Findings
1 package with no automated fix
These advisories have no fix version Arguss can apply automatically. Review and remediate manually.
request@2.88.2
-
request@2.88.2EPSS 0.7% CVSS 6.1 medium
Server-Side Request Forgery in Request
The `request` package through 2.88.2 for Node.js and the `@cypress/request` package prior to 3.0.0 allow a bypass of SSRF mitigations via an attacker-controller server that does a cross-protocol redirect (HTTP to HTTPS, or HTTPS to HTTP). NOTE: The `request` package is no longer supported by the maintainer.
Dependency path: root → coveralls → request
got
@ 9.6.0
1 finding
medium
Trust 45/100
EPSS 2.2%
⚠ new maintainer
REVIEW
Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk.
Click for more →
Got allows a redirect to a UNIX socket
- major version bump requires human review (never auto-merge)
- trust veto: new maintainer added
Upgrade got from 9.6.0 to 11.8.5 or later
View advisoryBlast radius
Paths from project root to got - which dependencies pulled this package in?
form-data
@ 2.3.3
2 findings
critical–high
Trust 0/100
EPSS 1.7%
⚠ new maintainer
REVIEW
Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk.
Click for more →
form-data uses unsafe random function in form-data for choosing boundary
form-data: CRLF injection in form-data via unescaped multipart field names and filenames
- trust veto: new maintainer added
Upgrade form-data from 2.3.3 to 2.5.4 or later
View advisoryBlast radius
Paths from project root to form-data - which dependencies pulled this package in?
braces
@ 2.3.2
1 finding
high
Trust 0/100
EPSS 1.5%
⚠ new maintainer
REVIEW
Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk.
Click for more →
Uncontrolled resource consumption in braces
- major version bump requires human review (never auto-merge)
- trust veto: new maintainer added
Upgrade braces from 2.3.2 to 3.0.3 or later
View advisoryBlast radius
Paths from project root to braces - which dependencies pulled this package in?
micromatch
@ 3.1.10
1 finding
medium
Trust 0/100
EPSS 1.4%
⚠ new maintainer
REVIEW
Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk.
Click for more →
Regular Expression Denial of Service (ReDoS) in micromatch
- major version bump requires human review (never auto-merge)
- trust veto: new maintainer added
Upgrade micromatch from 3.1.10 to 4.0.8 or later
View advisoryBlast radius
Paths from project root to micromatch - which dependencies pulled this package in?
serialize-javascript
@ 6.0.0
3 findings
high–medium
Trust 0/100
EPSS 1.1%
REVIEW
Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk.
Click for more →
Serialize JavaScript is Vulnerable to RCE via RegExp.flags and Date.prototype.toISOString()
Serialize JavaScript has CPU Exhaustion Denial of Service via crafted array-like objects
Cross-site Scripting (XSS) in serialize-javascript
- major version bump requires human review (never auto-merge)
Upgrade serialize-javascript from 6.0.0 to 7.0.3 or later
View advisoryBlast radius
Paths from project root to serialize-javascript - which dependencies pulled this package in?
nanoid
@ 3.3.1
1 finding
medium
Trust 30/100
EPSS 0.7%
AUTO-MERGE
Verdict tier: the fix passes all three lenses cleanly. In Mode C, Arguss opens a pull request for the upgrade; it does not merge PRs on GitHub.
Click for more →
Predictable results in nanoid generation when given non-integer values
- patch-level upgrade; trust signals unchanged; CI verifies tests
Upgrade nanoid from 3.3.1 to 3.3.8 or later
View advisoryBlast radius
Paths from project root to nanoid - which dependencies pulled this package in?
diff
@ 5.0.0
1 finding
low
Trust 30/100
EPSS 0.6%
⚠ new maintainer
REVIEW
Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk.
Click for more →
jsdiff has a Denial of Service vulnerability in parsePatch and applyPatch
- trust veto: new maintainer added
Upgrade diff from 5.0.0 to 5.2.2 or later
View advisoryBlast radius
Paths from project root to diff - which dependencies pulled this package in?
minimatch
@ 4.2.1
3 findings
high
Trust 30/100
EPSS 0.5%
AUTO-MERGE
Verdict tier: the fix passes all three lenses cleanly. In Mode C, Arguss opens a pull request for the upgrade; it does not merge PRs on GitHub.
Click for more →
minimatch ReDoS: nested *() extglobs generate catastrophically backtracking regular expressions
minimatch has a ReDoS via repeated wildcards with non-matching literal in pattern
minimatch has ReDoS: matchOne() combinatorial backtracking via multiple non-adjacent GLOBSTAR segments
- patch-level upgrade; trust signals unchanged; CI verifies tests
Upgrade minimatch from 4.2.1 to 4.2.5 or later
View advisoryBlast radius
Paths from project root to minimatch - which dependencies pulled this package in?
js-yaml
@ 4.1.0
3 findings
high–medium
Trust 30/100
EPSS 0.4%
AUTO-MERGE
Verdict tier: the fix passes all three lenses cleanly. In Mode C, Arguss opens a pull request for the upgrade; it does not merge PRs on GitHub.
Click for more →
js-yaml: YAML merge-key chains can force quadratic CPU consumption
JS-YAML: Quadratic-complexity DoS in merge key handling via repeated aliases
js-yaml has prototype pollution in merge (<<)
- minor-level upgrade; trust signals unchanged; CI verifies tests
Upgrade js-yaml from 4.1.0 to 4.3.0 or later
View advisoryBlast radius
Paths from project root to js-yaml - which dependencies pulled this package in?
qs
@ 6.5.5
1 finding
low
Trust 0/100
EPSS 0.4%
AUTO-MERGE
Verdict tier: the fix passes all three lenses cleanly. In Mode C, Arguss opens a pull request for the upgrade; it does not merge PRs on GitHub.
Click for more →
qs's arrayLimit bypass in its bracket notation allows DoS via memory exhaustion
- minor-level upgrade; trust signals unchanged; CI verifies tests
Upgrade qs from 6.5.5 to 6.14.1 or later
View advisoryBlast radius
Paths from project root to qs - which dependencies pulled this package in?
uuid
@ 3.4.0
1 finding
high
Trust 0/100
EPSS 0.3%
REVIEW
Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk.
Click for more →
uuid: Missing buffer bounds check in v3/v5/v6 when buf is provided
- major version bump requires human review (never auto-merge)
Upgrade uuid from 3.4.0 to 11.1.1 or later
View advisoryBlast radius
Paths from project root to uuid - which dependencies pulled this package in?
Package status
778 packages scanned.
- 8 Review-required candidates Arguss flagged these for a human decision - nothing merges until you review them.
- 1 Package with no automated fix
- 4 Auto-merge candidates
-
- abort-controller 3.0.0 direct
- abortcontroller-polyfill 1.7.8 direct
- busboy 1.6.0 direct
- c8 7.14.0 direct
- chai 4.5.0 direct
- chai-as-promised 7.1.2 direct
- chai-iterator 3.0.2 direct
- chai-string 1.6.0 direct
- coveralls 3.1.1 direct
- data-uri-to-buffer 4.0.1 direct
- fetch-blob 3.2.0 direct
- form-data 4.0.6 direct
- formdata-node 4.4.1 direct
- formdata-polyfill 4.0.10 direct
- mocha 9.2.2 direct
- p-timeout 5.1.0 direct
- stream-consumers 1.0.2 direct
- tsd 0.14.0 direct
- xo 0.39.1 direct
- @babel/code-frame 7.12.11
- @babel/code-frame 7.29.7
- @babel/compat-data 7.29.7
- @babel/core 7.29.7
- @babel/eslint-parser 7.29.7
- @babel/generator 7.29.7
- @babel/helper-compilation-targets 7.29.7
- @babel/helper-globals 7.29.7
- @babel/helper-module-imports 7.29.7
- @babel/helper-module-transforms 7.29.7
- @babel/helper-string-parser 7.29.7
- @babel/helper-validator-identifier 7.29.7
- @babel/helper-validator-option 7.29.7
- @babel/helpers 7.29.7
- @babel/highlight 7.25.9
- @babel/parser 7.29.7
- @babel/template 7.29.7
- @babel/traverse 7.29.7
- @babel/types 7.29.7
- @bcoe/v8-coverage 0.2.3
- @eslint/eslintrc 0.4.3
- @humanwhocodes/config-array 0.5.0
- @humanwhocodes/object-schema 1.2.1
- @istanbuljs/schema 0.1.6
- @jridgewell/gen-mapping 0.3.13
- @jridgewell/remapping 2.3.5
- @jridgewell/resolve-uri 3.1.2
- @jridgewell/source-map 0.3.11
- @jridgewell/sourcemap-codec 1.5.5
- @jridgewell/trace-mapping 0.3.31
- @mrmlnc/readdir-enhanced 2.2.1
- @nicolo-ribaudo/eslint-scope-5-internals 5.1.1-v1
- @nodelib/fs.scandir 2.1.5
- @nodelib/fs.stat 1.1.3
- @nodelib/fs.stat 2.0.5
- @nodelib/fs.walk 1.2.8
- @rtsao/scc 1.1.0
- @sindresorhus/is 0.14.0
- @szmarczak/http-timer 1.1.2
- @types/eslint 7.29.0
- @types/estree 1.0.9
- @types/glob 7.2.0
- @types/istanbul-lib-coverage 2.0.6
- @types/json-schema 7.0.15
- @types/json5 0.0.29
- @types/minimatch 5.1.2
- @types/minimist 1.2.5
- @types/node 26.1.1
- @types/normalize-package-data 2.4.4
- @types/parse-json 4.0.2
- @typescript-eslint/eslint-plugin 4.33.0
- @typescript-eslint/experimental-utils 4.33.0
- @typescript-eslint/parser 4.33.0
- @typescript-eslint/scope-manager 4.33.0
- @typescript-eslint/types 4.33.0
- @typescript-eslint/typescript-estree 4.33.0
- @typescript-eslint/visitor-keys 4.33.0
- @ungap/promise-all-settled 1.1.2
- @webassemblyjs/ast 1.14.1
- @webassemblyjs/floating-point-hex-parser 1.13.2
- @webassemblyjs/helper-api-error 1.13.2
- @webassemblyjs/helper-buffer 1.14.1
- @webassemblyjs/helper-numbers 1.13.2
- @webassemblyjs/helper-wasm-bytecode 1.13.2
- @webassemblyjs/helper-wasm-section 1.14.1
- @webassemblyjs/ieee754 1.13.2
- @webassemblyjs/leb128 1.13.2
- @webassemblyjs/utf8 1.13.2
- @webassemblyjs/wasm-edit 1.14.1
- @webassemblyjs/wasm-gen 1.14.1
- @webassemblyjs/wasm-opt 1.14.1
- @webassemblyjs/wasm-parser 1.14.1
- @webassemblyjs/wast-printer 1.14.1
- @xtuc/ieee754 1.2.0
- @xtuc/long 4.2.2
- acorn 7.4.1
- acorn 8.17.0
- acorn-import-phases 1.0.4
- acorn-jsx 5.3.2
- ajv 6.15.0
- ajv 8.20.0
- ajv-formats 2.1.1
- ajv-keywords 5.1.0
- ansi-align 3.0.1
- ansi-colors 4.1.1
- ansi-escapes 4.3.2
- ansi-regex 5.0.1
- ansi-styles 3.2.1
- ansi-styles 4.3.0
- anymatch 3.1.3
- argparse 1.0.10
- argparse 2.0.1
- arr-diff 4.0.0
- arr-flatten 1.1.0
- arr-union 3.1.0
- array-buffer-byte-length 1.0.2
- array-includes 3.1.9
- array-union 1.0.2
- array-union 2.1.0
- array-uniq 1.0.3
- array-unique 0.3.2
- array.prototype.findlastindex 1.2.6
- array.prototype.flat 1.3.3
- array.prototype.flatmap 1.3.3
- arraybuffer.prototype.slice 1.0.4
- arrify 1.0.1
- arrify 2.0.1
- asn1 0.2.6
- assert-plus 1.0.0
- assertion-error 1.1.0
- assign-symbols 1.0.0
- astral-regex 2.0.0
- async-function 1.0.0
- asynckit 0.4.0
- at-least-node 1.0.0
- atob 2.1.2
- available-typed-arrays 1.0.7
- aws-sign2 0.7.0
- aws4 1.13.2
- balanced-match 1.0.2
- base 0.11.2
- baseline-browser-mapping 2.11.0
- bcrypt-pbkdf 1.0.2
- binary-extensions 2.3.0
- boxen 4.2.0
- boxen 5.1.2
- brace-expansion 1.1.16
- braces 3.0.3
- browser-stdout 1.3.1
- browserslist 4.28.6
- buf-compare 1.0.1
- buffer-from 1.1.2
- cache-base 1.0.1
- cacheable-request 6.1.0
- call-bind 1.0.9
- call-bind-apply-helpers 1.0.2
- call-bound 1.0.4
- call-me-maybe 1.0.2
- callsites 3.1.0
- camelcase 5.3.1
- camelcase 6.3.0
- camelcase-keys 6.2.2
- caniuse-lite 1.0.30001806
- caseless 0.12.0
- chalk 2.4.2
- chalk 3.0.0
- chalk 4.1.2
- check-error 1.0.3
- chokidar 3.5.3
- chrome-trace-event 1.0.4
- ci-info 2.0.0
- ci-info 3.9.0
- class-utils 0.3.6
- clean-regexp 1.0.0
- cli-boxes 2.2.1
- cliui 7.0.4
- clone-response 1.0.3
- collection-visit 1.0.0
- color-convert 1.9.3
- color-convert 2.0.1
- color-name 1.1.3
- color-name 1.1.4
- combined-stream 1.0.8
- commander 2.20.3
- commondir 1.0.1
- component-emitter 1.3.1
- concat-map 0.0.1
- configstore 5.0.1
- confusing-browser-globals 1.0.10
- convert-source-map 2.0.0
- copy-descriptor 0.1.1
- core-assert 0.2.1
- core-util-is 1.0.2
- cosmiconfig 7.1.0
- cross-spawn 7.0.6
- crypto-random-string 2.0.0
- dashdash 1.14.1
- data-view-buffer 1.0.2
- data-view-byte-length 1.0.2
- data-view-byte-offset 1.0.1
- debug 2.6.9
- debug 3.2.7
- debug 4.3.3
- decamelize 1.2.0
- decamelize 4.0.0
- decamelize-keys 1.1.1
- decode-uri-component 0.2.2
- decompress-response 3.3.0
- deep-eql 4.1.4
- deep-extend 0.6.0
- deep-is 0.1.4
- deep-strict-equal 0.2.0
- defer-to-connect 1.1.3
- define-data-property 1.1.4
- define-properties 1.2.1
- define-property 0.2.5
- define-property 1.0.0
- define-property 2.0.2
- delayed-stream 1.0.0
- dir-glob 2.2.2
- dir-glob 3.0.1
- doctrine 2.1.0
- doctrine 3.0.0
- dot-prop 5.3.0
- dunder-proto 1.0.1
- duplexer3 0.1.5
- ecc-jsbn 0.1.2
- electron-to-chromium 1.5.394
- emoji-regex 8.0.0
- end-of-stream 1.4.5
- enhance-visitors 1.0.0
- enhanced-resolve 0.9.1
- enhanced-resolve 5.24.3
- enquirer 2.4.1
- env-editor 0.4.2
- error-ex 1.3.4
- es-abstract 1.24.2
- es-abstract-get 1.0.0
- es-define-property 1.0.1
- es-errors 1.3.0
- es-module-lexer 2.3.1
- es-object-atoms 1.1.2
- es-set-tostringtag 2.1.0
- es-shim-unscopables 1.1.0
- es-to-primitive 1.3.4
- escalade 3.2.0
- escape-goat 2.1.1
- escape-string-regexp 1.0.5
- escape-string-regexp 4.0.0
- eslint 7.32.0
- eslint-config-prettier 8.10.2
- eslint-config-xo 0.36.0
- eslint-config-xo-typescript 0.39.0
- eslint-formatter-pretty 4.1.0
- eslint-import-resolver-node 0.3.10
- eslint-import-resolver-webpack 0.13.11
- eslint-module-utils 2.14.0
- eslint-plugin-ava 12.0.0
- eslint-plugin-es 3.0.1
- eslint-plugin-eslint-comments 3.2.0
- eslint-plugin-import 2.32.0
- eslint-plugin-no-use-extend-native 0.5.0
- eslint-plugin-node 11.1.0
- eslint-plugin-prettier 3.4.1
- eslint-plugin-promise 5.2.0
- eslint-plugin-unicorn 30.0.0
- eslint-rule-docs 1.1.235
- eslint-scope 5.1.1
- eslint-template-visitor 2.3.2
- eslint-utils 2.1.0
- eslint-utils 3.0.0
- eslint-visitor-keys 1.3.0
- eslint-visitor-keys 2.1.0
- espree 7.3.1
- esprima 4.0.1
- espurify 2.1.1
- esquery 1.7.0
- esrecurse 4.3.0
- estraverse 4.3.0
- estraverse 5.3.0
- esutils 2.0.3
- event-target-shim 5.0.1
- events 3.3.0
- execa 5.1.1
- expand-brackets 2.1.4
- extend 3.0.2
- extend-shallow 2.0.1
- extend-shallow 3.0.2
- extglob 2.0.4
- extsprintf 1.3.0
- fast-deep-equal 3.1.3
- fast-diff 1.3.0
- fast-glob 2.2.7
- fast-glob 3.3.3
- fast-json-stable-stringify 2.1.0
- fast-levenshtein 2.0.6
- fast-uri 3.1.4
- fastq 1.20.1
- file-entry-cache 6.0.1
- fill-range 4.0.0
- fill-range 7.1.1
- find-cache-dir 3.3.2
- find-root 1.1.0
- find-up 4.1.0
- find-up 5.0.0
- flat 5.0.2
- flat-cache 3.2.0
- flatted 3.4.2
- for-each 0.3.5
- for-in 1.0.2
- foreground-child 2.0.0
- forever-agent 0.6.1
- fragment-cache 0.2.1
- fs-extra 9.1.0
- fs.realpath 1.0.0
- fsevents 2.3.3
- function-bind 1.1.2
- function.prototype.name 1.2.0
- functional-red-black-tree 1.0.1
- functions-have-names 1.2.3
- generator-function 2.0.1
- gensync 1.0.0-beta.2
- get-caller-file 2.0.5
- get-func-name 2.0.2
- get-intrinsic 1.3.0
- get-proto 1.0.1
- get-set-props 0.1.0
- get-stdin 8.0.0
- get-stream 4.1.0
- get-stream 5.2.0
- get-stream 6.0.1
- get-symbol-description 1.1.0
- get-value 2.0.6
- getpass 0.1.7
- glob 7.2.0
- glob-parent 3.1.0
- glob-parent 5.1.2
- glob-to-regexp 0.3.0
- global-dirs 2.1.0
- global-dirs 3.0.1
- globals 13.24.0
- globalthis 1.0.4
- globby 11.1.0
- globby 9.2.0
- gopd 1.2.0
- graceful-fs 4.2.11
- growl 1.10.5
- har-schema 2.0.0
- har-validator 5.1.5
- hard-rejection 2.1.0
- has-bigints 1.1.0
- has-flag 3.0.0
- has-flag 4.0.0
- has-property-descriptors 1.0.2
- has-proto 1.2.0
- has-symbols 1.1.0
- has-tostringtag 1.0.2
- has-value 0.3.1
- has-value 1.0.0
- has-values 0.1.4
- has-values 1.0.0
- has-yarn 2.1.0
- hasown 2.0.4
- he 1.2.0
- hosted-git-info 2.8.9
- hosted-git-info 4.1.0
- html-escaper 2.0.2
- http-cache-semantics 4.2.0
- http-signature 1.2.0
- human-signals 2.1.0
- ignore 4.0.6
- ignore 5.3.2
- import-fresh 3.3.1
- import-lazy 2.1.0
- import-modules 2.1.0
- imurmurhash 0.1.4
- indent-string 4.0.0
- inflight 1.0.6
- inherits 2.0.4
- ini 1.3.7
- ini 2.0.0
- internal-slot 1.1.0
- interpret 1.4.0
- irregular-plurals 3.5.0
- is-absolute 1.0.0
- is-accessor-descriptor 1.0.2
- is-array-buffer 3.0.5
- is-arrayish 0.2.1
- is-async-function 2.1.1
- is-bigint 1.1.0
- is-binary-path 2.1.0
- is-boolean-object 1.2.2
- is-buffer 1.1.6
- is-callable 1.2.7
- is-ci 2.0.0
- is-core-module 2.16.2
- is-data-descriptor 1.0.1
- is-data-view 1.0.2
- is-date-object 1.1.0
- is-descriptor 0.1.8
- is-descriptor 1.0.4
- is-docker 2.2.1
- is-document.all 1.0.0
- is-error 2.2.2
- is-extendable 0.1.1
- is-extendable 1.0.1
- is-extglob 2.1.1
- is-finalizationregistry 1.1.1
- is-fullwidth-code-point 3.0.0
- is-generator-function 1.1.2
- is-get-set-prop 1.0.0
- is-glob 3.1.0
- is-glob 4.0.3
- is-installed-globally 0.3.2
- is-installed-globally 0.4.0
- is-js-type 2.0.0
- is-map 2.0.3
- is-negated-glob 1.0.0
- is-negative-zero 2.0.3
- is-npm 4.0.0
- is-npm 5.0.0
- is-number 3.0.0
- is-number 7.0.0
- is-number-object 1.1.1
- is-obj 2.0.0
- is-obj-prop 1.0.0
- is-path-inside 3.0.3
- is-plain-obj 1.1.0
- is-plain-obj 2.1.0
- is-plain-object 2.0.4
- is-proto-prop 2.0.0
- is-regex 1.2.1
- is-relative 1.0.0
- is-set 2.0.3
- is-shared-array-buffer 1.0.4
- is-stream 2.0.1
- is-string 1.1.1
- is-symbol 1.1.1
- is-typed-array 1.1.15
- is-typedarray 1.0.0
- is-unc-path 1.0.0
- is-unicode-supported 0.1.0
- is-weakmap 2.0.2
- is-weakref 1.1.1
- is-weakset 2.0.4
- is-windows 1.0.2
- is-wsl 2.2.0
- is-yarn-global 0.3.0
- isarray 1.0.0
- isarray 2.0.5
- isexe 2.0.0
- isobject 2.1.0
- isobject 3.0.1
- isstream 0.1.2
- istanbul-lib-coverage 3.2.2
- istanbul-lib-report 3.0.1
- istanbul-reports 3.2.0
- jest-worker 27.5.1
- js-tokens 4.0.0
- js-types 1.0.0
- js-yaml 3.15.0
- jsbn 0.1.1
- jsesc 3.1.0
- json-buffer 3.0.0
- json-buffer 3.0.1
- json-parse-even-better-errors 2.3.1
- json-schema 0.4.0
- json-schema-traverse 0.4.1
- json-schema-traverse 1.0.0
- json-stable-stringify-without-jsonify 1.0.1
- json-stringify-safe 5.0.1
- json5 1.0.2
- json5 2.2.3
- jsonfile 6.2.1
- jsprim 1.4.2
- keyv 3.1.0
- keyv 4.5.4
- kind-of 3.2.2
- kind-of 4.0.0
- kind-of 6.0.3
- latest-version 5.1.0
- lcov-parse 1.0.0
- levn 0.4.1
- line-column-path 2.0.0
- lines-and-columns 1.2.4
- loader-runner 4.3.2
- locate-path 5.0.0
- locate-path 6.0.0
- lodash 4.18.1
- lodash.merge 4.6.2
- lodash.truncate 4.4.2
- log-driver 1.2.7
- log-symbols 4.1.0
- loupe 2.3.7
- lowercase-keys 1.0.1
- lowercase-keys 2.0.0
- lru-cache 5.1.1
- lru-cache 6.0.0
- make-dir 3.1.0
- make-dir 4.0.0
- map-cache 0.2.2
- map-obj 1.0.1
- map-obj 4.3.0
- map-visit 1.0.0
- math-intrinsics 1.1.0
- memory-fs 0.2.0
- meow 7.1.1
- meow 9.0.0
- merge-stream 2.0.0
- merge2 1.4.1
- micro-spelling-correcter 1.1.1
- micromatch 4.0.8
- mime-db 1.52.0
- mime-db 1.54.0
- mime-types 2.1.35
- mimic-fn 2.1.0
- mimic-response 1.0.1
- min-indent 1.0.1
- minimatch 3.1.5
- minimist 1.2.8
- minimist-options 4.1.0
- minimizer-webpack-plugin 5.6.1
- mixin-deep 1.3.2
- ms 2.0.0
- ms 2.1.2
- ms 2.1.3
- multimap 1.1.0
- nanomatch 1.2.13
- natural-compare 1.4.0
- neo-async 2.6.2
- node-domexception 1.0.0
- node-exports-info 1.6.2
- node-releases 2.0.51
- normalize-package-data 2.5.0
- normalize-package-data 3.0.3
- normalize-path 3.0.0
- normalize-url 4.5.1
- npm-run-path 4.0.1
- oauth-sign 0.9.0
- obj-props 1.4.0
- object-copy 0.1.0
- object-inspect 1.13.4
- object-keys 1.1.1
- object-visit 1.0.1
- object.assign 4.1.7
- object.entries 1.1.9
- object.fromentries 2.0.8
- object.groupby 1.0.3
- object.pick 1.3.0
- object.values 1.2.1
- once 1.4.0
- onetime 5.1.2
- open 7.4.2
- open-editor 3.0.0
- optionator 0.9.4
- own-keys 1.0.2
- p-cancelable 1.1.0
- p-limit 2.3.0
- p-limit 3.1.0
- p-locate 4.1.0
- p-locate 5.0.0
- p-reduce 2.1.0
- p-try 2.2.0
- package-json 6.5.0
- parent-module 1.0.1
- parse-json 5.2.0
- pascalcase 0.1.1
- path-dirname 1.0.2
- path-exists 4.0.0
- path-is-absolute 1.0.1
- path-key 3.1.1
- path-parse 1.0.7
- path-type 3.0.0
- path-type 4.0.0
- pathval 1.1.1
- performance-now 2.1.0
- picocolors 1.1.1
- picomatch 2.3.2
- pify 3.0.0
- pify 4.0.1
- pkg-dir 4.2.0
- pkg-dir 5.0.0
- plur 4.0.0
- pluralize 8.0.0
- posix-character-classes 0.1.1
- possible-typed-array-names 1.1.0
- prelude-ls 1.2.1
- prepend-http 2.0.0
- prettier 2.8.8
- prettier-linter-helpers 1.0.1
- progress 2.0.3
- proto-props 2.0.0
- psl 1.15.0
- pump 3.0.4
- punycode 2.3.1
- pupa 2.1.1
- queue-microtask 1.2.3
- quick-lru 4.0.1
- randombytes 2.1.0
- rc 1.2.8
- read-pkg 5.2.0
- read-pkg-up 7.0.1
- readdirp 3.6.0
- redent 3.0.0
- reflect.getprototypeof 1.0.10
- regex-not 1.0.2
- regexp-tree 0.1.27
- regexp.prototype.flags 1.5.4
- regexpp 3.2.0
- registry-auth-token 4.2.2
- registry-url 5.1.0
- repeat-element 1.1.4
- repeat-string 1.6.1
- require-directory 2.1.1
- require-from-string 2.0.2
- reserved-words 0.1.2
- resolve 1.22.12
- resolve 2.0.0-next.7
- resolve-cwd 3.0.0
- resolve-from 4.0.0
- resolve-from 5.0.0
- resolve-url 0.2.1
- responselike 1.0.2
- ret 0.1.15
- reusify 1.1.0
- rimraf 3.0.2
- run-parallel 1.2.0
- safe-array-concat 1.1.4
- safe-buffer 5.2.1
- safe-push-apply 1.0.0
- safe-regex 1.1.0
- safe-regex 2.1.1
- safe-regex-test 1.1.0
- safer-buffer 2.1.2
- schema-utils 4.3.3
- semver 5.7.2
- semver 6.3.1
- semver 7.8.5
- semver-diff 3.1.1
- set-function-length 1.2.2
- set-function-name 2.0.2
- set-proto 1.0.0
- set-value 2.0.1
- shebang-command 2.0.0
- shebang-regex 3.0.0
- side-channel 1.1.1
- side-channel-list 1.0.1
- side-channel-map 1.0.1
- side-channel-weakmap 1.0.2
- signal-exit 3.0.7
- slash 2.0.0
- slash 3.0.0
- slice-ansi 4.0.0
- snapdragon 0.8.2
- snapdragon-node 2.1.1
- snapdragon-util 3.0.1
- source-map 0.5.7
- source-map 0.6.1
- source-map-resolve 0.5.3
- source-map-support 0.5.21
- source-map-url 0.4.1
- spdx-correct 3.2.0
- spdx-exceptions 2.5.0
- spdx-expression-parse 3.0.1
- spdx-license-ids 3.0.23
- split-string 3.1.0
- sprintf-js 1.0.3
- sshpk 1.18.0
- static-extend 0.1.2
- stop-iteration-iterator 1.1.0
- streamsearch 1.1.0
- string-width 4.2.3
- string.prototype.trim 1.2.11
- string.prototype.trimend 1.0.10
- string.prototype.trimstart 1.0.8
- strip-ansi 6.0.1
- strip-bom 3.0.0
- strip-final-newline 2.0.0
- strip-indent 3.0.0
- strip-json-comments 2.0.1
- strip-json-comments 3.1.1
- supports-color 5.5.0
- supports-color 7.2.0
- supports-color 8.1.1
- supports-hyperlinks 2.3.0
- supports-preserve-symlinks-flag 1.0.0
- table 6.9.0
- tapable 0.1.10
- tapable 2.3.3
- term-size 2.2.1
- terser 5.49.0
- test-exclude 6.0.0
- text-table 0.2.0
- to-absolute-glob 2.0.2
- to-object-path 0.3.0
- to-readable-stream 1.0.0
- to-regex 3.0.2
- to-regex-range 2.1.1
- to-regex-range 5.0.1
- trim-newlines 3.0.1
- tsconfig-paths 3.15.0
- tslib 1.14.1
- tsutils 3.21.0
- tunnel-agent 0.6.0
- tweetnacl 0.14.5
- type-check 0.4.0
- type-detect 4.1.0
- type-fest 0.13.1
- type-fest 0.18.1
- type-fest 0.20.2
- type-fest 0.21.3
- type-fest 0.4.1
- type-fest 0.6.0
- type-fest 0.8.1
- typed-array-buffer 1.0.3
- typed-array-byte-length 1.0.3
- typed-array-byte-offset 1.0.4
- typed-array-length 1.0.8
- typedarray-to-buffer 3.1.5
- typescript 4.9.5
- unbox-primitive 1.1.0
- unc-path-regex 0.1.2
- undici-types 8.3.0
- union-value 1.0.1
- unique-string 2.0.0
- universalify 2.0.1
- unset-value 1.0.0
- update-browserslist-db 1.2.3
- update-notifier 4.1.3
- update-notifier 5.1.0
- uri-js 4.4.1
- urix 0.1.0
- url-parse-lax 3.0.0
- use 3.1.1
- v8-compile-cache 2.4.0
- v8-to-istanbul 9.3.0
- validate-npm-package-license 3.0.4
- verror 1.10.0
- watchpack 2.5.2
- web-streams-polyfill 3.3.3
- web-streams-polyfill 4.0.0-beta.3
- webpack 5.108.4
- webpack-sources 3.5.1
- which 2.0.2
- which-boxed-primitive 1.1.1
- which-builtin-type 1.2.1
- which-collection 1.0.2
- which-typed-array 1.1.22
- widest-line 3.1.0
- word-wrap 1.2.5
- workerpool 6.2.0
- wrap-ansi 7.0.0
- wrappy 1.0.2
- write-file-atomic 3.0.3
- xdg-basedir 4.0.0
- y18n 5.0.8
- yallist 3.1.1
- yallist 4.0.0
- yaml 1.10.3
- yargs 16.2.0
- yargs 16.2.2
- yargs-parser 18.1.3
- yargs-parser 20.2.4
- yargs-parser 20.2.9
- yargs-unparser 2.0.0
- yocto-queue 0.1.0
Review auto-merge candidates and open PRs in a guided flow.
Glossary
What the labels and signals mean.
Glossary
What the labels and signals mean.
- Trust Save
- A package upgrade Arguss would have blocked despite the new version being available, because trust signals, like ownership transfer or a new maintainer, fired during the upgrade window. The name reflects what the agent did for the user: saved them from a potentially malicious update that a version-only auto-PR tool would have merged.
- AUTO-MERGE
- Verdict tier indicating the fix passes all three lenses cleanly. After you confirm action from a Scan assessment, Arguss opens a pull request for the upgrade; it does not merge PRs on GitHub. The envelope is conservative on purpose: patch or minor version bump, trust signals unchanged, blast radius bounded, real tests pass.
- REVIEW
- Verdict tier requiring a human decision. At least one veto fired during fix-confidence evaluation, trust signals shifted, the pipeline can't verify post-upgrade behavior, or the upgrade is a major version bump. The agent surfaces the reasons; the developer decides.
- DECLINE
- Verdict tier indicating no remediation is recommended. Typically applies when no fix version exists for the finding, or when multiple critical vetoes make even human review unproductive.
fix_kind.major- Veto signal that fires when the available fix requires a major version bump (1.x → 2.x). Major bumps imply potential breaking changes and fall outside the auto-merge envelope by default, even when the upgrade is the only available fix.
trust.new_maintainer- Veto signal that fires when a package added a new maintainer during the upgrade window, meaning between the user's current version and the proposed upgrade. New publishing identities are a well-documented attack vector for typosquats and supply chain takeovers.
trust.ownership_transferred- Veto signal that fires when a package's primary maintainer changed during the upgrade window. Combined with
trust.new_maintainer, this is the highest-risk trust combination, typical of the xz-utils style attacks and historical npm credential theft incidents. pipeline.test_reality- Veto signal that fires when Arguss can't verify tests will run on the upgraded code. Four conditions must hold: a test script exists in
package.json, it isn't a no-op, real test files exist, and a workflow actually invokes them. If any fail, the fix cannot qualify for AUTO_MERGE because there's no way to verify the upgrade didn't break the user's project. - CVSS
- Common Vulnerability Scoring System. A numeric score (0.0–10.0) representing how damaging a vulnerability could be if exploited. Sourced from NIST's National Vulnerability Database via OSV.dev. Severity, not urgency.
- EPSS
- Exploit Prediction Scoring System. A daily-updated probability (0.0–1.0, displayed as percent) that a CVE will be exploited in the next 30 days. Sourced from FIRST.org. Probability, not severity.
- KEV
- CISA's Known Exploited Vulnerabilities catalog. A federal list of CVEs with documented active exploitation in the wild. Federal agencies have a binding patching deadline; for everyone else, presence on KEV is the strongest "this is being used right now" signal available. Sourced directly from CISA.
- Project Risk Score (PRS)
- A weighted blend of the three lens subscores (40% vulnerability, 30% trust, 30% pipeline) producing an overall 0–100 indicator of the project's dependency health. Useful for at-a-glance triage; the per-finding fix-confidence verdicts are what drive automated decisions.
Dependency graph
Full-project map of transitive dependencies. Severity colors reflect vulnerabilities; trust rings apply only to direct dependencies analyzed by OpenSSF Scorecard (higher = riskier).