.2.2
- caniuse-lite 1.0.30001806
- chalk 4.1.2
- chalk 5.6.2
- chokidar 3.6.0
- chrome-trace-event 1.0.4
- chunkd 2.0.1
- ci-info 2.0.0
- ci-info 4.4.0
- ci-parallel-vars 1.0.1
- clean-regexp 1.0.0
- clean-stack 2.2.0
- clean-yaml-object 0.1.0
- cli-boxes 2.2.1
- cli-cursor 3.1.0
- cli-cursor 4.0.0
- cli-spinners 2.9.2
- cli-truncate 2.1.0
- cliui 7.0.4
- clone 1.0.4
- clone-response 1.0.3
- code-excerpt 3.0.0
- color-name 1.1.4
- commander 2.20.3
- common-path-prefix 3.0.0
- concat-map 0.0.1
- concordance 5.0.4
- configstore 5.0.1
- confusing-browser-globals 1.0.11
- convert-source-map 1.9.0
- convert-source-map 2.0.0
- convert-to-spaces 1.0.2
- core-js-compat 3.49.0
- cosmiconfig 8.3.6
- cross-spawn 7.0.6
- crypto-random-string 2.0.0
- currently-unhandled 0.4.1
- data-view-buffer 1.0.2
- data-view-byte-length 1.0.2
- data-view-byte-offset 1.0.1
- date-time 3.1.0
- debug 3.2.7
- debug 4.4.3
- decamelize 1.2.0
- decamelize-keys 1.1.1
- decompress-response 3.3.0
- deep-extend 0.6.0
- deep-is 0.1.4
- defaults 1.0.4
- defer-to-connect 1.1.3
- define-data-property 1.1.4
- define-lazy-prop 2.0.0
- define-lazy-prop 3.0.0
- define-properties 1.2.1
- del 6.1.1
- dir-glob 3.0.1
- doctrine 2.1.0
- doctrine 3.0.0
- dot-prop 5.3.0
- drip 1.1.0
- dunder-proto 1.0.1
- duplexer3 0.1.5
- eastasianwidth 0.2.0
- electron-to-chromium 1.5.394
- emittery 0.8.1
- emoji-regex 10.6.0
- emoji-regex 8.0.0
- emoji-regex 9.2.2
- end-of-stream 1.4.5
- enhance-visitors 1.0.0
- enhanced-resolve 0.9.1
- enhanced-resolve 5.24.3
- env-editor 1.3.0
- equal-length 1.0.1
- error-ex 1.3.4
- es-abstract 1.24.2
- es-abstract-get 1.0.0
- es-define-property 1.0.1
- es-errors 1.3.0
- es-module-lexer 2.3.1
- es-object-atoms 1.1.2
- es-set-tostringtag 2.1.0
- es-shim-unscopables 1.1.0
- es-to-primitive 1.3.4
- escalade 3.2.0
- escape-goat 2.1.1
- escape-string-regexp 1.0.5
- escape-string-regexp 2.0.0
- escape-string-regexp 4.0.0
- eslint 8.57.1
- eslint-compat-utils 0.5.1
- eslint-config-prettier 9.1.2
- eslint-config-xo 0.44.0
- eslint-config-xo-typescript 2.1.1
- eslint-formatter-pretty 4.1.0
- eslint-formatter-pretty 6.0.1
- eslint-import-resolver-node 0.3.10
- eslint-import-resolver-webpack 0.13.11
- eslint-module-utils 2.14.0
- eslint-plugin-ava 14.0.0
- eslint-plugin-es-x 7.8.0
- eslint-plugin-eslint-comments 3.2.0
- eslint-plugin-import 2.32.0
- eslint-plugin-n 16.6.2
- eslint-plugin-no-use-extend-native 0.5.0
- eslint-plugin-prettier 5.5.6
- eslint-plugin-unicorn 51.0.1
- eslint-rule-docs 1.1.235
- eslint-scope 5.1.1
- eslint-scope 7.2.2
- eslint-utils 3.0.0
- eslint-visitor-keys 2.1.0
- eslint-visitor-keys 3.4.3
- eslint-visitor-keys 4.2.1
- esm-utils 4.4.2
- espree 10.4.0
- espree 9.6.1
- esprima 4.0.1
- espurify 2.1.1
- esquery 1.7.0
- esrecurse 4.3.0
- estraverse 4.3.0
- estraverse 5.3.0
- esutils 2.0.3
- events 3.3.0
- fast-deep-equal 3.1.3
- fast-diff 1.3.0
- fast-glob 3.3.3
- fast-json-stable-stringify 2.1.0
- fast-levenshtein 2.0.6
- fast-uri 3.1.4
- fastq 1.20.1
- figures 3.2.0
- file-entry-cache 6.0.1
- fill-range 7.1.1
- find-cache-dir 5.0.0
- find-root 1.1.0
- find-up 3.0.0
- find-up 4.1.0
- find-up 5.0.0
- find-up 6.3.0
- find-up-simple 1.0.1
- flat-cache 3.2.0
- flatted 3.4.2
- for-each 0.3.5
- foreground-child 2.0.0
- fs.realpath 1.0.0
- fsevents 2.3.3
- function-bind 1.1.2
- function.prototype.name 1.2.0
- functions-have-names 1.2.3
- generator-function 2.0.1
- get-caller-file 2.0.5
- get-east-asian-width 1.6.0
- get-intrinsic 1.3.0
- get-proto 1.0.1
- get-set-props 0.1.0
- get-stdin 9.0.0
- get-stream 4.1.0
- get-stream 5.2.0
- get-stream 6.0.1
- get-symbol-description 1.1.0
- get-tsconfig 4.14.0
- glob 7.2.3
- glob-parent 5.1.2
- glob-parent 6.0.2
- global-dirs 3.0.1
- globals 13.24.0
- globals 14.0.0
- globalthis 1.0.4
- globby 11.1.0
- globby 14.1.0
- gopd 1.2.0
- graceful-fs 4.2.11
- graphemer 1.4.0
- hard-rejection 2.1.0
- has-bigints 1.1.0
- has-flag 4.0.0
- has-property-descriptors 1.0.2
- has-proto 1.2.0
- has-symbols 1.1.0
- has-tostringtag 1.0.2
- has-yarn 2.1.0
- hasown 2.0.4
- hosted-git-info 2.8.9
- hosted-git-info 4.1.0
- html-escaper 2.0.2
- http-cache-semantics 4.2.0
- human-signals 2.1.0
- human-signals 3.0.1
- ieee754 1.2.1
- ignore 5.3.2
- ignore 7.0.6
- ignore-by-default 2.1.0
- import-fresh 3.3.1
- import-lazy 2.1.0
- import-local 3.2.0
- import-meta-resolve 4.2.0
- import-modules 2.1.0
- imurmurhash 0.1.4
- indent-string 4.0.0
- inflight 1.0.6
- inherits 2.0.4
- ini 1.3.8
- ini 2.0.0
- internal-slot 1.1.0
- interpret 1.4.0
- irregular-plurals 3.5.0
- is-absolute 1.0.0
- is-array-buffer 3.0.5
- is-arrayish 0.2.1
- is-async-function 2.1.1
- is-bigint 1.1.0
- is-binary-path 2.1.0
- is-boolean-object 1.2.2
- is-builtin-module 3.2.1
- is-callable 1.2.7
- is-ci 2.0.0
- is-core-module 2.16.2
- is-data-view 1.0.2
- is-date-object 1.1.0
- is-docker 2.2.1
- is-document.all 1.0.0
- is-error 2.2.2
- is-extglob 2.1.1
- is-finalizationregistry 1.1.1
- is-fullwidth-code-point 3.0.0
- is-fullwidth-code-point 4.0.0
- is-generator-function 1.1.2
- is-get-set-prop 1.0.0
- is-glob 4.0.3
- is-installed-globally 0.4.0
- is-interactive 1.0.0
- is-js-type 2.0.0
- is-map 2.0.3
- is-negated-glob 1.0.0
- is-negative-zero 2.0.3
- is-npm 5.0.0
- is-number 7.0.0
- is-number-object 1.1.1
- is-obj 2.0.0
- is-obj-prop 1.0.0
- is-path-cwd 2.2.0
- is-path-inside 3.0.3
- is-plain-obj 1.1.0
- is-plain-object 5.0.0
- is-promise 4.0.0
- is-proto-prop 2.0.0
- is-regex 1.2.1
- is-relative 1.0.0
- is-set 2.0.3
- is-shared-array-buffer 1.0.4
- is-stream 2.0.1
- is-stream 3.0.0
- is-string 1.1.1
- is-symbol 1.1.1
- is-typed-array 1.1.15
- is-typedarray 1.0.0
- is-unc-path 1.0.0
- is-unicode-supported 0.1.0
- is-unicode-supported 1.3.0
- is-weakmap 2.0.2
- is-weakref 1.1.1
- is-weakset 2.0.4
- is-windows 1.0.2
- is-wsl 2.2.0
- is-yarn-global 0.3.0
- isarray 2.0.5
- isexe 2.0.0
- istanbul-lib-coverage 3.2.2
- istanbul-lib-report 3.0.1
- istanbul-reports 3.2.0
- jest-worker 27.5.1
- js-string-escape 1.0.1
- js-tokens 4.0.0
- js-types 1.0.0
- js-yaml 3.15.0
- js-yaml 4.3.0
- jsesc 0.5.0
- jsesc 3.1.0
- json-buffer 3.0.0
- json-buffer 3.0.1
- json-parse-better-errors 1.0.2
- json-parse-even-better-errors 2.3.1
- json-schema-traverse 0.4.1
- json-schema-traverse 1.0.0
- json-stable-stringify-without-jsonify 1.0.1
- json5 1.0.2
- keyv 3.1.0
- keyv 4.5.4
- kind-of 6.0.3
- latest-version 5.1.0
- levn 0.4.1
- line-column-path 3.0.0
- lines-and-columns 1.2.4
- load-json-file 5.3.0
- loader-runner 4.3.2
- locate-path 3.0.0
- locate-path 5.0.0
- locate-path 6.0.0
- locate-path 7.2.0
- lodash 4.18.1
- lodash-es 4.18.1
- lodash.merge 4.6.2
- log-symbols 4.1.0
- log-symbols 6.0.0
- lowercase-keys 1.0.1
- lowercase-keys 2.0.0
- lru-cache 6.0.0
- make-dir 3.1.0
- make-dir 4.0.0
- map-age-cleaner 0.1.3
- map-obj 1.0.1
- map-obj 4.3.0
- matcher 3.0.0
- math-intrinsics 1.1.0
- md5-hex 3.0.1
- mem 8.1.1
- memory-fs 0.2.0
- meow 13.2.0
- meow 9.0.0
- merge-stream 2.0.0
- merge2 1.4.1
- micro-spelling-correcter 1.1.1
- micromatch 4.0.8
- mime-db 1.54.0
- mimic-fn 2.1.0
- mimic-fn 3.1.0
- mimic-fn 4.0.0
- mimic-response 1.0.1
- min-indent 1.0.1
- minimatch 3.1.5
- minimist 1.2.8
- minimist-options 4.1.0
- minimizer-webpack-plugin 5.6.1
- ms 2.1.3
- natural-compare 1.4.0
- neo-async 2.6.2
- node-exports-info 1.6.2
- node-releases 2.0.51
- normalize-package-data 2.5.0
- normalize-package-data 3.0.3
- normalize-path 3.0.0
- normalize-url 4.5.1
- npm-run-path 4.0.1
- npm-run-path 5.3.0
- obj-props 1.4.0
- object-inspect 1.13.4
- object-keys 1.1.1
- object.assign 4.1.7
- object.entries 1.1.9
- object.fromentries 2.0.8
- object.groupby 1.0.3
- object.values 1.2.1
- once 1.4.0
- onetime 5.1.2
- onetime 6.0.0
- open 8.4.2
- open-editor 4.1.1
- optionator 0.9.4
- ora 5.4.1
- own-keys 1.0.2
- p-cancelable 1.1.0
- p-defer 1.0.0
- p-event 4.2.0
- p-finally 1.0.0
- p-limit 2.3.0
- p-limit 3.1.0
- p-limit 4.0.0
- p-locate 3.0.0
- p-locate 4.1.0
- p-locate 5.0.0
- p-locate 6.0.0
- p-map 4.0.0
- p-timeout 3.2.0
- p-try 2.2.0
- package-json 6.5.0
- parent-module 1.0.1
- parse-json 4.0.0
- parse-json 5.2.0
- parse-ms 2.1.0
- path-exists 3.0.0
- path-exists 4.0.0
- path-exists 5.0.0
- path-is-absolute 1.0.1
- path-key 3.1.1
- path-key 4.0.0
- path-parse 1.0.7
- path-type 4.0.0
- path-type 6.0.0
- picocolors 1.1.1
- picomatch 2.3.2
- pify 4.0.1
- pkg-conf 3.1.0
- pkg-dir 4.2.0
- pkg-dir 5.0.0
- pkg-dir 7.0.0
- plur 4.0.0
- plur 5.1.0
- pluralize 8.0.0
- possible-typed-array-names 1.1.0
- prelude-ls 1.2.1
- prepend-http 2.0.0
- prettier 3.9.6
- prettier-linter-helpers 1.0.1
- pretty-ms 7.0.1
- proto-props 2.0.0
- pump 3.0.4
- punycode 2.3.1
- pupa 2.1.1
- queue-microtask 1.2.3
- quick-lru 4.0.1
- rc 1.2.8
- read-pkg 5.2.0
- read-pkg-up 7.0.1
- readable-stream 3.6.2
- readdirp 3.6.0
- redent 3.0.0
- reflect.getprototypeof 1.0.10
- regexp-tree 0.1.27
- regexp.prototype.flags 1.5.4
- registry-auth-token 4.2.2
- registry-url 5.1.0
- regjsparser 0.10.0
- require-directory 2.1.1
- require-from-string 2.0.2
- resolve 1.22.12
- resolve 2.0.0-next.7
- resolve-cwd 3.0.0
- resolve-from 4.0.0
- resolve-from 5.0.0
- resolve-pkg-maps 1.0.0
- responselike 1.0.2
- restore-cursor 3.1.0
- restore-cursor 4.0.0
- reusify 1.1.0
- rimraf 3.0.2
- run-parallel 1.2.0
- safe-array-concat 1.1.4
- safe-buffer 5.2.1
- safe-push-apply 1.0.0
- safe-regex-test 1.1.0
- schema-utils 4.3.3
- semver 5.7.2
- semver 6.3.1
- semver 7.8.5
- semver-diff 3.1.1
- serialize-error 7.0.1
- set-function-length 1.2.2
- set-function-name 2.0.2
- set-proto 1.0.0
- shebang-command 2.0.0
- shebang-regex 3.0.0
- side-channel 1.1.1
- side-channel-list 1.0.1
- side-channel-map 1.0.1
- side-channel-weakmap 1.0.2
- signal-exit 3.0.7
- slash 3.0.0
- slash 5.1.0
- slice-ansi 3.0.0
- slice-ansi 5.0.0
- source-map 0.6.1
- source-map-support 0.5.21
- spdx-correct 3.2.0
- spdx-exceptions 2.5.0
- spdx-expression-parse 3.0.1
- spdx-license-ids 3.0.23
- sprintf-js 1.0.3
- stack-utils 2.0.6
- stop-iteration-iterator 1.1.0
- string-width 4.2.3
- string-width 5.1.2
- string-width 7.2.0
- string.prototype.trim 1.2.11
- string.prototype.trimend 1.0.10
- string.prototype.trimstart 1.0.8
- string_decoder 1.3.0
- strip-ansi 6.0.1
- strip-ansi 7.2.0
- strip-bom 3.0.0
- strip-final-newline 2.0.0
- strip-final-newline 3.0.0
- strip-indent 3.0.0
- strip-json-comments 2.0.1
- strip-json-comments 3.1.1
- supertap 2.0.0
- supports-color 7.2.0
- supports-color 8.1.1
- supports-hyperlinks 2.3.0
- supports-hyperlinks 3.2.0
- supports-preserve-symlinks-flag 1.0.0
- synckit 0.11.13
- tapable 0.1.10
- tapable 2.3.3
- tea-concat 0.1.0
- temp-dir 2.0.0
- terser 5.49.0
- test-exclude 6.0.0
- text-table 0.2.0
- time-zone 1.0.0
- to-absolute-glob 3.0.0
- to-readable-stream 1.0.0
- to-regex-range 5.0.1
- trim-newlines 3.0.1
- trim-off-newlines 1.0.3
- ts-api-utils 1.4.3
- tsconfig-paths 3.15.0
- type-check 0.4.0
- type-fest 0.13.1
- type-fest 0.18.1
- type-fest 0.20.2
- type-fest 0.21.3
- type-fest 0.3.1
- type-fest 0.6.0
- type-fest 0.8.1
- type-fest 1.4.0
- type-fest 2.19.0
- typed-array-buffer 1.0.3
- typed-array-byte-length 1.0.3
- typed-array-byte-offset 1.0.4
- typed-array-length 1.0.8
- typedarray-to-buffer 3.1.5
- typescript 5.9.3
- unbox-primitive 1.1.0
- unc-path-regex 0.1.2
- unicorn-magic 0.3.0
- unique-string 2.0.0
- update-browserslist-db 1.2.3
- update-notifier 5.1.0
- uri-js 4.4.1
- url-or-path 2.7.1
- url-parse-lax 3.0.0
- util-deprecate 1.0.2
- v8-argv 0.1.0
- v8-to-istanbul 9.3.0
- validate-npm-package-license 3.0.4
- watchpack 2.5.2
- wcwidth 1.0.1
- webpack 5.108.4
- webpack-sources 3.5.1
- well-known-symbols 2.0.0
- which 2.0.2
- which-boxed-primitive 1.1.1
- which-builtin-type 1.2.1
- which-collection 1.0.2
- which-typed-array 1.1.22
- widest-line 3.1.0
- word-wrap 1.2.5
- wrap-ansi 7.0.0
- wrap-ansi 8.1.0
- wrappy 1.0.2
- write-file-atomic 3.0.3
- xdg-basedir 4.0.0
- y18n 5.0.8
- yallist 4.0.0
- yargs 16.2.2
- yargs-parser 20.2.9
- yocto-queue 0.1.0
- yocto-queue 1.2.2
Review auto-merge candidates and open PRs in a guided flow.
Glossary
What the labels and signals mean.
Glossary
What the labels and signals mean.
- Trust Save
- A package upgrade Arguss would have blocked despite the new version being available, because trust signals, like ownership transfer or a new maintainer, fired during the upgrade window. The name reflects what the agent did for the user: saved them from a potentially malicious update that a version-only auto-PR tool would have merged.
- AUTO-MERGE
- Verdict tier indicating the fix passes all three lenses cleanly. After you confirm action from a Scan assessment, Arguss opens a pull request for the upgrade; it does not merge PRs on GitHub. The envelope is conservative on purpose: patch or minor version bump, trust signals unchanged, blast radius bounded, real tests pass.
- REVIEW
- Verdict tier requiring a human decision. At least one veto fired during fix-confidence evaluation, trust signals shifted, the pipeline can't verify post-upgrade behavior, or the upgrade is a major version bump. The agent surfaces the reasons; the developer decides.
- DECLINE
- Verdict tier indicating no remediation is recommended. Typically applies when no fix version exists for the finding, or when multiple critical vetoes make even human review unproductive.
fix_kind.major- Veto signal that fires when the available fix requires a major version bump (1.x → 2.x). Major bumps imply potential breaking changes and fall outside the auto-merge envelope by default, even when the upgrade is the only available fix.
trust.new_maintainer- Veto signal that fires when a package added a new maintainer during the upgrade window, meaning between the user's current version and the proposed upgrade. New publishing identities are a well-documented attack vector for typosquats and supply chain takeovers.
trust.ownership_transferred- Veto signal that fires when a package's primary maintainer changed during the upgrade window. Combined with
trust.new_maintainer, this is the highest-risk trust combination, typical of the xz-utils style attacks and historical npm credential theft incidents. pipeline.test_reality- Veto signal that fires when Arguss can't verify tests will run on the upgraded code. Four conditions must hold: a test script exists in
package.json, it isn't a no-op, real test files exist, and a workflow actually invokes them. If any fail, the fix cannot qualify for AUTO_MERGE because there's no way to verify the upgrade didn't break the user's project. - CVSS
- Common Vulnerability Scoring System. A numeric score (0.0–10.0) representing how damaging a vulnerability could be if exploited. Sourced from NIST's National Vulnerability Database via OSV.dev. Severity, not urgency.
- EPSS
- Exploit Prediction Scoring System. A daily-updated probability (0.0–1.0, displayed as percent) that a CVE will be exploited in the next 30 days. Sourced from FIRST.org. Probability, not severity.
- KEV
- CISA's Known Exploited Vulnerabilities catalog. A federal list of CVEs with documented active exploitation in the wild. Federal agencies have a binding patching deadline; for everyone else, presence on KEV is the strongest "this is being used right now" signal available. Sourced directly from CISA.
- Project Risk Score (PRS)
- A weighted blend of the three lens subscores (40% vulnerability, 30% trust, 30% pipeline) producing an overall 0–100 indicator of the project's dependency health. Useful for at-a-glance triage; the per-finding fix-confidence verdicts are what drive automated decisions.
Dependency graph
Full-project map of transitive dependencies. Severity colors reflect vulnerabilities; trust rings apply only to direct dependencies analyzed by OpenSSF Scorecard (higher = riskier).