Total Findings
1
All detected issues
KEV Findings
0
Known exploited
High EPSS
0
Likely to be exploited
Auto-merge ready
1
Remediation candidates
Affected pkgs
1
with remediation paths
KEV catalog
CISA's Known Exploited Vulnerabilities catalog. Documented active exploitation in the wild; the strongest 'this is happening now' signal.
Click for more →
0
actively exploited CVEs
Highest EPSS
Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity.
Click for more →
0.4%
CVE-2026-13149
Active vetos
0
lens blocks on candidates
Findings
brace-expansion
@ 5.0.6
1 finding
medium
Trust 0/100
EPSS 0.4%
AUTO-MERGE
Verdict tier: the fix passes all three lenses cleanly. In Mode C, Arguss opens a pull request for the upgrade; it does not merge PRs on GitHub.
Click for more →
brace-expansion
@ 5.0.6
5.0.6 → 5.0.7
patch
Max CVSS 5.3 · 1 finding
Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency.
Click for more →
Max EPSS 0.4%
· 28th percentile
Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity.
Click for more →
- patch-level upgrade; trust signals unchanged; CI verifies tests
GHSA-3jxr-9vmj-r5cp: brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups
Upgrade brace-expansion from 5.0.6 to 5.0.7 or later
View advisory
root →
eslint →
minimatch →
brace-expansion
Blast radius
Paths from project root to brace-expansion - which dependencies pulled this package in?
Package status
204 packages scanned.
- 1 Auto-merge candidate
-
- @eslint/js 10.0.1 direct
- @types/node 22.19.19 direct
- eslint 10.4.0 direct
- eslint-config-prettier 10.1.8 direct
- globals 17.6.0 direct
- prettier 3.8.3 direct
- tsd 0.33.0 direct
- typescript 6.0.3 direct
- typescript-eslint 8.59.4 direct
- @babel/code-frame 7.29.0
- @babel/helper-validator-identifier 7.28.5
- @eslint-community/eslint-utils 4.9.1
- @eslint-community/regexpp 4.12.2
- @eslint/config-array 0.23.5
- @eslint/config-helpers 0.6.0
- @eslint/core 1.2.1
- @eslint/object-schema 3.0.5
- @eslint/plugin-kit 0.7.1
- @humanfs/core 0.19.2
- @humanfs/node 0.16.8
- @humanfs/types 0.15.0
- @humanwhocodes/module-importer 1.0.1
- @humanwhocodes/retry 0.4.3
- @jest/schemas 29.6.3
- @nodelib/fs.scandir 2.1.5
- @nodelib/fs.stat 2.0.5
- @nodelib/fs.walk 1.2.8
- @sinclair/typebox 0.27.10
- @tsd/typescript 5.9.3
- @types/eslint 7.29.0
- @types/esrecurse 4.3.1
- @types/estree 1.0.9
- @types/json-schema 7.0.15
- @types/minimist 1.2.5
- @types/normalize-package-data 2.4.4
- @typescript-eslint/eslint-plugin 8.59.4
- @typescript-eslint/parser 8.59.4
- @typescript-eslint/project-service 8.59.4
- @typescript-eslint/scope-manager 8.59.4
- @typescript-eslint/tsconfig-utils 8.59.4
- @typescript-eslint/type-utils 8.59.4
- @typescript-eslint/types 8.59.4
- @typescript-eslint/typescript-estree 8.59.4
- @typescript-eslint/utils 8.59.4
- @typescript-eslint/visitor-keys 8.59.4
- acorn 8.16.0
- acorn-jsx 5.3.2
- ajv 6.15.0
- ansi-escapes 4.3.2
- ansi-regex 5.0.1
- ansi-styles 4.3.0
- ansi-styles 5.2.0
- array-union 2.1.0
- arrify 1.0.1
- balanced-match 4.0.4
- braces 3.0.3
- camelcase 5.3.1
- camelcase-keys 6.2.2
- chalk 4.1.2
- color-convert 2.0.1
- color-name 1.1.4
- cross-spawn 7.0.6
- debug 4.4.3
- decamelize 1.2.0
- decamelize-keys 1.1.1
- deep-is 0.1.4
- diff-sequences 29.6.3
- dir-glob 3.0.1
- emoji-regex 8.0.0
- error-ex 1.3.4
- es-errors 1.3.0
- escape-string-regexp 4.0.0
- eslint-formatter-pretty 4.1.0
- eslint-rule-docs 1.1.235
- eslint-scope 9.1.2
- eslint-visitor-keys 3.4.3
- eslint-visitor-keys 5.0.1
- espree 11.2.0
- esquery 1.7.0
- esrecurse 4.3.0
- estraverse 5.3.0
- esutils 2.0.3
- fast-deep-equal 3.1.3
- fast-glob 3.3.3
- fast-json-stable-stringify 2.1.0
- fast-levenshtein 2.0.6
- fastq 1.20.1
- fdir 6.5.0
- file-entry-cache 8.0.0
- fill-range 7.1.1
- find-up 4.1.0
- find-up 5.0.0
- flat-cache 4.0.1
- flatted 3.4.2
- function-bind 1.1.2
- glob-parent 5.1.2
- glob-parent 6.0.2
- globby 11.1.0
- hard-rejection 2.1.0
- has-flag 4.0.0
- hasown 2.0.3
- hosted-git-info 2.8.9
- hosted-git-info 4.1.0
- ignore 5.3.2
- ignore 7.0.5
- imurmurhash 0.1.4
- indent-string 4.0.0
- irregular-plurals 3.5.0
- is-arrayish 0.2.1
- is-core-module 2.16.2
- is-extglob 2.1.1
- is-fullwidth-code-point 3.0.0
- is-glob 4.0.3
- is-number 7.0.0
- is-plain-obj 1.1.0
- is-unicode-supported 0.1.0
- isexe 2.0.0
- jest-diff 29.7.0
- jest-get-type 29.6.3
- js-tokens 4.0.0
- json-buffer 3.0.1
- json-parse-even-better-errors 2.3.1
- json-schema-traverse 0.4.1
- json-stable-stringify-without-jsonify 1.0.1
- keyv 4.5.4
- kind-of 6.0.3
- levn 0.4.1
- lines-and-columns 1.2.4
- locate-path 5.0.0
- locate-path 6.0.0
- log-symbols 4.1.0
- lru-cache 6.0.0
- map-obj 1.0.1
- map-obj 4.3.0
- meow 9.0.0
- merge2 1.4.1
- micromatch 4.0.8
- min-indent 1.0.1
- minimatch 10.2.5
- minimist-options 4.1.0
- ms 2.1.3
- natural-compare 1.4.0
- normalize-package-data 2.5.0
- normalize-package-data 3.0.3
- optionator 0.9.4
- p-limit 2.3.0
- p-limit 3.1.0
- p-locate 4.1.0
- p-locate 5.0.0
- p-try 2.2.0
- parse-json 5.2.0
- path-exists 4.0.0
- path-key 3.1.1
- path-parse 1.0.7
- path-type 4.0.0
- picocolors 1.1.1
- picomatch 2.3.2
- picomatch 4.0.4
- plur 4.0.0
- prelude-ls 1.2.1
- pretty-format 29.7.0
- punycode 2.3.1
- queue-microtask 1.2.3
- quick-lru 4.0.1
- react-is 18.3.1
- read-pkg 5.2.0
- read-pkg-up 7.0.1
- redent 3.0.0
- resolve 1.22.12
- reusify 1.1.0
- run-parallel 1.2.0
- semver 5.7.2
- semver 7.8.1
- shebang-command 2.0.0
- shebang-regex 3.0.0
- slash 3.0.0
- spdx-correct 3.2.0
- spdx-exceptions 2.5.0
- spdx-expression-parse 3.0.1
- spdx-license-ids 3.0.23
- string-width 4.2.3
- strip-ansi 6.0.1
- strip-indent 3.0.0
- supports-color 7.2.0
- supports-hyperlinks 2.3.0
- supports-preserve-symlinks-flag 1.0.0
- tinyglobby 0.2.16
- to-regex-range 5.0.1
- trim-newlines 3.0.1
- ts-api-utils 2.5.0
- type-check 0.4.0
- type-fest 0.18.1
- type-fest 0.21.3
- type-fest 0.6.0
- type-fest 0.8.1
- undici-types 6.21.0
- uri-js 4.4.1
- validate-npm-package-license 3.0.4
- which 2.0.2
- word-wrap 1.2.5
- yallist 4.0.0
- yargs-parser 20.2.9
- yocto-queue 0.1.0
Review auto-merge candidates and open PRs in a guided flow.
Glossary
What the labels and signals mean.
Glossary
What the labels and signals mean.
- Trust Save
- A package upgrade Arguss would have blocked despite the new version being available, because trust signals, like ownership transfer or a new maintainer, fired during the upgrade window. The name reflects what the agent did for the user: saved them from a potentially malicious update that a version-only auto-PR tool would have merged.
- AUTO-MERGE
- Verdict tier indicating the fix passes all three lenses cleanly. After you confirm action from a Scan assessment, Arguss opens a pull request for the upgrade; it does not merge PRs on GitHub. The envelope is conservative on purpose: patch or minor version bump, trust signals unchanged, blast radius bounded, real tests pass.
- REVIEW
- Verdict tier requiring a human decision. At least one veto fired during fix-confidence evaluation, trust signals shifted, the pipeline can't verify post-upgrade behavior, or the upgrade is a major version bump. The agent surfaces the reasons; the developer decides.
- DECLINE
- Verdict tier indicating no remediation is recommended. Typically applies when no fix version exists for the finding, or when multiple critical vetoes make even human review unproductive.
fix_kind.major- Veto signal that fires when the available fix requires a major version bump (1.x → 2.x). Major bumps imply potential breaking changes and fall outside the auto-merge envelope by default, even when the upgrade is the only available fix.
trust.new_maintainer- Veto signal that fires when a package added a new maintainer during the upgrade window, meaning between the user's current version and the proposed upgrade. New publishing identities are a well-documented attack vector for typosquats and supply chain takeovers.
trust.ownership_transferred- Veto signal that fires when a package's primary maintainer changed during the upgrade window. Combined with
trust.new_maintainer, this is the highest-risk trust combination, typical of the xz-utils style attacks and historical npm credential theft incidents. pipeline.test_reality- Veto signal that fires when Arguss can't verify tests will run on the upgraded code. Four conditions must hold: a test script exists in
package.json, it isn't a no-op, real test files exist, and a workflow actually invokes them. If any fail, the fix cannot qualify for AUTO_MERGE because there's no way to verify the upgrade didn't break the user's project. - CVSS
- Common Vulnerability Scoring System. A numeric score (0.0–10.0) representing how damaging a vulnerability could be if exploited. Sourced from NIST's National Vulnerability Database via OSV.dev. Severity, not urgency.
- EPSS
- Exploit Prediction Scoring System. A daily-updated probability (0.0–1.0, displayed as percent) that a CVE will be exploited in the next 30 days. Sourced from FIRST.org. Probability, not severity.
- KEV
- CISA's Known Exploited Vulnerabilities catalog. A federal list of CVEs with documented active exploitation in the wild. Federal agencies have a binding patching deadline; for everyone else, presence on KEV is the strongest "this is being used right now" signal available. Sourced directly from CISA.
- Project Risk Score (PRS)
- A weighted blend of the three lens subscores (40% vulnerability, 30% trust, 30% pipeline) producing an overall 0–100 indicator of the project's dependency health. Useful for at-a-glance triage; the per-finding fix-confidence verdicts are what drive automated decisions.
Dependency graph
Full-project map of transitive dependencies. Severity colors reflect vulnerabilities; trust rings apply only to direct dependencies analyzed by OpenSSF Scorecard (higher = riskier).