Project Risk Score Project Risk Score: weighted blend of vulnerability (40%), trust (30%), and pipeline (30%) subscores. Useful for at-a-glance triage. Click for more →
79 /100
Critical

231 findings across 47 packages · 538 packages clean

Candidates: 0 auto-merge · 60 review · 0 decline · 8 no fix

Scanned lodash/lodash @ main Scan · Completed 215 hrs ago Download SBOM
Total Findings
231
All detected issues
KEV Findings
1
Known exploited
High EPSS
37
Likely to be exploited
Auto-merge ready
0
Remediation candidates
Affected pkgs
47
with remediation paths
KEV catalog CISA's Known Exploited Vulnerabilities catalog. Documented active exploitation in the wild; the strongest 'this is happening now' signal. Click for more →
1
actively exploited CVEs
Highest EPSS Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
99.0%
CVE-2020-11022
Active vetos
128
lens blocks on candidates

Findings

jquery @ 3.4.1
root → jquery
2 findings medium
Trust 15/100 EPSS 99.0% ↑
REVIEW Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more →
3.4.1 → 3.5.0 minor
review-required Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more → Score 75
Max CVSS 6.9 · 2 findings Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → CISA KEV CISA's Known Exploited Vulnerabilities catalog. Documented active exploitation in the wild; the strongest 'this is happening now' signal. Click for more → Max EPSS 99.0% · 99th percentile Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
pipeline.test_reality Veto: Arguss can't verify tests will run on upgraded code. Needs a test script in package.json, real test files, and a workflow that runs them. Click for more →
  • CI workflow doesn't run tests reliably; can't verify upgrade safety.
GHSA-gxr4-xjj5-5px2: Potential XSS vulnerability in jQuery

Upgrade jquery from 3.4.1 to 3.5.0 or later

View advisory
root → jquery

Blast radius

Paths from project root to jquery - which dependencies pulled this package in?

y18n @ 3.2.1
root → optional-dev-dependency → yargs → y18n
1 finding high
Trust 0/100 EPSS 69.1% ↑ ⚠ new maintainer
REVIEW Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more →
3.2.1 → 3.2.2 patch
review-required Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more → Score 60
Max CVSS 7.3 · 1 finding Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → Max EPSS 69.1% · 99th percentile Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
pipeline.test_reality Veto: Arguss can't verify tests will run on upgraded code. Needs a test script in package.json, real test files, and a workflow that runs them. Click for more → trust.new_maintainer Veto: a new publishing identity was added between your current version and the upgrade target. A well-documented supply chain attack vector. Click for more →
  • CI workflow doesn't run tests reliably; can't verify upgrade safety.
  • trust veto: new maintainer added
GHSA-c4w7-xm78-47vh: Prototype Pollution in y18n

Upgrade y18n from 3.2.1 to 3.2.2 or later

View advisory
root → optional-dev-dependency → yargs → y18n

Blast radius

Paths from project root to y18n - which dependencies pulled this package in?

dojo @ 1.15.0
root → dojo
2 findings high
Trust 0/100 EPSS 30.4% ↑
REVIEW Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more →
Prototype Pollution in dojo

No fixed version published in OSV

GHSA-m8gw-hjpr-rjv7
1.15.0 → 1.15.3 patch
review-required Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more → Score 75
Max CVSS 7.8 · 1 finding Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → Max EPSS 4.0% · 89th percentile Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
pipeline.test_reality Veto: Arguss can't verify tests will run on upgraded code. Needs a test script in package.json, real test files, and a workflow that runs them. Click for more →
  • CI workflow doesn't run tests reliably; can't verify upgrade safety.
GHSA-jxfh-8wgv-vfr2: Prototype pollution in dojo

Upgrade dojo from 1.15.0 to 1.15.3 or later

View advisory
root → dojo

Blast radius

Paths from project root to dojo - which dependencies pulled this package in?

lodash @ 3.10.1 An upgrade Arguss blocked despite the newer version being available, because trust signals like ownership transfer or new maintainer fired during the upgrade window. Click for more →
root → jscs → jscs-jsdoc → jsdoctypeparser → lodash
95 findings critical–medium
Trust 0/100 EPSS 22.4% ↑ ⚠ ownership transferred
REVIEW Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more →
GHSA-jf85-cpcp-j695 critical CVSS 9.1 EPSS 5.0%
Prototype Pollution in lodash

Affects 3 install paths

GHSA-r5fr-rjxr-66jc high CVSS 8.1 EPSS 22.4%
lodash vulnerable to Code Injection via `_.template` imports key names

Affects 13 install paths

GHSA-4xc9-xhrj-v574 high CVSS 7.5 EPSS 1.6%
Prototype Pollution in lodash

Affects 3 install paths

GHSA-p6mc-m468-83gw high CVSS 7.4 EPSS 5.2%
Prototype Pollution in lodash

Affects 15 install paths

GHSA-35jh-r3h4-6jhm high CVSS 7.2 EPSS 22.4%
Command Injection in lodash

Affects 16 install paths

GHSA-f23m-r3pf-42rh medium CVSS 6.5 EPSS 1.5%
lodash vulnerable to Prototype Pollution via array path bypass in `_.unset` and `_.omit`

Affects 16 install paths

GHSA-fvqr-27wr-82fm medium CVSS 6.5 EPSS 2.4%
Prototype Pollution in lodash

Affects 3 install paths

GHSA-xxjr-mmjv-4gpg medium CVSS 6.5 EPSS 1.5%
Lodash has Prototype Pollution Vulnerability in `_.unset` and `_.omit` functions

Affects 13 install paths

GHSA-29mw-wpgm-hmr9 medium CVSS 5.3 EPSS 7.3%
Regular Expression Denial of Service (ReDoS) in lodash

Affects 13 install paths

3.10.1 → 4.18.0 major
review-required Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more → Score 1
Max CVSS 9.1 · 18 findings Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → Max EPSS 22.4% · 97th percentile Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
fix_kind.major Veto: the available fix requires a major version bump (1.x → 2.x), which implies potential breaking changes outside the auto-merge envelope. Click for more → pipeline.test_reality Veto: Arguss can't verify tests will run on upgraded code. Needs a test script in package.json, real test files, and a workflow that runs them. Click for more → trust.new_maintainer Veto: a new publishing identity was added between your current version and the upgrade target. A well-documented supply chain attack vector. Click for more → trust.ownership_transferred Veto: the package's primary maintainer changed during the upgrade window. Combined with new-maintainer, this is the highest-risk trust combination. Click for more →
  • major version bump requires human review (never auto-merge)
  • CI workflow doesn't run tests reliably; can't verify upgrade safety.
  • trust veto: new maintainer added
  • trust veto: package ownership transferred between versions
GHSA-jf85-cpcp-j695: Prototype Pollution in lodash

Upgrade lodash from 3.10.1 to 4.17.12 or later

View advisory
root → jscs → jscs-jsdoc → jsdoctypeparser → lodash
4.17.14 → 4.18.0 minor
review-required Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more → Score 60
Max CVSS 8.1 · 72 findings Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → Max EPSS 22.4% · 97th percentile Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
pipeline.test_reality Veto: Arguss can't verify tests will run on upgraded code. Needs a test script in package.json, real test files, and a workflow that runs them. Click for more → trust.new_maintainer Veto: a new publishing identity was added between your current version and the upgrade target. A well-documented supply chain attack vector. Click for more →
  • CI workflow doesn't run tests reliably; can't verify upgrade safety.
  • trust veto: new maintainer added
GHSA-r5fr-rjxr-66jc: lodash vulnerable to Code Injection via `_.template` imports key names

Upgrade lodash from 4.17.14 to 4.18.0 or later

View advisory
root → docdown → lodash
4.17.20 → 4.18.0 minor
review-required Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more → Score 75
Max CVSS 8.1 · 5 findings Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → Max EPSS 22.4% · 97th percentile Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
pipeline.test_reality Veto: Arguss can't verify tests will run on upgraded code. Needs a test script in package.json, real test files, and a workflow that runs them. Click for more →
  • CI workflow doesn't run tests reliably; can't verify upgrade safety.
GHSA-r5fr-rjxr-66jc: lodash vulnerable to Code Injection via `_.template` imports key names

Upgrade lodash from 4.17.20 to 4.18.0 or later

View advisory
root → lodash-doc-globals → lodash

Blast radius

Paths from project root to lodash - which dependencies pulled this package in?

tar @ 4.4.10 An upgrade Arguss blocked despite the newer version being available, because trust signals like ownership transfer or new maintainer fired during the upgrade window. Click for more →
root → node-pre-gyp → tar
17 findings high–medium
Trust 0/100 EPSS 15.0% ↑ ⚠ ownership transferred
REVIEW Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more →
GHSA-r6q2-hw4h-h46w high CVSS 8.8 EPSS 0.2%
Race Condition in node-tar Path Reservations via Unicode Ligature Collisions on macOS APFS
GHSA-3jfq-g458-7qm9 high CVSS 8.3 EPSS 15.0%
Arbitrary File Creation/Overwrite due to insufficient absolute path sanitization
GHSA-5955-9wpr-37jh high CVSS 8.3 EPSS 1.3%
Arbitrary File Creation/Overwrite on Windows via insufficient relative path sanitization
GHSA-9r2w-394v-53qc high CVSS 8.3 EPSS 3.3%
Arbitrary File Creation/Overwrite via insufficient symlink protection due to directory cache poisoning using symbolic links
GHSA-qq89-hq3f-393p high CVSS 8.3 EPSS 1.8%
Arbitrary File Creation/Overwrite via insufficient symlink protection due to directory cache poisoning using symbolic links
GHSA-r628-mhmh-qjhw high CVSS 8.3 EPSS 7.8%
Arbitrary File Creation/Overwrite via insufficient symlink protection due to directory cache poisoning
GHSA-34x7-hfp2-rc4v high CVSS 8.2 EPSS 0.5%
node-tar Vulnerable to Arbitrary File Creation/Overwrite via Hardlink Path Traversal
GHSA-23hp-3jrh-7fpw high CVSS 7.5 EPSS 0.4%
node-tar: Decompression/parse DoS via unlimited input
GHSA-8qq5-rm4j-mr97 high CVSS 7.5 EPSS 0.3%
node-tar is Vulnerable to Arbitrary File Overwrite and Symlink Poisoning via Insufficient Path Sanitization
GHSA-8x88-c5mf-7j5w high CVSS 7.5 EPSS 0.4%
node-tar: Negative tar entry size causes infinite loop in archive replace
GHSA-9ppj-qmqm-q256 high CVSS 7.5 EPSS 0.3%
node-tar Symlink Path Traversal via Drive-Relative Linkpath
GHSA-qffp-2rhf-9h96 high CVSS 7.5 EPSS 0.4%
tar has Hardlink Path Traversal via Drive-Relative Linkpath
GHSA-83g3-92jg-28cx high CVSS 7.1 EPSS 0.3%
Arbitrary File Read/Write via Hardlink Target Escape Through Symlink Chain in node-tar Extraction
GHSA-f5x3-32g6-xq36 medium CVSS 6.5 EPSS 0.9%
Denial of service while parsing a tar file due to lack of folders count validation
GHSA-gvwx-54wh-qm9j medium CVSS 5.3 EPSS 0.3%
node-tar: Uncaught Exception DoS via NUL byte in PAX path/linkpath records
GHSA-w8wr-v893-vjvp medium CVSS 5.3 EPSS 0.4%
node-tar: Process crash via PAX numeric path type confusion
GHSA-vmf3-w455-68vh medium CVSS 5.0 EPSS 0.1%
node-tar applies PAX size override to intermediary GNU long-name/long-link headers, causing tar parser interpretation differential (file smuggling)
4.4.10 → 7.5.19 major
review-required Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more → Score 10
Max CVSS 8.8 · 17 findings Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → Max EPSS 15.0% · 96th percentile Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
fix_kind.major Veto: the available fix requires a major version bump (1.x → 2.x), which implies potential breaking changes outside the auto-merge envelope. Click for more → pipeline.test_reality Veto: Arguss can't verify tests will run on upgraded code. Needs a test script in package.json, real test files, and a workflow that runs them. Click for more → trust.ownership_transferred Veto: the package's primary maintainer changed during the upgrade window. Combined with new-maintainer, this is the highest-risk trust combination. Click for more →
  • major version bump requires human review (never auto-merge)
  • CI workflow doesn't run tests reliably; can't verify upgrade safety.
  • trust veto: package ownership transferred between versions
GHSA-r6q2-hw4h-h46w: Race Condition in node-tar Path Reservations via Unicode Ligature Collisions on macOS APFS

Upgrade tar from 4.4.10 to 7.5.4 or later

View advisory
root → node-pre-gyp → tar

Blast radius

Paths from project root to tar - which dependencies pulled this package in?

qs @ 1.2.2
root → request → qs
7 findings high–low
Trust 0/100 EPSS 14.7% ↑ ⚠ new maintainer
REVIEW Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more →
GHSA-hrpp-h998-j3pp high CVSS 7.5 EPSS 14.7%
qs vulnerable to Prototype Pollution

Affects 3 install paths

GHSA-6rw7-vpxm-498p low CVSS 3.7 EPSS 0.4%
qs's arrayLimit bypass in its bracket notation allows DoS via memory exhaustion

Affects 3 install paths

1.2.2 → 6.14.1 major
review-required Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more → Score 10
Max CVSS 7.5 · 3 findings Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → Max EPSS 14.7% · 96th percentile Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
fix_kind.major Veto: the available fix requires a major version bump (1.x → 2.x), which implies potential breaking changes outside the auto-merge envelope. Click for more → pipeline.test_reality Veto: Arguss can't verify tests will run on upgraded code. Needs a test script in package.json, real test files, and a workflow that runs them. Click for more → trust.new_maintainer Veto: a new publishing identity was added between your current version and the upgrade target. A well-documented supply chain attack vector. Click for more →
  • major version bump requires human review (never auto-merge)
  • CI workflow doesn't run tests reliably; can't verify upgrade safety.
  • trust veto: new maintainer added
GHSA-gqgv-6jq5-jjj9: Prototype Pollution Protection Bypass in qs

Upgrade qs from 1.2.2 to 6.0.4 or later

View advisory
root → request → qs
6.3.2 → 6.14.1 minor
review-required Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more → Score 75
Max CVSS 7.5 · 2 findings Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → Max EPSS 14.7% · 96th percentile Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
pipeline.test_reality Veto: Arguss can't verify tests will run on upgraded code. Needs a test script in package.json, real test files, and a workflow that runs them. Click for more →
  • CI workflow doesn't run tests reliably; can't verify upgrade safety.
GHSA-hrpp-h998-j3pp: qs vulnerable to Prototype Pollution

Upgrade qs from 6.3.2 to 6.3.3 or later

View advisory
root → request → qs
6.5.2 → 6.14.1 minor
review-required Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more → Score 75
Max CVSS 7.5 · 2 findings Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → Max EPSS 14.7% · 96th percentile Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
pipeline.test_reality Veto: Arguss can't verify tests will run on upgraded code. Needs a test script in package.json, real test files, and a workflow that runs them. Click for more →
  • CI workflow doesn't run tests reliably; can't verify upgrade safety.
GHSA-hrpp-h998-j3pp: qs vulnerable to Prototype Pollution

Upgrade qs from 6.5.2 to 6.5.3 or later

View advisory
root → request → qs

Blast radius

Paths from project root to qs - which dependencies pulled this package in?

json5 @ 0.5.1
root → markdown-doctest → babel-core → json5
1 finding high
Trust 0/100 EPSS 9.3%
REVIEW Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more →
0.5.1 → 1.0.2 major
review-required Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more → Score 25
Max CVSS 7.1 · 1 finding Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → Max EPSS 9.3% · 94th percentile Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
fix_kind.major Veto: the available fix requires a major version bump (1.x → 2.x), which implies potential breaking changes outside the auto-merge envelope. Click for more → pipeline.test_reality Veto: Arguss can't verify tests will run on upgraded code. Needs a test script in package.json, real test files, and a workflow that runs them. Click for more →
  • major version bump requires human review (never auto-merge)
  • CI workflow doesn't run tests reliably; can't verify upgrade safety.
GHSA-9c47-m6qq-7p4h: Prototype Pollution in JSON5 via Parse Method

Upgrade json5 from 0.5.1 to 1.0.2 or later

View advisory
root → markdown-doctest → babel-core → json5

Blast radius

Paths from project root to json5 - which dependencies pulled this package in?

handlebars @ 4.1.2
root → istanbul → handlebars
16 findings critical–low
Trust 0/100 EPSS 7.1% ⚠ new maintainer
REVIEW Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more →
GHSA-2w6w-674q-4c4q critical CVSS 9.8 EPSS 1.8%
Handlebars.js has JavaScript Injection via AST Type Confusion
GHSA-f2jv-r9rf-7988 critical CVSS 9.8 EPSS 7.0%
Remote code execution in handlebars when compiling templates
GHSA-xjpj-3mr7-gcpf high CVSS 8.8 EPSS 0.3%
Handlebars.js has JavaScript Injection in CLI Precompiler via Unescaped Names and Options
GHSA-3mfm-83xf-c92r high CVSS 8.1 EPSS 0.7%
Handlebars.js has JavaScript Injection via AST Type Confusion by tampering @partial-block
GHSA-xhpv-hc6g-r9c6 high CVSS 8.1 EPSS 0.7%
Handlebars.js has JavaScript Injection via AST Type Confusion when passing an object as dynamic partial
GHSA-62gr-4qp9-h98f high CVSS 7.5 EPSS 3.8%
Regular Expression Denial of Service in Handlebars
GHSA-9cx6-37pm-9jff high CVSS 7.5 EPSS 0.6%
Handlebars.js has Denial of Service via Malformed Decorator Syntax in Template Compilation
GHSA-2qvq-rjwj-gvw9 medium CVSS 4.7 EPSS 0.3%
Handlebars.js has Prototype Pollution Leading to XSS through Partial Template Injection
GHSA-442j-39wm-28r2 low CVSS 3.7 EPSS n/a
Handlebars.js has a Property Access Validation Bypass in container.lookup
4.1.2 → 4.7.9 minor
review-required Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more → Score 60
Max CVSS 9.8 · 16 findings Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → Max EPSS 7.1% · 93rd percentile Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
pipeline.test_reality Veto: Arguss can't verify tests will run on upgraded code. Needs a test script in package.json, real test files, and a workflow that runs them. Click for more → trust.new_maintainer Veto: a new publishing identity was added between your current version and the upgrade target. A well-documented supply chain attack vector. Click for more →
  • CI workflow doesn't run tests reliably; can't verify upgrade safety.
  • trust veto: new maintainer added
GHSA-2w6w-674q-4c4q: Handlebars.js has JavaScript Injection via AST Type Confusion

Upgrade handlebars from 4.1.2 to 4.7.9 or later

View advisory
root → istanbul → handlebars

Blast radius

Paths from project root to handlebars - which dependencies pulled this package in?

minimist @ 0.0.10 An upgrade Arguss blocked despite the newer version being available, because trust signals like ownership transfer or new maintainer fired during the upgrade window. Click for more →
root → webpack → optimist → minimist
8 findings critical–medium
Trust 30/100 EPSS 4.6% ⚠ ownership transferred
REVIEW Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more →
GHSA-xvch-5gv4-984h critical CVSS 9.8 EPSS 4.6%
Prototype Pollution in minimist

Affects 4 install paths

GHSA-vh95-rmgr-6w4m medium CVSS 5.6 EPSS 1.9%
Prototype Pollution in minimist

Affects 4 install paths

0.0.10 → 0.2.4 minor
review-required Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more → Score 45
Max CVSS 9.8 · 2 findings Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → Max EPSS 4.6% · 90th percentile Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
pipeline.test_reality Veto: Arguss can't verify tests will run on upgraded code. Needs a test script in package.json, real test files, and a workflow that runs them. Click for more → trust.new_maintainer Veto: a new publishing identity was added between your current version and the upgrade target. A well-documented supply chain attack vector. Click for more → trust.ownership_transferred Veto: the package's primary maintainer changed during the upgrade window. Combined with new-maintainer, this is the highest-risk trust combination. Click for more →
  • CI workflow doesn't run tests reliably; can't verify upgrade safety.
  • trust veto: new maintainer added
  • trust veto: package ownership transferred between versions
GHSA-xvch-5gv4-984h: Prototype Pollution in minimist

Upgrade minimist from 0.0.10 to 0.2.4 or later

View advisory
root → webpack → optimist → minimist
0.0.8 → 0.2.4 minor
review-required Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more → Score 45
Max CVSS 9.8 · 4 findings Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → Max EPSS 4.6% · 90th percentile Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
pipeline.test_reality Veto: Arguss can't verify tests will run on upgraded code. Needs a test script in package.json, real test files, and a workflow that runs them. Click for more → trust.new_maintainer Veto: a new publishing identity was added between your current version and the upgrade target. A well-documented supply chain attack vector. Click for more → trust.ownership_transferred Veto: the package's primary maintainer changed during the upgrade window. Combined with new-maintainer, this is the highest-risk trust combination. Click for more →
  • CI workflow doesn't run tests reliably; can't verify upgrade safety.
  • trust veto: new maintainer added
  • trust veto: package ownership transferred between versions
GHSA-xvch-5gv4-984h: Prototype Pollution in minimist

Upgrade minimist from 0.0.8 to 0.2.4 or later

View advisory
root → istanbul → mkdirp → minimist
1.2.0 → 1.2.6 patch
review-required Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more → Score 60
Max CVSS 9.8 · 2 findings Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → Max EPSS 4.6% · 90th percentile Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
pipeline.test_reality Veto: Arguss can't verify tests will run on upgraded code. Needs a test script in package.json, real test files, and a workflow that runs them. Click for more → trust.new_maintainer Veto: a new publishing identity was added between your current version and the upgrade target. A well-documented supply chain attack vector. Click for more →
  • CI workflow doesn't run tests reliably; can't verify upgrade safety.
  • trust veto: new maintainer added
GHSA-xvch-5gv4-984h: Prototype Pollution in minimist

Upgrade minimist from 1.2.0 to 1.2.6 or later

View advisory
root → coveralls → minimist

Blast radius

Paths from project root to minimist - which dependencies pulled this package in?

hoek @ 0.9.1
root → request → hawk → boom → hoek
4 findings high
Trust 0/100 EPSS 4.3% ⚠ new maintainer
REVIEW Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more →
GHSA-jp4x-w63m-7wgm high CVSS 8.8 EPSS 4.3%
Prototype Pollution in hoek

Affects 2 install paths

hoek subject to prototype pollution via the clone function.

No fixed version published in OSV

GHSA-c429-5p7v-vgjp
0.9.1 → 4.2.1 major
review-required Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more → Score 10
Max CVSS 8.8 · 1 finding Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → Max EPSS 4.3% · 90th percentile Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
fix_kind.major Veto: the available fix requires a major version bump (1.x → 2.x), which implies potential breaking changes outside the auto-merge envelope. Click for more → pipeline.test_reality Veto: Arguss can't verify tests will run on upgraded code. Needs a test script in package.json, real test files, and a workflow that runs them. Click for more → trust.new_maintainer Veto: a new publishing identity was added between your current version and the upgrade target. A well-documented supply chain attack vector. Click for more →
  • major version bump requires human review (never auto-merge)
  • CI workflow doesn't run tests reliably; can't verify upgrade safety.
  • trust veto: new maintainer added
GHSA-jp4x-w63m-7wgm: Prototype Pollution in hoek

Upgrade hoek from 0.9.1 to 4.2.1 or later

View advisory
root → request → hawk → boom → hoek
2.16.3 → 4.2.1 major
review-required Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more → Score 10
Max CVSS 8.8 · 1 finding Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → Max EPSS 4.3% · 90th percentile Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
fix_kind.major Veto: the available fix requires a major version bump (1.x → 2.x), which implies potential breaking changes outside the auto-merge envelope. Click for more → pipeline.test_reality Veto: Arguss can't verify tests will run on upgraded code. Needs a test script in package.json, real test files, and a workflow that runs them. Click for more → trust.new_maintainer Veto: a new publishing identity was added between your current version and the upgrade target. A well-documented supply chain attack vector. Click for more →
  • major version bump requires human review (never auto-merge)
  • CI workflow doesn't run tests reliably; can't verify upgrade safety.
  • trust veto: new maintainer added
GHSA-jp4x-w63m-7wgm: Prototype Pollution in hoek

Upgrade hoek from 2.16.3 to 4.2.1 or later

View advisory
root → request → hawk → boom → hoek

Blast radius

Paths from project root to hoek - which dependencies pulled this package in?

underscore @ 1.6.0
root → jscs → jsonlint → nomnom → underscore
2 findings critical–medium
Trust 30/100 EPSS 4.1% ⚠ new maintainer
REVIEW Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more →
GHSA-qpx9-hpmf-5gmw medium CVSS 5.9 EPSS 0.6%
Underscore has unlimited recursion in _.flatten and _.isEqual, potential for DoS attack
1.6.0 → 1.13.8 minor
review-required Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more → Score 60
Max CVSS 9.8 · 2 findings Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → Max EPSS 4.1% · 89th percentile Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
pipeline.test_reality Veto: Arguss can't verify tests will run on upgraded code. Needs a test script in package.json, real test files, and a workflow that runs them. Click for more → trust.new_maintainer Veto: a new publishing identity was added between your current version and the upgrade target. A well-documented supply chain attack vector. Click for more →
  • CI workflow doesn't run tests reliably; can't verify upgrade safety.
  • trust veto: new maintainer added
GHSA-cf4h-3jhx-xvhq: Arbitrary Code Execution in underscore

Upgrade underscore from 1.6.0 to 1.12.1 or later

View advisory
root → jscs → jsonlint → nomnom → underscore

Blast radius

Paths from project root to underscore - which dependencies pulled this package in?

hosted-git-info @ 2.6.0 An upgrade Arguss blocked despite the newer version being available, because trust signals like ownership transfer or new maintainer fired during the upgrade window. Click for more →
root → optional-dev-dependency → yargs → read-pkg-up → read-pkg → normalize-package-data → hosted-git-info
1 finding medium
Trust 0/100 EPSS 3.6% ⚠ ownership transferred
REVIEW Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more →
GHSA-43f8-2h32-f4cj medium CVSS 5.3 EPSS 3.6%
Regular Expression Denial of Service in hosted-git-info
2.6.0 → 2.8.9 minor
review-required Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more → Score 45
Max CVSS 5.3 · 1 finding Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → Max EPSS 3.6% · 88th percentile Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
pipeline.test_reality Veto: Arguss can't verify tests will run on upgraded code. Needs a test script in package.json, real test files, and a workflow that runs them. Click for more → trust.new_maintainer Veto: a new publishing identity was added between your current version and the upgrade target. A well-documented supply chain attack vector. Click for more → trust.ownership_transferred Veto: the package's primary maintainer changed during the upgrade window. Combined with new-maintainer, this is the highest-risk trust combination. Click for more →
  • CI workflow doesn't run tests reliably; can't verify upgrade safety.
  • trust veto: new maintainer added
  • trust veto: package ownership transferred between versions
GHSA-43f8-2h32-f4cj: Regular Expression Denial of Service in hosted-git-info

Upgrade hosted-git-info from 2.6.0 to 2.8.9 or later

View advisory
root → optional-dev-dependency → yargs → read-pkg-up → read-pkg → normalize-package-data → hosted-git-info

Blast radius

Paths from project root to hosted-git-info - which dependencies pulled this package in?

ini @ 1.3.5
root → qunitjs → findup-sync → resolve-dir → global-modules → global-prefix → ini
1 finding high
Trust 30/100 EPSS 3.6%
REVIEW Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more →
GHSA-qqgx-2p2h-9c37 high CVSS 7.3 EPSS 3.6%
ini before 1.3.6 vulnerable to Prototype Pollution via ini.parse
1.3.5 → 1.3.6 patch
review-required Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more → Score 75
Max CVSS 7.3 · 1 finding Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → Max EPSS 3.6% · 88th percentile Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
pipeline.test_reality Veto: Arguss can't verify tests will run on upgraded code. Needs a test script in package.json, real test files, and a workflow that runs them. Click for more →
  • CI workflow doesn't run tests reliably; can't verify upgrade safety.
GHSA-qqgx-2p2h-9c37: ini before 1.3.6 vulnerable to Prototype Pollution via ini.parse

Upgrade ini from 1.3.5 to 1.3.6 or later

View advisory
root → qunitjs → findup-sync → resolve-dir → global-modules → global-prefix → ini

Blast radius

Paths from project root to ini - which dependencies pulled this package in?

json-schema @ 0.2.3
root → request → http-signature → jsprim → json-schema
1 finding critical
Trust 30/100 EPSS 3.6%
REVIEW Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more →
GHSA-896r-f27r-55mw critical CVSS 9.8 EPSS 3.6%
json-schema is vulnerable to Prototype Pollution
0.2.3 → 0.4.0 minor
review-required Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more → Score 75
Max CVSS 9.8 · 1 finding Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → Max EPSS 3.6% · 88th percentile Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
pipeline.test_reality Veto: Arguss can't verify tests will run on upgraded code. Needs a test script in package.json, real test files, and a workflow that runs them. Click for more →
  • CI workflow doesn't run tests reliably; can't verify upgrade safety.
GHSA-896r-f27r-55mw: json-schema is vulnerable to Prototype Pollution

Upgrade json-schema from 0.2.3 to 0.4.0 or later

View advisory
root → request → http-signature → jsprim → json-schema

Blast radius

Paths from project root to json-schema - which dependencies pulled this package in?

hawk @ 1.1.1
root → hawk
3 findings high
Trust 45/100 EPSS 3.4% ⚠ new maintainer
REVIEW Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more →
GHSA-44pw-h2cw-w3vq high CVSS 7.4 EPSS 1.0%
Uncontrolled Resource Consumption in Hawk

Affects 2 install paths

1.1.1 → 9.0.1 major
review-required Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more → Score 10
Max CVSS 7.5 · 2 findings Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → Max EPSS 3.4% · 87th percentile Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
fix_kind.major Veto: the available fix requires a major version bump (1.x → 2.x), which implies potential breaking changes outside the auto-merge envelope. Click for more → pipeline.test_reality Veto: Arguss can't verify tests will run on upgraded code. Needs a test script in package.json, real test files, and a workflow that runs them. Click for more → trust.new_maintainer Veto: a new publishing identity was added between your current version and the upgrade target. A well-documented supply chain attack vector. Click for more →
  • major version bump requires human review (never auto-merge)
  • CI workflow doesn't run tests reliably; can't verify upgrade safety.
  • trust veto: new maintainer added
GHSA-jcpv-g9rr-qxrc: Regular Expression Denial of Service in hawk

Upgrade hawk from 1.1.1 to 3.1.3 or later

View advisory
root → hawk
3.1.3 → 9.0.1 major
review-required Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more → Score 10
Max CVSS 7.4 · 1 finding Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → Max EPSS 1.0% · 59th percentile Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
fix_kind.major Veto: the available fix requires a major version bump (1.x → 2.x), which implies potential breaking changes outside the auto-merge envelope. Click for more → pipeline.test_reality Veto: Arguss can't verify tests will run on upgraded code. Needs a test script in package.json, real test files, and a workflow that runs them. Click for more → trust.new_maintainer Veto: a new publishing identity was added between your current version and the upgrade target. A well-documented supply chain attack vector. Click for more →
  • major version bump requires human review (never auto-merge)
  • CI workflow doesn't run tests reliably; can't verify upgrade safety.
  • trust veto: new maintainer added
GHSA-44pw-h2cw-w3vq: Uncontrolled Resource Consumption in Hawk

Upgrade hawk from 3.1.3 to 9.0.1 or later

View advisory
root → request → hawk

Blast radius

Paths from project root to hawk - which dependencies pulled this package in?

async @ 2.6.3
root → optional-dev-dependency → async
1 finding high
Trust 0/100 EPSS 3.3%
REVIEW Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more →
2.6.3 → 2.6.4 patch
review-required Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more → Score 75
Max CVSS 7.8 · 1 finding Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → Max EPSS 3.3% · 87th percentile Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
pipeline.test_reality Veto: Arguss can't verify tests will run on upgraded code. Needs a test script in package.json, real test files, and a workflow that runs them. Click for more →
  • CI workflow doesn't run tests reliably; can't verify upgrade safety.
GHSA-fwr7-v2mv-hh25: Prototype Pollution in async

Upgrade async from 2.6.3 to 2.6.4 or later

View advisory
root → optional-dev-dependency → async

Blast radius

Paths from project root to async - which dependencies pulled this package in?

extend @ 3.0.1
root → request → extend
1 finding medium
Trust 0/100 EPSS 3.0%
REVIEW Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more →
3.0.1 → 3.0.2 patch
review-required Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more → Score 75
Max CVSS 5.0 · 1 finding Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → Max EPSS 3.0% · 86th percentile Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
pipeline.test_reality Veto: Arguss can't verify tests will run on upgraded code. Needs a test script in package.json, real test files, and a workflow that runs them. Click for more →
  • CI workflow doesn't run tests reliably; can't verify upgrade safety.
GHSA-qrmc-fj45-qfc2: Prototype Pollution in extend

Upgrade extend from 3.0.1 to 3.0.2 or later

View advisory
root → request → extend

Blast radius

Paths from project root to extend - which dependencies pulled this package in?

semver @ 5.5.0 An upgrade Arguss blocked despite the newer version being available, because trust signals like ownership transfer or new maintainer fired during the upgrade window. Click for more →
root → node-pre-gyp → semver
2 findings high
Trust 0/100 EPSS 2.8% ⚠ ownership transferred
REVIEW Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more →
GHSA-c2qf-rxjj-qqgw high CVSS 7.5 EPSS 2.8%
semver vulnerable to Regular Expression Denial of Service

Affects 2 install paths

5.5.0 → 5.7.2 minor
review-required Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more → Score 45
Max CVSS 7.5 · 2 findings Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → Max EPSS 2.8% · 84th percentile Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
pipeline.test_reality Veto: Arguss can't verify tests will run on upgraded code. Needs a test script in package.json, real test files, and a workflow that runs them. Click for more → trust.new_maintainer Veto: a new publishing identity was added between your current version and the upgrade target. A well-documented supply chain attack vector. Click for more → trust.ownership_transferred Veto: the package's primary maintainer changed during the upgrade window. Combined with new-maintainer, this is the highest-risk trust combination. Click for more →
  • CI workflow doesn't run tests reliably; can't verify upgrade safety.
  • trust veto: new maintainer added
  • trust veto: package ownership transferred between versions
GHSA-c2qf-rxjj-qqgw: semver vulnerable to Regular Expression Denial of Service

Upgrade semver from 5.5.0 to 5.7.2 or later

View advisory
root → node-pre-gyp → semver

Blast radius

Paths from project root to semver - which dependencies pulled this package in?

request @ 2.42.0
root → codecov.io → request
4 findings medium
Trust 30/100 EPSS 2.6% ⚠ new maintainer
REVIEW Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more →
Server-Side Request Forgery in Request

No fixed version published in OSV

GHSA-p8p7-x288-28g6
2.42.0 → 2.68.0 minor
review-required Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more → Score 60
Max CVSS 5.9 · 1 finding Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → Max EPSS 2.6% · 83rd percentile Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
pipeline.test_reality Veto: Arguss can't verify tests will run on upgraded code. Needs a test script in package.json, real test files, and a workflow that runs them. Click for more → trust.new_maintainer Veto: a new publishing identity was added between your current version and the upgrade target. A well-documented supply chain attack vector. Click for more →
  • CI workflow doesn't run tests reliably; can't verify upgrade safety.
  • trust veto: new maintainer added
GHSA-7xfp-9c55-5vqj: Remote Memory Exposure in request

Upgrade request from 2.42.0 to 2.68.0 or later

View advisory
root → codecov.io → request

Blast radius

Paths from project root to request - which dependencies pulled this package in?

loader-utils @ 0.2.17
root → webpack → loader-utils
1 finding critical
Trust 0/100 EPSS 2.6% ⚠ new maintainer
REVIEW Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more →
0.2.17 → 1.4.1 major
review-required Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more → Score 10
Max CVSS 9.8 · 1 finding Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → Max EPSS 2.6% · 83rd percentile Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
fix_kind.major Veto: the available fix requires a major version bump (1.x → 2.x), which implies potential breaking changes outside the auto-merge envelope. Click for more → pipeline.test_reality Veto: Arguss can't verify tests will run on upgraded code. Needs a test script in package.json, real test files, and a workflow that runs them. Click for more → trust.new_maintainer Veto: a new publishing identity was added between your current version and the upgrade target. A well-documented supply chain attack vector. Click for more →
  • major version bump requires human review (never auto-merge)
  • CI workflow doesn't run tests reliably; can't verify upgrade safety.
  • trust veto: new maintainer added
GHSA-76p3-8jx3-jpfq: Prototype pollution in webpack loader-utils

Upgrade loader-utils from 0.2.17 to 1.4.1 or later

View advisory
root → webpack → loader-utils

Blast radius

Paths from project root to loader-utils - which dependencies pulled this package in?

jsonpointer @ 4.0.1
root → request → har-validator → is-my-json-valid → jsonpointer
1 finding medium
Trust 0/100 EPSS 2.5%
REVIEW Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more →
4.0.1 → 5.0.0 major
review-required Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more → Score 25
Max CVSS 5.6 · 1 finding Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → Max EPSS 2.5% · 83rd percentile Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
fix_kind.major Veto: the available fix requires a major version bump (1.x → 2.x), which implies potential breaking changes outside the auto-merge envelope. Click for more → pipeline.test_reality Veto: Arguss can't verify tests will run on upgraded code. Needs a test script in package.json, real test files, and a workflow that runs them. Click for more →
  • major version bump requires human review (never auto-merge)
  • CI workflow doesn't run tests reliably; can't verify upgrade safety.
GHSA-282f-qqgm-c34q: Prototype Pollution in node-jsonpointer

Upgrade jsonpointer from 4.0.1 to 5.0.0 or later

View advisory
root → request → har-validator → is-my-json-valid → jsonpointer

Blast radius

Paths from project root to jsonpointer - which dependencies pulled this package in?

kind-of @ 6.0.2
root → qunitjs → findup-sync → micromatch → braces → expand-range → fill-range → randomatic → kind-of
1 finding high
Trust 0/100 EPSS 2.3%
REVIEW Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more →
6.0.2 → 6.0.3 patch
review-required Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more → Score 75
Max CVSS 7.5 · 1 finding Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → Max EPSS 2.3% · 81st percentile Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
pipeline.test_reality Veto: Arguss can't verify tests will run on upgraded code. Needs a test script in package.json, real test files, and a workflow that runs them. Click for more →
  • CI workflow doesn't run tests reliably; can't verify upgrade safety.
GHSA-6c8f-qphg-qjgp: Validation Bypass in kind-of

Upgrade kind-of from 6.0.2 to 6.0.3 or later

View advisory
root → qunitjs → findup-sync → micromatch → braces → expand-range → fill-range → randomatic → kind-of

Blast radius

Paths from project root to kind-of - which dependencies pulled this package in?

ajv @ 6.10.2
root → request → har-validator → ajv
2 findings medium
Trust 0/100 EPSS 2.3%
REVIEW Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more →
6.10.2 → 6.14.0 minor
review-required Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more → Score 75
Max CVSS 5.6 · 2 findings Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → Max EPSS 2.3% · 81st percentile Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
pipeline.test_reality Veto: Arguss can't verify tests will run on upgraded code. Needs a test script in package.json, real test files, and a workflow that runs them. Click for more →
  • CI workflow doesn't run tests reliably; can't verify upgrade safety.
GHSA-v88g-cgmw-v5xw: Prototype Pollution in Ajv

Upgrade ajv from 6.10.2 to 6.12.3 or later

View advisory
root → request → har-validator → ajv

Blast radius

Paths from project root to ajv - which dependencies pulled this package in?

path-parse @ 1.0.5
root → istanbul → resolve → path-parse
1 finding medium
Trust 30/100 EPSS 2.2%
REVIEW Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more →
GHSA-hj48-42vr-x3v9 medium CVSS 5.3 EPSS 2.2%
Regular Expression Denial of Service in path-parse
1.0.5 → 1.0.7 patch
review-required Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more → Score 75
Max CVSS 5.3 · 1 finding Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → Max EPSS 2.2% · 80th percentile Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
pipeline.test_reality Veto: Arguss can't verify tests will run on upgraded code. Needs a test script in package.json, real test files, and a workflow that runs them. Click for more →
  • CI workflow doesn't run tests reliably; can't verify upgrade safety.
GHSA-hj48-42vr-x3v9: Regular Expression Denial of Service in path-parse

Upgrade path-parse from 1.0.5 to 1.0.7 or later

View advisory
root → istanbul → resolve → path-parse

Blast radius

Paths from project root to path-parse - which dependencies pulled this package in?

bl @ 0.9.5
root → request → bl
1 finding medium
Trust 30/100 EPSS 2.2% ⚠ new maintainer
REVIEW Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more →
0.9.5 → 1.2.3 major
review-required Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more → Score 10
Max CVSS 6.5 · 1 finding Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → Max EPSS 2.2% · 80th percentile Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
fix_kind.major Veto: the available fix requires a major version bump (1.x → 2.x), which implies potential breaking changes outside the auto-merge envelope. Click for more → pipeline.test_reality Veto: Arguss can't verify tests will run on upgraded code. Needs a test script in package.json, real test files, and a workflow that runs them. Click for more → trust.new_maintainer Veto: a new publishing identity was added between your current version and the upgrade target. A well-documented supply chain attack vector. Click for more →
  • major version bump requires human review (never auto-merge)
  • CI workflow doesn't run tests reliably; can't verify upgrade safety.
  • trust veto: new maintainer added
GHSA-pp7h-53gx-mx7r: Remote Memory Exposure in bl

Upgrade bl from 0.9.5 to 1.2.3 or later

View advisory
root → request → bl

Blast radius

Paths from project root to bl - which dependencies pulled this package in?

nth-check @ 1.0.1
root → cheerio → css-select → nth-check
1 finding high
Trust 30/100 EPSS 2.2%
REVIEW Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more →
GHSA-rp65-9cf3-cjxr high CVSS 7.5 EPSS 2.2%
Inefficient Regular Expression Complexity in nth-check
1.0.1 → 2.0.1 major
review-required Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more → Score 25
Max CVSS 7.5 · 1 finding Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → Max EPSS 2.2% · 80th percentile Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
fix_kind.major Veto: the available fix requires a major version bump (1.x → 2.x), which implies potential breaking changes outside the auto-merge envelope. Click for more → pipeline.test_reality Veto: Arguss can't verify tests will run on upgraded code. Needs a test script in package.json, real test files, and a workflow that runs them. Click for more →
  • major version bump requires human review (never auto-merge)
  • CI workflow doesn't run tests reliably; can't verify upgrade safety.
GHSA-rp65-9cf3-cjxr: Inefficient Regular Expression Complexity in nth-check

Upgrade nth-check from 1.0.1 to 2.0.1 or later

View advisory
root → cheerio → css-select → nth-check

Blast radius

Paths from project root to nth-check - which dependencies pulled this package in?

mime @ 1.2.11
root → request → form-data → mime
1 finding high
Trust 0/100 EPSS 2.1%
REVIEW Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more →
GHSA-wrvr-8mpx-r7pp high CVSS 7.5 EPSS 2.1%
mime Regular Expression Denial of Service when MIME lookup performed on untrusted user input
1.2.11 → 1.4.1 minor
review-required Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more → Score 75
Max CVSS 7.5 · 1 finding Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → Max EPSS 2.1% · 79th percentile Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
pipeline.test_reality Veto: Arguss can't verify tests will run on upgraded code. Needs a test script in package.json, real test files, and a workflow that runs them. Click for more →
  • CI workflow doesn't run tests reliably; can't verify upgrade safety.
GHSA-wrvr-8mpx-r7pp: mime Regular Expression Denial of Service when MIME lookup performed on untrusted user input

Upgrade mime from 1.2.11 to 1.4.1 or later

View advisory
root → request → form-data → mime

Blast radius

Paths from project root to mime - which dependencies pulled this package in?

form-data @ 0.1.4 An upgrade Arguss blocked despite the newer version being available, because trust signals like ownership transfer or new maintainer fired during the upgrade window. Click for more →
root → form-data
6 findings critical–high
Trust 0/100 EPSS 1.7% ⚠ ownership transferred
REVIEW Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more →
GHSA-fjxv-7rqg-78g4 critical CVSS 9.5 EPSS 1.7%
form-data uses unsafe random function in form-data for choosing boundary

Affects 3 install paths

GHSA-hmw2-7cc7-3qxx high CVSS 7.5 EPSS 0.4%
form-data: CRLF injection in form-data via unescaped multipart field names and filenames

Affects 3 install paths

0.1.4 → 2.5.6 major
review-required Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more → Score 1
Max CVSS 9.5 · 2 findings Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → Max EPSS 1.7% · 75th percentile Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
fix_kind.major Veto: the available fix requires a major version bump (1.x → 2.x), which implies potential breaking changes outside the auto-merge envelope. Click for more → pipeline.test_reality Veto: Arguss can't verify tests will run on upgraded code. Needs a test script in package.json, real test files, and a workflow that runs them. Click for more → trust.new_maintainer Veto: a new publishing identity was added between your current version and the upgrade target. A well-documented supply chain attack vector. Click for more → trust.ownership_transferred Veto: the package's primary maintainer changed during the upgrade window. Combined with new-maintainer, this is the highest-risk trust combination. Click for more →
  • major version bump requires human review (never auto-merge)
  • CI workflow doesn't run tests reliably; can't verify upgrade safety.
  • trust veto: new maintainer added
  • trust veto: package ownership transferred between versions
GHSA-fjxv-7rqg-78g4: form-data uses unsafe random function in form-data for choosing boundary

Upgrade form-data from 0.1.4 to 2.5.4 or later

View advisory
root → form-data
2.1.4 → 2.5.6 minor
review-required Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more → Score 60
Max CVSS 9.5 · 2 findings Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → Max EPSS 1.7% · 75th percentile Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
pipeline.test_reality Veto: Arguss can't verify tests will run on upgraded code. Needs a test script in package.json, real test files, and a workflow that runs them. Click for more → trust.new_maintainer Veto: a new publishing identity was added between your current version and the upgrade target. A well-documented supply chain attack vector. Click for more →
  • CI workflow doesn't run tests reliably; can't verify upgrade safety.
  • trust veto: new maintainer added
GHSA-fjxv-7rqg-78g4: form-data uses unsafe random function in form-data for choosing boundary

Upgrade form-data from 2.1.4 to 2.5.4 or later

View advisory
root → request → form-data
2.3.3 → 2.5.6 minor
review-required Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more → Score 60
Max CVSS 9.5 · 2 findings Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → Max EPSS 1.7% · 75th percentile Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
pipeline.test_reality Veto: Arguss can't verify tests will run on upgraded code. Needs a test script in package.json, real test files, and a workflow that runs them. Click for more → trust.new_maintainer Veto: a new publishing identity was added between your current version and the upgrade target. A well-documented supply chain attack vector. Click for more →
  • CI workflow doesn't run tests reliably; can't verify upgrade safety.
  • trust veto: new maintainer added
GHSA-fjxv-7rqg-78g4: form-data uses unsafe random function in form-data for choosing boundary

Upgrade form-data from 2.3.3 to 2.5.4 or later

View advisory
root → request → form-data

Blast radius

Paths from project root to form-data - which dependencies pulled this package in?

minimatch @ 3.0.4
root → glob → minimatch
8 findings high
Trust 30/100 EPSS 1.7%
REVIEW Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more →
GHSA-23c5-xmqv-rm74 high CVSS 7.5 EPSS 0.5%
minimatch ReDoS: nested *() extglobs generate catastrophically backtracking regular expressions

Affects 2 install paths

GHSA-3ppc-4f35-3m26 high CVSS 7.5 EPSS 0.5%
minimatch has a ReDoS via repeated wildcards with non-matching literal in pattern

Affects 2 install paths

GHSA-7r86-cg39-jmmj high CVSS 7.5 EPSS 0.5%
minimatch has ReDoS: matchOne() combinatorial backtracking via multiple non-adjacent GLOBSTAR segments

Affects 2 install paths

GHSA-f8q6-p94x-37v3 high CVSS 7.5 EPSS 1.7%
minimatch ReDoS vulnerability

Affects 2 install paths

3.0.4 → 3.1.4 minor
review-required Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more → Score 75
Max CVSS 7.5 · 8 findings Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → Max EPSS 1.7% · 74th percentile Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
pipeline.test_reality Veto: Arguss can't verify tests will run on upgraded code. Needs a test script in package.json, real test files, and a workflow that runs them. Click for more →
  • CI workflow doesn't run tests reliably; can't verify upgrade safety.
GHSA-23c5-xmqv-rm74: minimatch ReDoS: nested *() extglobs generate catastrophically backtracking regular expressions

Upgrade minimatch from 3.0.4 to 3.1.4 or later

View advisory
root → glob → minimatch

Blast radius

Paths from project root to minimatch - which dependencies pulled this package in?

fsevents @ 1.2.2
root → fsevents
2 findings critical–medium
Trust 15/100 EPSS 1.5% ⚠ new maintainer
REVIEW Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more →
MAL-2023-462 medium EPSS n/a
MAL-2023-462: Malicious code in fsevents (npm)
1.2.2 → 1.2.11 patch
review-required Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more → Score 60
Max CVSS 9.8 · 2 findings Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → Max EPSS 1.5% · 72nd percentile Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
pipeline.test_reality Veto: Arguss can't verify tests will run on upgraded code. Needs a test script in package.json, real test files, and a workflow that runs them. Click for more → trust.new_maintainer Veto: a new publishing identity was added between your current version and the upgrade target. A well-documented supply chain attack vector. Click for more →
  • CI workflow doesn't run tests reliably; can't verify upgrade safety.
  • trust veto: new maintainer added
GHSA-8r6j-v8pm-fqw3: Code injection in fsevents

Upgrade fsevents from 1.2.2 to 1.2.11 or later

View advisory
root → fsevents

Blast radius

Paths from project root to fsevents - which dependencies pulled this package in?

pathval @ 0.1.1 An upgrade Arguss blocked despite the newer version being available, because trust signals like ownership transfer or new maintainer fired during the upgrade window. Click for more →
root → jscs → pathval
1 finding high
Trust 0/100 EPSS 1.5% ⚠ ownership transferred
REVIEW Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more →
0.1.1 → 1.1.1 major
review-required Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more → Score 1
Max CVSS 7.2 · 1 finding Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → Max EPSS 1.5% · 71st percentile Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
fix_kind.major Veto: the available fix requires a major version bump (1.x → 2.x), which implies potential breaking changes outside the auto-merge envelope. Click for more → pipeline.test_reality Veto: Arguss can't verify tests will run on upgraded code. Needs a test script in package.json, real test files, and a workflow that runs them. Click for more → trust.new_maintainer Veto: a new publishing identity was added between your current version and the upgrade target. A well-documented supply chain attack vector. Click for more → trust.ownership_transferred Veto: the package's primary maintainer changed during the upgrade window. Combined with new-maintainer, this is the highest-risk trust combination. Click for more →
  • major version bump requires human review (never auto-merge)
  • CI workflow doesn't run tests reliably; can't verify upgrade safety.
  • trust veto: new maintainer added
  • trust veto: package ownership transferred between versions
GHSA-g6ww-v8xp-vmwg: Prototype pollution in pathval

Upgrade pathval from 0.1.1 to 1.1.1 or later

View advisory
root → jscs → pathval

Blast radius

Paths from project root to pathval - which dependencies pulled this package in?

braces @ 1.8.5
root → qunitjs → findup-sync → micromatch → braces
1 finding high
Trust 0/100 EPSS 1.5% ⚠ new maintainer
REVIEW Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more →
1.8.5 → 3.0.3 major
review-required Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more → Score 10
Max CVSS 7.5 · 1 finding Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → Max EPSS 1.5% · 70th percentile Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
fix_kind.major Veto: the available fix requires a major version bump (1.x → 2.x), which implies potential breaking changes outside the auto-merge envelope. Click for more → pipeline.test_reality Veto: Arguss can't verify tests will run on upgraded code. Needs a test script in package.json, real test files, and a workflow that runs them. Click for more → trust.new_maintainer Veto: a new publishing identity was added between your current version and the upgrade target. A well-documented supply chain attack vector. Click for more →
  • major version bump requires human review (never auto-merge)
  • CI workflow doesn't run tests reliably; can't verify upgrade safety.
  • trust veto: new maintainer added
GHSA-grv7-fg5c-xmjg: Uncontrolled resource consumption in braces

Upgrade braces from 1.8.5 to 3.0.3 or later

View advisory
root → qunitjs → findup-sync → micromatch → braces

Blast radius

Paths from project root to braces - which dependencies pulled this package in?

css-what @ 2.1.0
root → cheerio → css-select → css-what
1 finding high
Trust 30/100 EPSS 1.5%
REVIEW Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more →
GHSA-p28h-cc7q-c4fg high CVSS 7.5 EPSS 1.5%
css-what vulnerable to ReDoS due to use of insecure regular expression
2.1.0 → 2.1.3 patch
review-required Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more → Score 75
Max CVSS 7.5 · 1 finding Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → Max EPSS 1.5% · 70th percentile Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
pipeline.test_reality Veto: Arguss can't verify tests will run on upgraded code. Needs a test script in package.json, real test files, and a workflow that runs them. Click for more →
  • CI workflow doesn't run tests reliably; can't verify upgrade safety.
GHSA-p28h-cc7q-c4fg: css-what vulnerable to ReDoS due to use of insecure regular expression

Upgrade css-what from 2.1.0 to 2.1.3 or later

View advisory
root → cheerio → css-select → css-what

Blast radius

Paths from project root to css-what - which dependencies pulled this package in?

micromatch @ 2.3.11
root → qunitjs → chokidar → anymatch → micromatch
1 finding medium
Trust 0/100 EPSS 1.4% ⚠ new maintainer
REVIEW Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more →
GHSA-952p-6rrq-rcjv medium CVSS 5.3 EPSS 1.4%
Regular Expression Denial of Service (ReDoS) in micromatch
2.3.11 → 4.0.8 major
review-required Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more → Score 10
Max CVSS 5.3 · 1 finding Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → Max EPSS 1.4% · 70th percentile Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
fix_kind.major Veto: the available fix requires a major version bump (1.x → 2.x), which implies potential breaking changes outside the auto-merge envelope. Click for more → pipeline.test_reality Veto: Arguss can't verify tests will run on upgraded code. Needs a test script in package.json, real test files, and a workflow that runs them. Click for more → trust.new_maintainer Veto: a new publishing identity was added between your current version and the upgrade target. A well-documented supply chain attack vector. Click for more →
  • major version bump requires human review (never auto-merge)
  • CI workflow doesn't run tests reliably; can't verify upgrade safety.
  • trust veto: new maintainer added
GHSA-952p-6rrq-rcjv: Regular Expression Denial of Service (ReDoS) in micromatch

Upgrade micromatch from 2.3.11 to 4.0.8 or later

View advisory
root → qunitjs → chokidar → anymatch → micromatch

Blast radius

Paths from project root to micromatch - which dependencies pulled this package in?

ecstatic @ 2.2.2
root → ecstatic
1 finding medium
Trust 0/100 EPSS 1.3% ⚠ trust.unavailable
REVIEW Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more →
2.2.2 → 4.1.3 major
review-required Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more → Score 5
Max CVSS 5.0 · 1 finding Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → Max EPSS 1.3% · 66th percentile Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
fix_kind.major Veto: the available fix requires a major version bump (1.x → 2.x), which implies potential breaking changes outside the auto-merge envelope. Click for more → pipeline.test_reality Veto: Arguss can't verify tests will run on upgraded code. Needs a test script in package.json, real test files, and a workflow that runs them. Click for more → trust.unavailable
  • major version bump requires human review (never auto-merge)
  • CI workflow doesn't run tests reliably; can't verify upgrade safety.
  • trust signals unavailable for this package upgrade
GHSA-jc84-3g44-wf2q: Denial of Service in ecstatic

Upgrade ecstatic from 2.2.2 to 4.1.3 or later

View advisory
root → ecstatic

Blast radius

Paths from project root to ecstatic - which dependencies pulled this package in?

i @ 0.3.6
root → jscs → prompt → utile → i
1 finding high
Trust 45/100 EPSS 1.2%
REVIEW Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more →
GHSA-x55w-vjjp-222r high CVSS 7.5 EPSS 1.2%
inflect vulnerable to Inefficient Regular Expression Complexity
0.3.6 → 0.3.7 patch
review-required Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more → Score 75
Max CVSS 7.5 · 1 finding Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → Max EPSS 1.2% · 65th percentile Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
pipeline.test_reality Veto: Arguss can't verify tests will run on upgraded code. Needs a test script in package.json, real test files, and a workflow that runs them. Click for more →
  • CI workflow doesn't run tests reliably; can't verify upgrade safety.
GHSA-x55w-vjjp-222r: inflect vulnerable to Inefficient Regular Expression Complexity

Upgrade i from 0.3.6 to 0.3.7 or later

View advisory
root → jscs → prompt → utile → i

Blast radius

Paths from project root to i - which dependencies pulled this package in?

cross-spawn @ 5.1.0
root → optional-dev-dependency → cross-spawn
1 finding high
Trust 30/100 EPSS 0.9%
REVIEW Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more →
GHSA-3xgq-45jj-v275 high CVSS 7.5 EPSS 0.9%
Regular Expression Denial of Service (ReDoS) in cross-spawn
5.1.0 → 6.0.6 major
review-required Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more → Score 25
Max CVSS 7.5 · 1 finding Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → Max EPSS 0.9% · 54th percentile Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
fix_kind.major Veto: the available fix requires a major version bump (1.x → 2.x), which implies potential breaking changes outside the auto-merge envelope. Click for more → pipeline.test_reality Veto: Arguss can't verify tests will run on upgraded code. Needs a test script in package.json, real test files, and a workflow that runs them. Click for more →
  • major version bump requires human review (never auto-merge)
  • CI workflow doesn't run tests reliably; can't verify upgrade safety.
GHSA-3xgq-45jj-v275: Regular Expression Denial of Service (ReDoS) in cross-spawn

Upgrade cross-spawn from 5.1.0 to 6.0.6 or later

View advisory
root → optional-dev-dependency → cross-spawn

Blast radius

Paths from project root to cross-spawn - which dependencies pulled this package in?

requirejs @ 2.3.6
root → requirejs
1 finding critical
Trust 30/100 EPSS 0.7%
REVIEW Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more →
GHSA-x3m3-4wpv-5vgc critical CVSS 10.0 EPSS 0.7%
jrburke requirejs vulnerable to prototype pollution
2.3.6 → 2.3.7 patch
review-required Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more → Score 75
Max CVSS 10.0 · 1 finding Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → Max EPSS 0.7% · 50th percentile Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
pipeline.test_reality Veto: Arguss can't verify tests will run on upgraded code. Needs a test script in package.json, real test files, and a workflow that runs them. Click for more →
  • CI workflow doesn't run tests reliably; can't verify upgrade safety.
GHSA-x3m3-4wpv-5vgc: jrburke requirejs vulnerable to prototype pollution

Upgrade requirejs from 2.3.6 to 2.3.7 or later

View advisory
root → requirejs

Blast radius

Paths from project root to requirejs - which dependencies pulled this package in?

sha.js @ 2.2.6 An upgrade Arguss blocked despite the newer version being available, because trust signals like ownership transfer or new maintainer fired during the upgrade window. Click for more →
root → webpack → node-libs-browser → crypto-browserify → sha.js
1 finding critical
Trust 30/100 EPSS 0.7% ⚠ ownership transferred
REVIEW Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more →
GHSA-95m3-7q98-8xr5 critical CVSS 9.1 EPSS 0.7%
sha.js is missing type checks leading to hash rewind and passing on crafted data
2.2.6 → 2.4.12 minor
review-required Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more → Score 45
Max CVSS 9.1 · 1 finding Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → Max EPSS 0.7% · 48th percentile Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
pipeline.test_reality Veto: Arguss can't verify tests will run on upgraded code. Needs a test script in package.json, real test files, and a workflow that runs them. Click for more → trust.new_maintainer Veto: a new publishing identity was added between your current version and the upgrade target. A well-documented supply chain attack vector. Click for more → trust.ownership_transferred Veto: the package's primary maintainer changed during the upgrade window. Combined with new-maintainer, this is the highest-risk trust combination. Click for more →
  • CI workflow doesn't run tests reliably; can't verify upgrade safety.
  • trust veto: new maintainer added
  • trust veto: package ownership transferred between versions
GHSA-95m3-7q98-8xr5: sha.js is missing type checks leading to hash rewind and passing on crafted data

Upgrade sha.js from 2.2.6 to 2.4.12 or later

View advisory
root → webpack → node-libs-browser → crypto-browserify → sha.js

Blast radius

Paths from project root to sha.js - which dependencies pulled this package in?

yargs-parser @ 5.0.0
root → optional-dev-dependency → yargs → yargs-parser
1 finding medium
Trust 0/100 EPSS 0.5% ⚠ new maintainer
REVIEW Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more →
5.0.0 → 5.0.1 patch
review-required Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more → Score 60
Max CVSS 5.3 · 1 finding Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → Max EPSS 0.5% · 40th percentile Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
pipeline.test_reality Veto: Arguss can't verify tests will run on upgraded code. Needs a test script in package.json, real test files, and a workflow that runs them. Click for more → trust.new_maintainer Veto: a new publishing identity was added between your current version and the upgrade target. A well-documented supply chain attack vector. Click for more →
  • CI workflow doesn't run tests reliably; can't verify upgrade safety.
  • trust veto: new maintainer added
GHSA-p9pc-299p-vxgp: yargs-parser Vulnerable to Prototype Pollution

Upgrade yargs-parser from 5.0.0 to 5.0.1 or later

View advisory
root → optional-dev-dependency → yargs → yargs-parser

Blast radius

Paths from project root to yargs-parser - which dependencies pulled this package in?

brace-expansion @ 1.1.11
root → glob → minimatch → brace-expansion
6 findings medium–low
Trust 0/100 EPSS 0.5%
REVIEW Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more →
GHSA-f886-m6hf-6m8v medium CVSS 6.5 EPSS 0.4%
brace-expansion: Zero-step sequence causes process hang and memory exhaustion

Affects 2 install paths

GHSA-3jxr-9vmj-r5cp medium CVSS 5.3 EPSS 0.4%
brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups

Affects 2 install paths

GHSA-v6h2-p8h4-qcjw low CVSS 3.1 EPSS 0.5%
brace-expansion Regular Expression Denial of Service vulnerability

Affects 2 install paths

1.1.11 → 1.1.16 patch
review-required Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more → Score 75
Max CVSS 6.5 · 6 findings Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → Max EPSS 0.5% · 37th percentile Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
pipeline.test_reality Veto: Arguss can't verify tests will run on upgraded code. Needs a test script in package.json, real test files, and a workflow that runs them. Click for more →
  • CI workflow doesn't run tests reliably; can't verify upgrade safety.
GHSA-f886-m6hf-6m8v: brace-expansion: Zero-step sequence causes process hang and memory exhaustion

Upgrade brace-expansion from 1.1.11 to 1.1.13 or later

View advisory
root → glob → minimatch → brace-expansion

Blast radius

Paths from project root to brace-expansion - which dependencies pulled this package in?

js-yaml @ 3.13.1
root → istanbul → js-yaml
13 findings high–medium
Trust 30/100 EPSS 0.4%
REVIEW Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more →
GHSA-52cp-r559-cp3m high CVSS 7.5 EPSS 0.4%
js-yaml: YAML merge-key chains can force quadratic CPU consumption

Affects 3 install paths

GHSA-2pr6-76vf-7546 medium CVSS 5.9 EPSS n/a
Denial of Service in js-yaml

Affects 2 install paths

GHSA-h67p-54hq-rp68 medium CVSS 5.3 EPSS 0.3%
JS-YAML: Quadratic-complexity DoS in merge key handling via repeated aliases

Affects 3 install paths

GHSA-mh29-5h37-fv8m medium CVSS 5.3 EPSS 0.4%
js-yaml has prototype pollution in merge (<<)

Affects 3 install paths

3.13.1 → 3.15.0 minor
review-required Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more → Score 75
Max CVSS 7.5 · 3 findings Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → Max EPSS 0.4% · 33rd percentile Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
pipeline.test_reality Veto: Arguss can't verify tests will run on upgraded code. Needs a test script in package.json, real test files, and a workflow that runs them. Click for more →
  • CI workflow doesn't run tests reliably; can't verify upgrade safety.
GHSA-52cp-r559-cp3m: js-yaml: YAML merge-key chains can force quadratic CPU consumption

Upgrade js-yaml from 3.13.1 to 3.15.0 or later

View advisory
root → istanbul → js-yaml
3.4.6 → 3.15.0 minor
review-required Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more → Score 75
Max CVSS 7.5 · 5 findings Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → Max EPSS 0.4% · 33rd percentile Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
pipeline.test_reality Veto: Arguss can't verify tests will run on upgraded code. Needs a test script in package.json, real test files, and a workflow that runs them. Click for more →
  • CI workflow doesn't run tests reliably; can't verify upgrade safety.
GHSA-52cp-r559-cp3m: js-yaml: YAML merge-key chains can force quadratic CPU consumption

Upgrade js-yaml from 3.4.6 to 3.15.0 or later

View advisory
root → jscs → js-yaml
3.6.1 → 3.15.0 minor
review-required Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more → Score 75
Max CVSS 7.5 · 5 findings Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → Max EPSS 0.4% · 33rd percentile Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
pipeline.test_reality Veto: Arguss can't verify tests will run on upgraded code. Needs a test script in package.json, real test files, and a workflow that runs them. Click for more →
  • CI workflow doesn't run tests reliably; can't verify upgrade safety.
GHSA-52cp-r559-cp3m: js-yaml: YAML merge-key chains can force quadratic CPU consumption

Upgrade js-yaml from 3.6.1 to 3.15.0 or later

View advisory
root → coveralls → js-yaml

Blast radius

Paths from project root to js-yaml - which dependencies pulled this package in?

uuid @ 2.0.3 An upgrade Arguss blocked despite the newer version being available, because trust signals like ownership transfer or new maintainer fired during the upgrade window. Click for more →
root → jscs → vow-fs → uuid
3 findings high
Trust 0/100 EPSS 0.3% ⚠ ownership transferred
REVIEW Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more →
GHSA-w5hq-g745-h8pq high CVSS 7.5 EPSS 0.3%
uuid: Missing buffer bounds check in v3/v5/v6 when buf is provided

Affects 3 install paths

2.0.3 → 11.1.1 major
review-required Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more → Score 1
Max CVSS 7.5 · 1 finding Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → Max EPSS 0.3% · 25th percentile Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
fix_kind.major Veto: the available fix requires a major version bump (1.x → 2.x), which implies potential breaking changes outside the auto-merge envelope. Click for more → pipeline.test_reality Veto: Arguss can't verify tests will run on upgraded code. Needs a test script in package.json, real test files, and a workflow that runs them. Click for more → trust.new_maintainer Veto: a new publishing identity was added between your current version and the upgrade target. A well-documented supply chain attack vector. Click for more → trust.ownership_transferred Veto: the package's primary maintainer changed during the upgrade window. Combined with new-maintainer, this is the highest-risk trust combination. Click for more →
  • major version bump requires human review (never auto-merge)
  • CI workflow doesn't run tests reliably; can't verify upgrade safety.
  • trust veto: new maintainer added
  • trust veto: package ownership transferred between versions
GHSA-w5hq-g745-h8pq: uuid: Missing buffer bounds check in v3/v5/v6 when buf is provided

Upgrade uuid from 2.0.3 to 11.1.1 or later

View advisory
root → jscs → vow-fs → uuid
3.2.1 → 11.1.1 major
review-required Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more → Score 1
Max CVSS 7.5 · 1 finding Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → Max EPSS 0.3% · 25th percentile Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
fix_kind.major Veto: the available fix requires a major version bump (1.x → 2.x), which implies potential breaking changes outside the auto-merge envelope. Click for more → pipeline.test_reality Veto: Arguss can't verify tests will run on upgraded code. Needs a test script in package.json, real test files, and a workflow that runs them. Click for more → trust.new_maintainer Veto: a new publishing identity was added between your current version and the upgrade target. A well-documented supply chain attack vector. Click for more → trust.ownership_transferred Veto: the package's primary maintainer changed during the upgrade window. Combined with new-maintainer, this is the highest-risk trust combination. Click for more →
  • major version bump requires human review (never auto-merge)
  • CI workflow doesn't run tests reliably; can't verify upgrade safety.
  • trust veto: new maintainer added
  • trust veto: package ownership transferred between versions
GHSA-w5hq-g745-h8pq: uuid: Missing buffer bounds check in v3/v5/v6 when buf is provided

Upgrade uuid from 3.2.1 to 11.1.1 or later

View advisory
root → request → uuid
3.3.2 → 11.1.1 major
review-required Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more → Score 1
Max CVSS 7.5 · 1 finding Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → Max EPSS 0.3% · 25th percentile Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
fix_kind.major Veto: the available fix requires a major version bump (1.x → 2.x), which implies potential breaking changes outside the auto-merge envelope. Click for more → pipeline.test_reality Veto: Arguss can't verify tests will run on upgraded code. Needs a test script in package.json, real test files, and a workflow that runs them. Click for more → trust.new_maintainer Veto: a new publishing identity was added between your current version and the upgrade target. A well-documented supply chain attack vector. Click for more → trust.ownership_transferred Veto: the package's primary maintainer changed during the upgrade window. Combined with new-maintainer, this is the highest-risk trust combination. Click for more →
  • major version bump requires human review (never auto-merge)
  • CI workflow doesn't run tests reliably; can't verify upgrade safety.
  • trust veto: new maintainer added
  • trust veto: package ownership transferred between versions
GHSA-w5hq-g745-h8pq: uuid: Missing buffer bounds check in v3/v5/v6 when buf is provided

Upgrade uuid from 3.3.2 to 11.1.1 or later

View advisory
root → request → uuid

Blast radius

Paths from project root to uuid - which dependencies pulled this package in?

tunnel-agent @ 0.4.3
root → request → tunnel-agent
1 finding medium
Trust 0/100
REVIEW Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more →
0.4.3 → 0.6.0 minor
review-required Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more → Score 75
Max CVSS 5.0 · 1 finding Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → Max EPSS: n/a
pipeline.test_reality Veto: Arguss can't verify tests will run on upgraded code. Needs a test script in package.json, real test files, and a workflow that runs them. Click for more →
  • CI workflow doesn't run tests reliably; can't verify upgrade safety.
GHSA-xc7v-wxcw-j472: Memory Exposure in tunnel-agent

Upgrade tunnel-agent from 0.4.3 to 0.6.0 or later

View advisory
root → request → tunnel-agent

Blast radius

Paths from project root to tunnel-agent - which dependencies pulled this package in?

Package status

602 packages scanned.

  • 60 Review-required candidates Arguss flagged these for a human decision - nothing merges until you review them.
  • 4 Packages with no automated fix +4 More with unfixable findings alongside fixable ones

Review auto-merge candidates and open PRs in a guided flow.

Glossary

What the labels and signals mean.

Trust Save
A package upgrade Arguss would have blocked despite the new version being available, because trust signals, like ownership transfer or a new maintainer, fired during the upgrade window. The name reflects what the agent did for the user: saved them from a potentially malicious update that a version-only auto-PR tool would have merged.
AUTO-MERGE
Verdict tier indicating the fix passes all three lenses cleanly. After you confirm action from a Scan assessment, Arguss opens a pull request for the upgrade; it does not merge PRs on GitHub. The envelope is conservative on purpose: patch or minor version bump, trust signals unchanged, blast radius bounded, real tests pass.
REVIEW
Verdict tier requiring a human decision. At least one veto fired during fix-confidence evaluation, trust signals shifted, the pipeline can't verify post-upgrade behavior, or the upgrade is a major version bump. The agent surfaces the reasons; the developer decides.
DECLINE
Verdict tier indicating no remediation is recommended. Typically applies when no fix version exists for the finding, or when multiple critical vetoes make even human review unproductive.
fix_kind.major
Veto signal that fires when the available fix requires a major version bump (1.x → 2.x). Major bumps imply potential breaking changes and fall outside the auto-merge envelope by default, even when the upgrade is the only available fix.
trust.new_maintainer
Veto signal that fires when a package added a new maintainer during the upgrade window, meaning between the user's current version and the proposed upgrade. New publishing identities are a well-documented attack vector for typosquats and supply chain takeovers.
trust.ownership_transferred
Veto signal that fires when a package's primary maintainer changed during the upgrade window. Combined with trust.new_maintainer, this is the highest-risk trust combination, typical of the xz-utils style attacks and historical npm credential theft incidents.
pipeline.test_reality
Veto signal that fires when Arguss can't verify tests will run on the upgraded code. Four conditions must hold: a test script exists in package.json, it isn't a no-op, real test files exist, and a workflow actually invokes them. If any fail, the fix cannot qualify for AUTO_MERGE because there's no way to verify the upgrade didn't break the user's project.
CVSS
Common Vulnerability Scoring System. A numeric score (0.0–10.0) representing how damaging a vulnerability could be if exploited. Sourced from NIST's National Vulnerability Database via OSV.dev. Severity, not urgency.
EPSS
Exploit Prediction Scoring System. A daily-updated probability (0.0–1.0, displayed as percent) that a CVE will be exploited in the next 30 days. Sourced from FIRST.org. Probability, not severity.
KEV
CISA's Known Exploited Vulnerabilities catalog. A federal list of CVEs with documented active exploitation in the wild. Federal agencies have a binding patching deadline; for everyone else, presence on KEV is the strongest "this is being used right now" signal available. Sourced directly from CISA.
Project Risk Score (PRS)
A weighted blend of the three lens subscores (40% vulnerability, 30% trust, 30% pipeline) producing an overall 0–100 indicator of the project's dependency health. Useful for at-a-glance triage; the per-finding fix-confidence verdicts are what drive automated decisions.

Dependency graph

Full-project map of transitive dependencies. Severity colors reflect vulnerabilities; trust rings apply only to direct dependencies analyzed by OpenSSF Scorecard (higher = riskier).