Findings
lodash
@ 4.17.21
3 findings
high–medium
Trust 0/100
EPSS 22.4% ↑
AUTO-MERGE
Verdict tier: the fix passes all three lenses cleanly. In Mode C, Arguss opens a pull request for the upgrade; it does not merge PRs on GitHub.
Click for more →
lodash vulnerable to Prototype Pollution via array path bypass in `_.unset` and `_.omit`
Lodash has Prototype Pollution Vulnerability in `_.unset` and `_.omit` functions
- minor-level upgrade; trust signals unchanged; CI verifies tests
Upgrade lodash from 4.17.21 to 4.18.0 or later
View advisoryBlast radius
Paths from project root to lodash - which dependencies pulled this package in?
ws
@ 7.5.9
2 findings
high
Trust 0/100
EPSS 1.4%
AUTO-MERGE
Verdict tier: the fix passes all three lenses cleanly. In Mode C, Arguss opens a pull request for the upgrade; it does not merge PRs on GitHub.
Click for more →
ws affected by a DoS when handling a request with many HTTP headers
ws: Memory exhaustion DoS from tiny fragments and data chunks
- patch-level upgrade; trust signals unchanged; CI verifies tests
Upgrade ws from 7.5.9 to 7.5.10 or later
View advisoryBlast radius
Paths from project root to ws - which dependencies pulled this package in?
shell-quote
@ 1.8.1
2 findings
high
Trust 0/100
EPSS 0.8%
AUTO-MERGE
Verdict tier: the fix passes all three lenses cleanly. In Mode C, Arguss opens a pull request for the upgrade; it does not merge PRs on GitHub.
Click for more →
shell-quote quote() does not escape newlines in object .op values
shell-quote: Quadratic-complexity Denial of Service in `parse()` (CWE-407)
- minor-level upgrade; trust signals unchanged; CI verifies tests
Upgrade shell-quote from 1.8.1 to 1.8.4 or later
View advisoryBlast radius
Paths from project root to shell-quote - which dependencies pulled this package in?
minimatch
@ 3.1.2
3 findings
high
Trust 30/100
EPSS 0.5%
AUTO-MERGE
Verdict tier: the fix passes all three lenses cleanly. In Mode C, Arguss opens a pull request for the upgrade; it does not merge PRs on GitHub.
Click for more →
minimatch ReDoS: nested *() extglobs generate catastrophically backtracking regular expressions
minimatch has a ReDoS via repeated wildcards with non-matching literal in pattern
minimatch has ReDoS: matchOne() combinatorial backtracking via multiple non-adjacent GLOBSTAR segments
- patch-level upgrade; trust signals unchanged; CI verifies tests
Upgrade minimatch from 3.1.2 to 3.1.4 or later
View advisoryBlast radius
Paths from project root to minimatch - which dependencies pulled this package in?
@babel/helpers
@ 7.23.6
1 finding
medium
Trust 0/100
EPSS 0.5%
AUTO-MERGE
Verdict tier: the fix passes all three lenses cleanly. In Mode C, Arguss opens a pull request for the upgrade; it does not merge PRs on GitHub.
Click for more →
Babel has inefficient RegExp complexity in generated code with .replace when transpiling named capturing groups
- minor-level upgrade; trust signals unchanged; CI verifies tests
Upgrade @babel/helpers from 7.23.6 to 7.26.10 or later
View advisoryBlast radius
Paths from project root to @babel/helpers - which dependencies pulled this package in?
yaml
@ 1.10.2
1 finding
medium
Trust 30/100
EPSS 0.5%
AUTO-MERGE
Verdict tier: the fix passes all three lenses cleanly. In Mode C, Arguss opens a pull request for the upgrade; it does not merge PRs on GitHub.
Click for more →
yaml is vulnerable to Stack Overflow via deeply nested YAML collections
- patch-level upgrade; trust signals unchanged; CI verifies tests
Upgrade yaml from 1.10.2 to 1.10.3 or later
View advisoryBlast radius
Paths from project root to yaml - which dependencies pulled this package in?
brace-expansion
@ 1.1.11
3 findings
medium–low
Trust 0/100
EPSS 0.5%
AUTO-MERGE
Verdict tier: the fix passes all three lenses cleanly. In Mode C, Arguss opens a pull request for the upgrade; it does not merge PRs on GitHub.
Click for more →
brace-expansion: Zero-step sequence causes process hang and memory exhaustion
brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups
brace-expansion Regular Expression Denial of Service vulnerability
- patch-level upgrade; trust signals unchanged; CI verifies tests
Upgrade brace-expansion from 1.1.11 to 1.1.13 or later
View advisoryBlast radius
Paths from project root to brace-expansion - which dependencies pulled this package in?
uuid
@ 8.3.2
1 finding
high
Trust 0/100
EPSS 0.3%
REVIEW
Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk.
Click for more →
uuid: Missing buffer bounds check in v3/v5/v6 when buf is provided
- major version bump requires human review (never auto-merge)
Upgrade uuid from 8.3.2 to 11.1.1 or later
View advisoryBlast radius
Paths from project root to uuid - which dependencies pulled this package in?
@babel/core
@ 7.23.6
1 finding
low
Trust 0/100
EPSS 0.1%
AUTO-MERGE
Verdict tier: the fix passes all three lenses cleanly. In Mode C, Arguss opens a pull request for the upgrade; it does not merge PRs on GitHub.
Click for more →
@babel/core: Arbitrary File Read via sourceMappingURL Comment
- minor-level upgrade; trust signals unchanged; CI verifies tests
Upgrade @babel/core from 7.23.6 to 7.29.6 or later
View advisoryBlast radius
Paths from project root to @babel/core - which dependencies pulled this package in?
Package status
786 packages scanned.
- 1 Review-required candidate Arguss flagged these for a human decision - nothing merges until you review them.
- 8 Auto-merge candidates
-
- @npmcli/eslint-config 7.0.0 direct
- @npmcli/template-oss 5.0.0 direct
- benchmark 2.1.4 direct
- tap 16.3.10 direct
- @actions/core 2.0.3
- @actions/exec 2.0.0
- @actions/http-client 3.0.2
- @actions/io 2.0.0
- @ampproject/remapping 2.2.1
- @babel/code-frame 7.23.5
- @babel/code-frame 7.29.7
- @babel/compat-data 7.23.5
- @babel/compat-data 7.29.7
- @babel/core 7.29.7
- @babel/generator 7.23.6
- @babel/generator 7.29.7
- @babel/helper-annotate-as-pure 7.22.5
- @babel/helper-compilation-targets 7.23.6
- @babel/helper-compilation-targets 7.29.7
- @babel/helper-environment-visitor 7.22.20
- @babel/helper-function-name 7.23.0
- @babel/helper-globals 7.29.7
- @babel/helper-hoist-variables 7.22.5
- @babel/helper-module-imports 7.22.15
- @babel/helper-module-imports 7.29.7
- @babel/helper-module-transforms 7.23.3
- @babel/helper-module-transforms 7.29.7
- @babel/helper-plugin-utils 7.22.5
- @babel/helper-simple-access 7.22.5
- @babel/helper-split-export-declaration 7.22.6
- @babel/helper-string-parser 7.23.4
- @babel/helper-string-parser 7.29.7
- @babel/helper-validator-identifier 7.22.20
- @babel/helper-validator-identifier 7.29.7
- @babel/helper-validator-option 7.23.5
- @babel/helper-validator-option 7.29.7
- @babel/helpers 7.29.7
- @babel/highlight 7.23.4
- @babel/parser 7.23.6
- @babel/parser 7.29.7
- @babel/plugin-proposal-object-rest-spread 7.20.7
- @babel/plugin-syntax-jsx 7.23.3
- @babel/plugin-syntax-object-rest-spread 7.8.3
- @babel/plugin-transform-destructuring 7.23.3
- @babel/plugin-transform-parameters 7.23.3
- @babel/plugin-transform-react-jsx 7.23.4
- @babel/template 7.22.15
- @babel/template 7.29.7
- @babel/traverse 7.23.6
- @babel/traverse 7.29.7
- @babel/types 7.23.6
- @babel/types 7.29.7
- @commitlint/cli 20.5.3
- @commitlint/config-conventional 20.5.3
- @commitlint/config-validator 20.5.0
- @commitlint/ensure 20.5.3
- @commitlint/execute-rule 20.0.0
- @commitlint/format 20.5.0
- @commitlint/is-ignored 20.5.0
- @commitlint/lint 20.5.3
- @commitlint/load 20.5.3
- @commitlint/message 20.4.3
- @commitlint/parse 20.5.0
- @commitlint/read 20.5.0
- @commitlint/resolve-extends 20.5.3
- @commitlint/rules 20.5.3
- @commitlint/to-lines 20.0.0
- @commitlint/top-level 20.4.3
- @commitlint/types 20.5.0
- @conventional-changelog/git-client 2.7.0
- @conventional-commits/parser 0.4.1
- @eslint-community/eslint-utils 4.9.1
- @eslint-community/regexpp 4.12.2
- @eslint/eslintrc 2.1.4
- @eslint/js 8.57.1
- @gar/promise-retry 1.0.3
- @google-automations/git-file-utils 3.0.0
- @humanwhocodes/config-array 0.13.0
- @humanwhocodes/module-importer 1.0.1
- @humanwhocodes/object-schema 2.0.3
- @iarna/toml 3.0.0
- @isaacs/fs-minipass 4.0.1
- @isaacs/import-jsx 4.0.1
- @isaacs/string-locale-compare 1.1.0
- @istanbuljs/load-nyc-config 1.1.0
- @istanbuljs/schema 0.1.6
- @jridgewell/gen-mapping 0.3.13
- @jridgewell/gen-mapping 0.3.3
- @jridgewell/remapping 2.3.5
- @jridgewell/resolve-uri 3.1.1
- @jridgewell/resolve-uri 3.1.2
- @jridgewell/set-array 1.1.2
- @jridgewell/sourcemap-codec 1.4.15
- @jridgewell/sourcemap-codec 1.5.5
- @jridgewell/trace-mapping 0.3.20
- @jridgewell/trace-mapping 0.3.31
- @jsep-plugin/assignment 1.3.0
- @jsep-plugin/regex 1.0.4
- @nodelib/fs.scandir 2.1.5
- @nodelib/fs.stat 2.0.5
- @nodelib/fs.walk 1.2.8
- @npmcli/agent 4.0.2
- @npmcli/arborist 9.9.0
- @npmcli/fs 5.0.0
- @npmcli/git 7.0.2
- @npmcli/installed-package-contents 4.0.0
- @npmcli/map-workspaces 5.0.3
- @npmcli/metavuln-calculator 9.0.3
- @npmcli/name-from-folder 4.0.0
- @npmcli/node-gyp 5.0.0
- @npmcli/package-json 7.0.5
- @npmcli/promise-spawn 9.0.1
- @npmcli/query 5.0.0
- @npmcli/redact 4.0.0
- @npmcli/run-script 10.0.4
- @octokit/auth-token 4.0.0
- @octokit/auth-token 6.0.0
- @octokit/core 5.2.2
- @octokit/core 7.0.6
- @octokit/endpoint 11.0.3
- @octokit/endpoint 9.0.6
- @octokit/graphql 7.1.1
- @octokit/graphql 9.0.3
- @octokit/openapi-types 24.2.0
- @octokit/openapi-types 27.0.0
- @octokit/plugin-paginate-rest 11.4.4-cjs.2
- @octokit/plugin-paginate-rest 14.0.0
- @octokit/plugin-request-log 4.0.1
- @octokit/plugin-request-log 6.0.0
- @octokit/plugin-rest-endpoint-methods 13.3.2-cjs.1
- @octokit/plugin-rest-endpoint-methods 17.0.0
- @octokit/request 10.0.11
- @octokit/request 8.4.1
- @octokit/request-error 5.1.1
- @octokit/request-error 7.1.0
- @octokit/rest 20.1.2
- @octokit/rest 22.0.1
- @octokit/types 13.10.0
- @octokit/types 16.0.0
- @rtsao/scc 1.1.0
- @sigstore/bundle 4.0.0
- @sigstore/core 3.2.1
- @sigstore/protobuf-specs 0.5.1
- @sigstore/sign 4.1.1
- @sigstore/tuf 4.0.2
- @sigstore/verify 3.1.1
- @simple-libs/child-process-utils 1.0.2
- @simple-libs/stream-utils 1.2.0
- @tufjs/canonical-json 2.0.0
- @tufjs/models 4.1.0
- @types/json5 0.0.29
- @types/minimist 1.2.5
- @types/node 26.1.1
- @types/normalize-package-data 2.4.4
- @types/npm-package-arg 6.1.4
- @types/prop-types 15.7.11
- @types/react 17.0.73
- @types/scheduler 0.16.8
- @types/unist 2.0.11
- @types/yargs 16.0.11
- @types/yargs-parser 21.0.3
- @types/yoga-layout 1.9.2
- @typescript/typescript-aix-ppc64 7.0.2
- @typescript/typescript-darwin-arm64 7.0.2
- @typescript/typescript-darwin-x64 7.0.2
- @typescript/typescript-freebsd-arm64 7.0.2
- @typescript/typescript-freebsd-x64 7.0.2
- @typescript/typescript-linux-arm 7.0.2
- @typescript/typescript-linux-arm64 7.0.2
- @typescript/typescript-linux-loong64 7.0.2
- @typescript/typescript-linux-mips64el 7.0.2
- @typescript/typescript-linux-ppc64 7.0.2
- @typescript/typescript-linux-riscv64 7.0.2
- @typescript/typescript-linux-s390x 7.0.2
- @typescript/typescript-linux-x64 7.0.2
- @typescript/typescript-netbsd-arm64 7.0.2
- @typescript/typescript-netbsd-x64 7.0.2
- @typescript/typescript-openbsd-arm64 7.0.2
- @typescript/typescript-openbsd-x64 7.0.2
- @typescript/typescript-sunos-x64 7.0.2
- @typescript/typescript-win32-arm64 7.0.2
- @typescript/typescript-win32-x64 7.0.2
- @ungap/structured-clone 1.3.3
- @xmldom/xmldom 0.8.13
- abbrev 4.0.0
- acorn 8.17.0
- acorn-jsx 5.3.2
- agent-base 7.1.4
- aggregate-error 3.1.0
- ajv 6.15.0
- ajv 8.20.0
- ansi-escapes 4.3.2
- ansi-regex 5.0.1
- ansi-styles 3.2.1
- ansi-styles 4.3.0
- ansicolors 0.3.2
- anymatch 3.1.3
- append-transform 2.0.0
- archy 1.0.0
- argparse 1.0.10
- argparse 2.0.1
- array-buffer-byte-length 1.0.2
- array-ify 1.0.0
- array-includes 3.1.9
- array.prototype.findlastindex 1.2.6
- array.prototype.flat 1.3.3
- array.prototype.flatmap 1.3.3
- arraybuffer.prototype.slice 1.0.4
- arrify 1.0.1
- astral-regex 2.0.0
- async-function 1.0.0
- async-hook-domain 2.0.4
- async-retry 1.3.3
- auto-bind 4.0.0
- available-typed-arrays 1.0.7
- balanced-match 1.0.2
- balanced-match 4.0.4
- baseline-browser-mapping 2.11.0
- before-after-hook 2.2.3
- before-after-hook 4.0.0
- bin-links 6.0.2
- binary-extensions 2.3.0
- bind-obj-methods 3.0.0
- boolbase 1.0.0
- brace-expansion 1.1.16
- brace-expansion 2.1.2
- brace-expansion 5.0.7
- braces 3.0.3
- browserslist 4.22.2
- browserslist 4.28.6
- buffer-from 1.1.2
- cacache 20.0.4
- caching-transform 4.0.0
- call-bind 1.0.9
- call-bind-apply-helpers 1.0.2
- call-bound 1.0.4
- caller-callsite 4.1.0
- caller-path 3.0.1
- callsites 3.1.0
- camelcase 5.3.1
- camelcase-keys 6.2.2
- caniuse-lite 1.0.30001570
- caniuse-lite 1.0.30001806
- cardinal 2.1.1
- chalk 2.4.2
- chalk 3.0.0
- chalk 4.1.2
- chokidar 3.6.0
- chownr 3.0.0
- ci-info 2.0.0
- clean-stack 2.2.0
- cli-boxes 2.2.1
- cli-cursor 3.1.0
- cli-truncate 2.1.0
- cliui 6.0.0
- cliui 7.0.4
- cliui 8.0.1
- cmd-shim 8.0.0
- code-excerpt 3.0.0
- code-suggester 5.0.1
- color-convert 1.9.3
- color-convert 2.0.1
- color-name 1.1.3
- color-name 1.1.4
- color-support 1.1.3
- common-ancestor-path 2.0.0
- commondir 1.0.1
- compare-func 2.0.0
- concat-map 0.0.1
- content-type 2.0.0
- conventional-changelog-angular 8.3.1
- conventional-changelog-conventionalcommits 6.1.0
- conventional-changelog-conventionalcommits 9.3.1
- conventional-changelog-writer 6.0.1
- conventional-commits-filter 3.0.0
- conventional-commits-parser 6.4.0
- convert-source-map 1.9.0
- convert-source-map 2.0.0
- convert-to-spaces 1.0.2
- cosmiconfig 9.0.2
- cosmiconfig-typescript-loader 6.3.0
- cross-spawn 7.0.6
- css-select 5.2.2
- css-what 6.2.2
- cssesc 3.0.0
- csstype 3.1.3
- data-view-buffer 1.0.2
- data-view-byte-length 1.0.2
- data-view-byte-offset 1.0.1
- dateformat 3.0.3
- debug 3.2.7
- debug 4.3.4
- debug 4.4.3
- decamelize 1.2.0
- decamelize-keys 1.1.1
- dedent 1.7.2
- deep-is 0.1.4
- default-require-extensions 3.0.1
- define-data-property 1.1.4
- define-properties 1.2.1
- deprecation 2.3.1
- detect-indent 6.1.0
- diff 4.0.4
- diff 8.0.4
- doctrine 2.1.0
- doctrine 3.0.0
- dom-serializer 2.0.0
- domelementtype 2.3.0
- domhandler 5.0.3
- domutils 3.2.2
- dot-prop 5.3.0
- dunder-proto 1.0.1
- electron-to-chromium 1.4.614
- electron-to-chromium 1.5.394
- emoji-regex 8.0.0
- entities 4.5.0
- env-paths 2.2.1
- error-ex 1.3.4
- es-abstract 1.24.2
- es-abstract-get 1.0.0
- es-define-property 1.0.1
- es-errors 1.3.0
- es-object-atoms 1.1.2
- es-set-tostringtag 2.1.0
- es-shim-unscopables 1.1.0
- es-to-primitive 1.3.4
- es-toolkit 1.49.0
- es6-error 4.1.1
- escalade 3.1.1
- escalade 3.2.0
- escape-string-regexp 1.0.5
- escape-string-regexp 2.0.0
- escape-string-regexp 4.0.0
- eslint 8.57.1
- eslint-import-resolver-node 0.3.10
- eslint-module-utils 2.14.0
- eslint-plugin-es 3.0.1
- eslint-plugin-import 2.32.0
- eslint-plugin-node 11.1.0
- eslint-plugin-promise 6.6.0
- eslint-scope 7.2.2
- eslint-utils 2.1.0
- eslint-visitor-keys 1.3.0
- eslint-visitor-keys 3.4.3
- espree 9.6.1
- esprima 4.0.1
- esquery 1.7.0
- esrecurse 4.3.0
- estraverse 5.3.0
- esutils 2.0.3
- events-to-array 1.1.2
- exponential-backoff 3.1.3
- fast-deep-equal 3.1.3
- fast-json-stable-stringify 2.1.0
- fast-levenshtein 2.0.6
- fast-uri 3.1.4
- fastq 1.20.1
- fdir 6.5.0
- figures 3.2.0
- file-entry-cache 6.0.1
- fill-range 7.1.1
- find-cache-dir 3.3.2
- find-up 4.1.0
- find-up 5.0.0
- findit 2.0.0
- flat-cache 3.2.0
- flatted 3.4.2
- for-each 0.3.5
- foreground-child 2.0.0
- fromentries 1.3.2
- fs-exists-cached 1.0.0
- fs-minipass 3.0.3
- fs.realpath 1.0.0
- fsevents 2.3.3
- function-bind 1.1.2
- function-loop 2.0.1
- function.prototype.name 1.2.0
- functions-have-names 1.2.3
- generator-function 2.0.1
- gensync 1.0.0-beta.2
- get-caller-file 2.0.5
- get-intrinsic 1.3.0
- get-package-type 0.1.0
- get-proto 1.0.1
- get-symbol-description 1.1.0
- git-raw-commits 5.0.1
- glob 13.0.6
- glob 7.2.3
- glob-parent 5.1.2
- glob-parent 6.0.2
- global-directory 5.0.0
- globals 11.12.0
- globals 13.24.0
- globalthis 1.0.4
- gopd 1.2.0
- graceful-fs 4.2.11
- graphemer 1.4.0
- handlebars 4.7.9
- hard-rejection 2.1.0
- has-bigints 1.1.0
- has-flag 3.0.0
- has-flag 4.0.0
- has-property-descriptors 1.0.2
- has-proto 1.2.0
- has-symbols 1.1.0
- has-tostringtag 1.0.2
- hasha 5.2.2
- hasown 2.0.4
- he 1.2.0
- hosted-git-info 2.8.9
- hosted-git-info 4.1.0
- hosted-git-info 9.0.3
- html-escaper 2.0.2
- http-cache-semantics 4.2.0
- http-proxy-agent 7.0.2
- https-proxy-agent 7.0.6
- iconv-lite 0.7.3
- ignore 5.3.2
- ignore-walk 8.0.0
- import-fresh 3.3.1
- import-meta-resolve 4.2.0
- imurmurhash 0.1.4
- indent-string 4.0.0
- inflight 1.0.6
- inherits 2.0.4
- ini 6.0.0
- ink 3.2.0
- internal-slot 1.1.0
- ip-address 10.2.0
- is-array-buffer 3.0.5
- is-arrayish 0.2.1
- is-async-function 2.1.1
- is-bigint 1.1.0
- is-binary-path 2.1.0
- is-boolean-object 1.2.2
- is-callable 1.2.7
- is-ci 2.0.0
- is-core-module 2.16.2
- is-data-view 1.0.2
- is-date-object 1.1.0
- is-document.all 1.0.0
- is-extglob 2.1.1
- is-finalizationregistry 1.1.1
- is-fullwidth-code-point 3.0.0
- is-generator-function 1.1.2
- is-glob 4.0.3
- is-map 2.0.3
- is-negative-zero 2.0.3
- is-number 7.0.0
- is-number-object 1.1.1
- is-obj 2.0.0
- is-path-inside 3.0.3
- is-plain-obj 1.1.0
- is-plain-obj 4.1.0
- is-regex 1.2.1
- is-set 2.0.3
- is-shared-array-buffer 1.0.4
- is-stream 2.0.1
- is-string 1.1.1
- is-symbol 1.1.1
- is-typed-array 1.1.15
- is-typedarray 1.0.0
- is-weakmap 2.0.2
- is-weakref 1.1.1
- is-weakset 2.0.4
- is-windows 1.0.2
- isarray 2.0.5
- isexe 2.0.0
- isexe 4.0.0
- istanbul-lib-coverage 3.2.2
- istanbul-lib-hook 3.0.0
- istanbul-lib-instrument 4.0.3
- istanbul-lib-processinfo 2.0.3
- istanbul-lib-report 3.0.1
- istanbul-lib-source-maps 4.0.1
- istanbul-reports 3.2.0
- jackspeak 1.4.2
- jiti 2.6.1
- js-tokens 4.0.0
- js-yaml 3.15.0
- js-yaml 4.3.0
- jsep 1.4.0
- jsesc 2.5.2
- jsesc 3.1.0
- json-buffer 3.0.1
- json-parse-even-better-errors 2.3.1
- json-parse-even-better-errors 5.0.0
- json-schema-traverse 0.4.1
- json-schema-traverse 1.0.0
- json-stable-stringify-without-jsonify 1.0.1
- json-stringify-nice 1.1.4
- json-stringify-safe 5.0.1
- json-with-bigint 3.5.10
- json5 1.0.2
- json5 2.2.3
- jsonparse 1.3.1
- jsonpath-plus 10.4.0
- just-deep-map-values 1.2.0
- just-diff 6.0.2
- just-diff-apply 5.5.0
- just-omit 2.2.0
- keyv 4.5.4
- kind-of 6.0.3
- levn 0.4.1
- libtap 1.4.1
- lines-and-columns 1.2.4
- locate-path 5.0.0
- locate-path 6.0.0
- lodash 4.18.1
- lodash.flattendeep 4.4.0
- lodash.ismatch 4.4.0
- lodash.merge 4.6.2
- loose-envify 1.4.0
- lru-cache 11.5.2
- lru-cache 5.1.1
- lru-cache 6.0.0
- make-dir 3.1.0
- make-dir 4.0.0
- make-fetch-happen 15.0.6
- map-obj 1.0.1
- map-obj 4.3.0
- math-intrinsics 1.1.0
- meow 13.2.0
- meow 8.1.2
- mimic-fn 2.1.0
- min-indent 1.0.1
- minimatch 10.2.5
- minimatch 3.1.5
- minimatch 5.1.9
- minimist 1.2.8
- minimist-options 4.1.0
- minipass 3.3.6
- minipass 7.1.3
- minipass-collect 2.0.1
- minipass-fetch 5.0.2
- minipass-flush 1.0.7
- minipass-pipeline 1.2.4
- minipass-sized 2.0.0
- minizlib 3.1.0
- mkdirp 1.0.4
- modify-values 1.0.1
- ms 2.1.2
- ms 2.1.3
- natural-compare 1.4.0
- negotiator 1.0.0
- neo-async 2.6.2
- node-exports-info 1.6.2
- node-gyp 12.4.0
- node-html-parser 6.1.13
- node-preload 0.2.1
- node-releases 2.0.14
- node-releases 2.0.51
- nopt 9.0.0
- normalize-package-data 2.5.0
- normalize-package-data 3.0.3
- normalize-path 3.0.0
- npm-bundled 5.0.0
- npm-install-checks 8.0.0
- npm-normalize-package-bin 5.0.0
- npm-package-arg 13.0.2
- npm-packlist 10.0.4
- npm-pick-manifest 11.0.3
- npm-registry-fetch 19.1.1
- nth-check 2.1.1
- nyc 15.1.0
- object-assign 4.1.1
- object-inspect 1.13.4
- object-keys 1.1.1
- object.assign 4.1.7
- object.entries 1.1.9
- object.fromentries 2.0.8
- object.groupby 1.0.3
- object.values 1.2.1
- once 1.4.0
- onetime 5.1.2
- opener 1.5.2
- optionator 0.9.4
- own-keys 1.0.2
- own-or 1.0.0
- own-or-env 1.0.2
- p-limit 2.3.0
- p-limit 3.1.0
- p-locate 4.1.0
- p-locate 5.0.0
- p-map 3.0.0
- p-map 7.0.6
- p-try 2.2.0
- package-hash 4.0.0
- pacote 21.5.1
- parent-module 1.0.1
- parse-conflict-json 5.0.1
- parse-diff 0.11.1
- parse-github-repo-url 1.4.1
- parse-json 5.2.0
- patch-console 1.0.0
- path-exists 4.0.0
- path-is-absolute 1.0.1
- path-key 3.1.1
- path-parse 1.0.7
- path-scurry 2.0.2
- picocolors 1.0.0
- picocolors 1.1.1
- picomatch 2.3.2
- picomatch 4.0.5
- pkg-dir 4.2.0
- platform 1.3.6
- possible-typed-array-names 1.1.0
- postcss-selector-parser 7.1.4
- prelude-ls 1.2.1
- proc-log 6.1.0
- process-on-spawn 1.1.0
- proggy 4.0.0
- promise-all-reject-late 1.0.1
- promise-call-limit 3.0.2
- punycode 2.3.1
- queue-microtask 1.2.3
- quick-lru 4.0.1
- react 17.0.2
- react-devtools-core 4.28.5
- react-reconciler 0.26.2
- read-cmd-shim 6.0.0
- read-pkg 5.2.0
- read-pkg-up 7.0.1
- readdirp 3.6.0
- redent 3.0.0
- redeyed 2.1.1
- reflect.getprototypeof 1.0.10
- regexp.prototype.flags 1.5.4
- regexpp 3.2.0
- release-please 17.3.0
- release-zalgo 1.0.0
- require-directory 2.1.1
- require-from-string 2.0.2
- require-main-filename 2.0.0
- resolve 1.22.12
- resolve 2.0.0-next.7
- resolve-from 3.0.0
- resolve-from 4.0.0
- resolve-from 5.0.0
- restore-cursor 3.1.0
- retry 0.13.1
- reusify 1.1.0
- rimraf 3.0.2
- run-parallel 1.2.0
- safe-array-concat 1.1.4
- safe-push-apply 1.0.0
- safe-regex-test 1.1.0
- safer-buffer 2.1.2
- scheduler 0.20.2
- semver 5.7.2
- semver 6.3.1
- semver 7.8.5
- set-blocking 2.0.0
- set-function-length 1.2.2
- set-function-name 2.0.2
- set-proto 1.0.0
- shebang-command 2.0.0
- shebang-regex 3.0.0
- side-channel 1.1.1
- side-channel-list 1.0.1
- side-channel-map 1.0.1
- side-channel-weakmap 1.0.2
- signal-exit 3.0.7
- signal-exit 4.1.0
- sigstore 4.1.1
- slice-ansi 3.0.0
- smart-buffer 4.2.0
- socks 2.8.9
- socks-proxy-agent 8.0.5
- source-map 0.6.1
- source-map-support 0.5.21
- spawn-wrap 2.0.0
- spdx-correct 3.2.0
- spdx-exceptions 2.5.0
- spdx-expression-parse 3.0.1
- spdx-expression-parse 4.0.0
- spdx-license-ids 3.0.23
- split 1.0.1
- sprintf-js 1.0.3
- ssri 13.0.1
- stack-utils 2.0.6
- stop-iteration-iterator 1.1.0
- string-width 4.2.3
- string.prototype.trim 1.2.11
- string.prototype.trimend 1.0.10
- string.prototype.trimstart 1.0.8
- strip-ansi 6.0.1
- strip-bom 3.0.0
- strip-bom 4.0.0
- strip-indent 3.0.0
- strip-json-comments 3.1.1
- supports-color 5.5.0
- supports-color 7.2.0
- supports-preserve-symlinks-flag 1.0.0
- tap-mocha-reporter 5.0.4
- tap-parser 11.0.2
- tap-yaml 1.0.2
- tar 7.5.20
- tcompare 5.0.7
- test-exclude 6.0.0
- text-table 0.2.0
- through 2.3.8
- tinyexec 1.2.4
- tinyglobby 0.2.17
- to-fast-properties 2.0.0
- to-regex-range 5.0.1
- treeverse 3.0.0
- treport 3.0.4
- trim-newlines 3.0.1
- trivial-deferred 1.1.2
- tsconfig-paths 3.15.0
- tuf-js 4.1.0
- tunnel 0.0.6
- type-check 0.4.0
- type-fest 0.12.0
- type-fest 0.18.1
- type-fest 0.20.2
- type-fest 0.21.3
- type-fest 0.6.0
- type-fest 0.8.1
- type-fest 3.13.1
- typed-array-buffer 1.0.3
- typed-array-byte-length 1.0.3
- typed-array-byte-offset 1.0.4
- typed-array-length 1.0.8
- typedarray-to-buffer 3.1.5
- typescript 4.9.5
- typescript 7.0.2
- uglify-js 3.19.3
- unbox-primitive 1.1.0
- undici 6.27.0
- undici-types 8.3.0
- unicode-length 2.1.0
- unist-util-is 4.1.0
- unist-util-visit 2.0.3
- unist-util-visit-parents 3.1.1
- universal-user-agent 6.0.1
- universal-user-agent 7.0.3
- update-browserslist-db 1.0.13
- update-browserslist-db 1.2.3
- uri-js 4.4.1
- util-deprecate 1.0.2
- validate-npm-package-license 3.0.4
- validate-npm-package-name 7.0.2
- walk-up-path 4.0.0
- which 2.0.2
- which 6.0.1
- which 7.0.0
- which-boxed-primitive 1.1.1
- which-builtin-type 1.2.1
- which-collection 1.0.2
- which-module 2.0.1
- which-typed-array 1.1.22
- widest-line 3.1.0
- word-wrap 1.2.5
- wordwrap 1.0.0
- wrap-ansi 6.2.0
- wrap-ansi 7.0.0
- wrappy 1.0.2
- write-file-atomic 3.0.3
- write-file-atomic 7.0.1
- xpath 0.0.34
- y18n 4.0.3
- y18n 5.0.8
- yallist 3.1.1
- yallist 4.0.0
- yallist 5.0.0
- yaml 1.10.3
- yaml 2.9.0
- yargs 15.4.1
- yargs 16.2.2
- yargs 17.7.3
- yargs-parser 18.1.3
- yargs-parser 20.2.9
- yargs-parser 21.1.1
- yocto-queue 0.1.0
- yoga-layout-prebuilt 1.10.0
Review auto-merge candidates and open PRs in a guided flow.
Glossary
What the labels and signals mean.
Glossary
What the labels and signals mean.
- Trust Save
- A package upgrade Arguss would have blocked despite the new version being available, because trust signals, like ownership transfer or a new maintainer, fired during the upgrade window. The name reflects what the agent did for the user: saved them from a potentially malicious update that a version-only auto-PR tool would have merged.
- AUTO-MERGE
- Verdict tier indicating the fix passes all three lenses cleanly. After you confirm action from a Scan assessment, Arguss opens a pull request for the upgrade; it does not merge PRs on GitHub. The envelope is conservative on purpose: patch or minor version bump, trust signals unchanged, blast radius bounded, real tests pass.
- REVIEW
- Verdict tier requiring a human decision. At least one veto fired during fix-confidence evaluation, trust signals shifted, the pipeline can't verify post-upgrade behavior, or the upgrade is a major version bump. The agent surfaces the reasons; the developer decides.
- DECLINE
- Verdict tier indicating no remediation is recommended. Typically applies when no fix version exists for the finding, or when multiple critical vetoes make even human review unproductive.
fix_kind.major- Veto signal that fires when the available fix requires a major version bump (1.x → 2.x). Major bumps imply potential breaking changes and fall outside the auto-merge envelope by default, even when the upgrade is the only available fix.
trust.new_maintainer- Veto signal that fires when a package added a new maintainer during the upgrade window, meaning between the user's current version and the proposed upgrade. New publishing identities are a well-documented attack vector for typosquats and supply chain takeovers.
trust.ownership_transferred- Veto signal that fires when a package's primary maintainer changed during the upgrade window. Combined with
trust.new_maintainer, this is the highest-risk trust combination, typical of the xz-utils style attacks and historical npm credential theft incidents. pipeline.test_reality- Veto signal that fires when Arguss can't verify tests will run on the upgraded code. Four conditions must hold: a test script exists in
package.json, it isn't a no-op, real test files exist, and a workflow actually invokes them. If any fail, the fix cannot qualify for AUTO_MERGE because there's no way to verify the upgrade didn't break the user's project. - CVSS
- Common Vulnerability Scoring System. A numeric score (0.0–10.0) representing how damaging a vulnerability could be if exploited. Sourced from NIST's National Vulnerability Database via OSV.dev. Severity, not urgency.
- EPSS
- Exploit Prediction Scoring System. A daily-updated probability (0.0–1.0, displayed as percent) that a CVE will be exploited in the next 30 days. Sourced from FIRST.org. Probability, not severity.
- KEV
- CISA's Known Exploited Vulnerabilities catalog. A federal list of CVEs with documented active exploitation in the wild. Federal agencies have a binding patching deadline; for everyone else, presence on KEV is the strongest "this is being used right now" signal available. Sourced directly from CISA.
- Project Risk Score (PRS)
- A weighted blend of the three lens subscores (40% vulnerability, 30% trust, 30% pipeline) producing an overall 0–100 indicator of the project's dependency health. Useful for at-a-glance triage; the per-finding fix-confidence verdicts are what drive automated decisions.
Dependency graph
Full-project map of transitive dependencies. Severity colors reflect vulnerabilities; trust rings apply only to direct dependencies analyzed by OpenSSF Scorecard (higher = riskier).