Findings
handlebars
@ 4.7.7
8 findings
critical–low
Trust 0/100
EPSS 1.8%
⚠ new maintainer
REVIEW
Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk.
Click for more →
Handlebars.js has JavaScript Injection in CLI Precompiler via Unescaped Names and Options
Handlebars.js has JavaScript Injection via AST Type Confusion by tampering @partial-block
Handlebars.js has JavaScript Injection via AST Type Confusion when passing an object as dynamic partial
Handlebars.js has Denial of Service via Malformed Decorator Syntax in Template Compilation
Handlebars.js has a Prototype Method Access Control Gap via Missing __lookupSetter__ Blocklist Entry
Handlebars.js has Prototype Pollution Leading to XSS through Partial Template Injection
Handlebars.js has a Property Access Validation Bypass in container.lookup
- trust veto: new maintainer added
Upgrade handlebars from 4.7.7 to 4.7.9 or later
View advisoryBlast radius
Paths from project root to handlebars - which dependencies pulled this package in?
diff
@ 7.0.0
1 finding
low
Trust 0/100
EPSS 0.6%
REVIEW
Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk.
Click for more →
jsdiff has a Denial of Service vulnerability in parsePatch and applyPatch
- major version bump requires human review (never auto-merge)
Upgrade diff from 7.0.0 to 8.0.3 or later
View advisoryBlast radius
Paths from project root to diff - which dependencies pulled this package in?
serialize-javascript
@ 6.0.2
2 findings
high–medium
Trust 0/100
EPSS 0.5%
REVIEW
Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk.
Click for more →
Serialize JavaScript is Vulnerable to RCE via RegExp.flags and Date.prototype.toISOString()
Serialize JavaScript has CPU Exhaustion Denial of Service via crafted array-like objects
- major version bump requires human review (never auto-merge)
Upgrade serialize-javascript from 6.0.2 to 7.0.3 or later
View advisoryBlast radius
Paths from project root to serialize-javascript - which dependencies pulled this package in?
uuid
@ 8.3.2
1 finding
high
Trust 0/100
EPSS 0.3%
REVIEW
Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk.
Click for more →
uuid: Missing buffer bounds check in v3/v5/v6 when buf is provided
- major version bump requires human review (never auto-merge)
Upgrade uuid from 8.3.2 to 11.1.1 or later
View advisoryBlast radius
Paths from project root to uuid - which dependencies pulled this package in?
Package status
371 packages scanned.
- 4 Review-required candidates Arguss flagged these for a human decision - nothing merges until you review them.
-
- accepts 2.0.0 direct
- after 0.8.2 direct
- body-parser 2.3.0 direct
- connect-redis 8.1.0 direct
- content-disposition 2.0.1 direct
- content-type 2.0.0 direct
- cookie 0.7.2 direct
- cookie-parser 1.4.7 direct
- cookie-session 2.1.1 direct
- cookie-signature 1.0.6 direct
- cookie-signature 1.0.7 direct
- cookie-signature 1.2.2 direct
- debug 2.6.9 direct
- debug 3.1.0 direct
- debug 3.2.7 direct
- debug 4.4.3 direct
- depd 2.0.0 direct
- ejs 3.1.10 direct
- encodeurl 2.0.0 direct
- escape-html 1.0.3 direct
- eslint 8.47.0 direct
- etag 1.8.1 direct
- express-session 1.19.0 direct
- finalhandler 2.1.1 direct
- fresh 2.0.0 direct
- hbs 4.2.0 direct
- http-errors 2.0.1 direct
- marked 15.0.12 direct
- merge-descriptors 2.0.0 direct
- method-override 3.0.0 direct
- mime-types 2.1.35 direct
- mime-types 3.0.2 direct
- mocha 11.7.6 direct
- morgan 1.11.0 direct
- nyc 17.1.0 direct
- on-finished 2.4.1 direct
- once 1.4.0 direct
- parseurl 1.3.3 direct
- pbkdf2-password 1.2.1 direct
- proxy-addr 2.0.7 direct
- qs 6.15.3 direct
- range-parser 1.3.0 direct
- router 2.2.0 direct
- send 1.2.1 direct
- serve-static 2.2.1 direct
- statuses 2.0.2 direct
- supertest 6.3.4 direct
- type-is 2.1.0 direct
- vary 1.1.2 direct
- vhost 3.0.2 direct
- @babel/code-frame 7.29.7
- @babel/compat-data 7.29.7
- @babel/core 7.29.7
- @babel/generator 7.29.7
- @babel/helper-compilation-targets 7.29.7
- @babel/helper-globals 7.29.7
- @babel/helper-module-imports 7.29.7
- @babel/helper-module-transforms 7.29.7
- @babel/helper-string-parser 7.29.7
- @babel/helper-validator-identifier 7.29.7
- @babel/helper-validator-option 7.29.7
- @babel/helpers 7.29.7
- @babel/parser 7.29.7
- @babel/template 7.29.7
- @babel/traverse 7.29.7
- @babel/types 7.29.7
- @eslint-community/eslint-utils 4.9.1
- @eslint-community/regexpp 4.12.2
- @eslint/eslintrc 2.1.4
- @eslint/js 8.57.1
- @humanwhocodes/config-array 0.11.14
- @humanwhocodes/module-importer 1.0.1
- @humanwhocodes/object-schema 2.0.3
- @isaacs/cliui 8.0.2
- @istanbuljs/load-nyc-config 1.1.0
- @istanbuljs/schema 0.1.6
- @jridgewell/gen-mapping 0.3.13
- @jridgewell/remapping 2.3.5
- @jridgewell/resolve-uri 3.1.2
- @jridgewell/sourcemap-codec 1.5.5
- @jridgewell/trace-mapping 0.3.31
- @noble/hashes 1.8.0
- @nodelib/fs.scandir 2.1.5
- @nodelib/fs.stat 2.0.5
- @nodelib/fs.walk 1.2.8
- @paralleldrive/cuid2 2.3.1
- @pkgjs/parseargs 0.11.0
- acorn 8.17.0
- acorn-jsx 5.3.2
- aggregate-error 3.1.0
- ajv 6.15.0
- ansi-regex 5.0.1
- ansi-regex 6.2.2
- ansi-styles 4.3.0
- ansi-styles 6.2.3
- append-transform 2.0.0
- archy 1.0.0
- argparse 1.0.10
- argparse 2.0.1
- asap 2.0.6
- async 3.2.6
- asynckit 0.4.0
- balanced-match 1.0.2
- baseline-browser-mapping 2.11.0
- basic-auth 2.0.1
- brace-expansion 1.1.16
- brace-expansion 2.1.2
- browser-stdout 1.3.1
- browserslist 4.28.6
- bytes 3.1.2
- caching-transform 4.0.0
- call-bind-apply-helpers 1.0.2
- call-bound 1.0.4
- callsites 3.1.0
- camelcase 5.3.1
- camelcase 6.3.0
- caniuse-lite 1.0.30001806
- chalk 4.1.2
- chokidar 4.0.3
- clean-stack 2.2.0
- cliui 6.0.0
- cliui 8.0.1
- color-convert 2.0.1
- color-name 1.1.4
- combined-stream 1.0.8
- commondir 1.0.1
- component-emitter 1.3.1
- concat-map 0.0.1
- convert-source-map 1.9.0
- convert-source-map 2.0.0
- cookiejar 2.1.4
- cookies 0.9.1
- cross-spawn 7.0.6
- decamelize 1.2.0
- decamelize 4.0.0
- deep-is 0.1.4
- default-require-extensions 3.0.1
- delayed-stream 1.0.0
- dezalgo 1.0.4
- doctrine 3.0.0
- dunder-proto 1.0.1
- eastasianwidth 0.2.0
- ee-first 1.1.1
- electron-to-chromium 1.5.394
- emoji-regex 8.0.0
- emoji-regex 9.2.2
- es-define-property 1.0.1
- es-errors 1.3.0
- es-object-atoms 1.1.2
- es-set-tostringtag 2.1.0
- es6-error 4.1.1
- escalade 3.2.0
- escape-string-regexp 4.0.0
- eslint-scope 7.2.2
- eslint-visitor-keys 3.4.3
- espree 9.6.1
- esprima 4.0.1
- esquery 1.7.0
- esrecurse 4.3.0
- estraverse 5.3.0
- esutils 2.0.3
- fast-deep-equal 3.1.3
- fast-json-stable-stringify 2.1.0
- fast-levenshtein 2.0.6
- fast-safe-stringify 2.1.1
- fastfall 1.5.1
- fastq 1.20.1
- file-entry-cache 6.0.1
- filelist 1.0.6
- find-cache-dir 3.3.2
- find-up 4.1.0
- find-up 5.0.0
- flat 5.0.2
- flat-cache 3.2.0
- flatted 3.4.2
- foreachasync 3.0.0
- foreground-child 2.0.0
- foreground-child 3.3.1
- form-data 4.0.6
- formidable 2.1.5
- forwarded 0.2.0
- fromentries 1.3.2
- fs.realpath 1.0.0
- function-bind 1.1.2
- gensync 1.0.0-beta.2
- get-caller-file 2.0.5
- get-intrinsic 1.3.0
- get-package-type 0.1.0
- get-proto 1.0.1
- glob 10.5.0
- glob 7.2.3
- glob-parent 6.0.2
- globals 13.24.0
- gopd 1.2.0
- graceful-fs 4.2.11
- graphemer 1.4.0
- has-flag 4.0.0
- has-symbols 1.1.0
- has-tostringtag 1.0.2
- hasha 5.2.2
- hasown 2.0.4
- he 1.2.0
- html-escaper 2.0.2
- iconv-lite 0.7.3
- ignore 5.3.2
- import-fresh 3.3.1
- imurmurhash 0.1.4
- indent-string 4.0.0
- inflight 1.0.6
- inherits 2.0.4
- ipaddr.js 1.9.1
- is-extglob 2.1.1
- is-fullwidth-code-point 3.0.0
- is-glob 4.0.3
- is-path-inside 3.0.3
- is-plain-obj 2.1.0
- is-promise 4.0.0
- is-stream 2.0.1
- is-typedarray 1.0.0
- is-unicode-supported 0.1.0
- is-windows 1.0.2
- isexe 2.0.0
- istanbul-lib-coverage 3.2.2
- istanbul-lib-hook 3.0.0
- istanbul-lib-instrument 6.0.3
- istanbul-lib-processinfo 2.0.3
- istanbul-lib-report 3.0.1
- istanbul-lib-source-maps 4.0.1
- istanbul-reports 3.2.0
- jackspeak 3.4.3
- jake 10.9.4
- js-tokens 4.0.0
- js-yaml 3.15.0
- js-yaml 4.3.0
- jsesc 3.1.0
- json-buffer 3.0.1
- json-schema-traverse 0.4.1
- json-stable-stringify-without-jsonify 1.0.1
- json5 2.2.3
- keygrip 1.1.0
- keyv 4.5.4
- levn 0.4.1
- locate-path 5.0.0
- locate-path 6.0.0
- lodash.flattendeep 4.4.0
- lodash.merge 4.6.2
- log-symbols 4.1.0
- lru-cache 10.4.3
- lru-cache 5.1.1
- make-dir 3.1.0
- make-dir 4.0.0
- math-intrinsics 1.1.0
- media-typer 1.1.0
- methods 1.1.2
- mime 2.6.0
- mime-db 1.52.0
- mime-db 1.54.0
- minimatch 3.1.5
- minimatch 5.1.9
- minimatch 9.0.9
- minimist 1.2.8
- minipass 7.1.3
- ms 2.0.0
- ms 2.1.3
- natural-compare 1.4.0
- negotiator 1.0.0
- neo-async 2.6.2
- node-preload 0.2.1
- node-releases 2.0.51
- object-inspect 1.13.4
- on-headers 1.1.0
- optionator 0.9.4
- p-limit 2.3.0
- p-limit 3.1.0
- p-locate 4.1.0
- p-locate 5.0.0
- p-map 3.0.0
- p-try 2.2.0
- package-hash 4.0.0
- package-json-from-dist 1.0.1
- parent-module 1.0.1
- path-exists 4.0.0
- path-is-absolute 1.0.1
- path-key 3.1.1
- path-scurry 1.11.1
- path-to-regexp 8.4.2
- picocolors 1.1.1
- pkg-dir 4.2.0
- prelude-ls 1.2.1
- process-on-spawn 1.1.0
- punycode 2.3.1
- queue-microtask 1.2.3
- random-bytes 1.0.0
- randombytes 2.1.0
- raw-body 3.0.2
- readdirp 4.1.2
- release-zalgo 1.0.0
- require-directory 2.1.1
- require-main-filename 2.0.0
- resolve-from 4.0.0
- resolve-from 5.0.0
- reusify 1.1.0
- rimraf 3.0.2
- run-parallel 1.2.0
- safe-buffer 5.1.2
- safe-buffer 5.2.1
- safer-buffer 2.1.2
- semver 6.3.1
- semver 7.8.5
- set-blocking 2.0.0
- setprototypeof 1.2.0
- shebang-command 2.0.0
- shebang-regex 3.0.0
- side-channel 1.1.1
- side-channel-list 1.0.1
- side-channel-map 1.0.1
- side-channel-weakmap 1.0.2
- signal-exit 3.0.7
- signal-exit 4.1.0
- source-map 0.6.1
- spawn-wrap 2.0.0
- sprintf-js 1.0.3
- string-width 4.2.3
- string-width 5.1.2
- string-width-cjs 4.2.3
- strip-ansi 6.0.1
- strip-ansi 7.2.0
- strip-ansi-cjs 6.0.1
- strip-bom 4.0.0
- strip-json-comments 3.1.1
- superagent 8.1.2
- supports-color 7.2.0
- supports-color 8.1.1
- test-exclude 6.0.0
- text-table 0.2.0
- toidentifier 1.0.1
- tsscmp 1.0.6
- type-check 0.4.0
- type-fest 0.20.2
- type-fest 0.8.1
- typedarray-to-buffer 3.1.5
- uglify-js 3.19.3
- uid-safe 2.1.5
- unpipe 1.0.0
- update-browserslist-db 1.2.3
- uri-js 4.4.1
- walk 2.3.15
- which 2.0.2
- which-module 2.0.1
- word-wrap 1.2.5
- wordwrap 1.0.0
- workerpool 9.3.4
- wrap-ansi 6.2.0
- wrap-ansi 7.0.0
- wrap-ansi 8.1.0
- wrap-ansi-cjs 7.0.0
- wrappy 1.0.2
- write-file-atomic 3.0.3
- y18n 4.0.3
- y18n 5.0.8
- yallist 3.1.1
- yargs 15.4.1
- yargs 17.7.3
- yargs-parser 18.1.3
- yargs-parser 21.1.1
- yargs-unparser 2.0.0
- yocto-queue 0.1.0
Review auto-merge candidates and open PRs in a guided flow.
Glossary
What the labels and signals mean.
Glossary
What the labels and signals mean.
- Trust Save
- A package upgrade Arguss would have blocked despite the new version being available, because trust signals, like ownership transfer or a new maintainer, fired during the upgrade window. The name reflects what the agent did for the user: saved them from a potentially malicious update that a version-only auto-PR tool would have merged.
- AUTO-MERGE
- Verdict tier indicating the fix passes all three lenses cleanly. After you confirm action from a Scan assessment, Arguss opens a pull request for the upgrade; it does not merge PRs on GitHub. The envelope is conservative on purpose: patch or minor version bump, trust signals unchanged, blast radius bounded, real tests pass.
- REVIEW
- Verdict tier requiring a human decision. At least one veto fired during fix-confidence evaluation, trust signals shifted, the pipeline can't verify post-upgrade behavior, or the upgrade is a major version bump. The agent surfaces the reasons; the developer decides.
- DECLINE
- Verdict tier indicating no remediation is recommended. Typically applies when no fix version exists for the finding, or when multiple critical vetoes make even human review unproductive.
fix_kind.major- Veto signal that fires when the available fix requires a major version bump (1.x → 2.x). Major bumps imply potential breaking changes and fall outside the auto-merge envelope by default, even when the upgrade is the only available fix.
trust.new_maintainer- Veto signal that fires when a package added a new maintainer during the upgrade window, meaning between the user's current version and the proposed upgrade. New publishing identities are a well-documented attack vector for typosquats and supply chain takeovers.
trust.ownership_transferred- Veto signal that fires when a package's primary maintainer changed during the upgrade window. Combined with
trust.new_maintainer, this is the highest-risk trust combination, typical of the xz-utils style attacks and historical npm credential theft incidents. pipeline.test_reality- Veto signal that fires when Arguss can't verify tests will run on the upgraded code. Four conditions must hold: a test script exists in
package.json, it isn't a no-op, real test files exist, and a workflow actually invokes them. If any fail, the fix cannot qualify for AUTO_MERGE because there's no way to verify the upgrade didn't break the user's project. - CVSS
- Common Vulnerability Scoring System. A numeric score (0.0–10.0) representing how damaging a vulnerability could be if exploited. Sourced from NIST's National Vulnerability Database via OSV.dev. Severity, not urgency.
- EPSS
- Exploit Prediction Scoring System. A daily-updated probability (0.0–1.0, displayed as percent) that a CVE will be exploited in the next 30 days. Sourced from FIRST.org. Probability, not severity.
- KEV
- CISA's Known Exploited Vulnerabilities catalog. A federal list of CVEs with documented active exploitation in the wild. Federal agencies have a binding patching deadline; for everyone else, presence on KEV is the strongest "this is being used right now" signal available. Sourced directly from CISA.
- Project Risk Score (PRS)
- A weighted blend of the three lens subscores (40% vulnerability, 30% trust, 30% pipeline) producing an overall 0–100 indicator of the project's dependency health. Useful for at-a-glance triage; the per-finding fix-confidence verdicts are what drive automated decisions.
Dependency graph
Full-project map of transitive dependencies. Severity colors reflect vulnerabilities; trust rings apply only to direct dependencies analyzed by OpenSSF Scorecard (higher = riskier).