Skip to content

Conversation

@orm-vulnerabilityscanner
Copy link

@orm-vulnerabilityscanner orm-vulnerabilityscanner commented Jul 27, 2025

This Pull Request was created to address Low or greater security vulnerabilities as idenitified by Dependabot.

Updates to examples/widget/package-lock.json

This pull request contains updates to examples/widget/package-lock.json. If you do not wish to accept one or more of these changes, please close the Dependabot issue. The vulnerabillity patcher will then update this pull request the next time it runs against this repository.

👍 This pull request only regenerated the file referenced above. No other updates were applied.

Package Vulnerable Versions Message Issue Severity Scope Status
nanoid < 3.3.8
>= 4.0.0 < 5.0.9
Addressed by lock regeneration Issue 24 Moderate Runtime
next >= 13.0 < 14.2.30
>= 15.0.0 < 15.2.2
Addressed by lock regeneration Issue 27 Low Runtime
next >= 0.9.9 < 14.2.31
>= 15.0.0 <= 15.4.4
Addressed by lock regeneration Issue 39 Moderate Runtime
next >= 0.9.9 < 14.2.31
>= 15.0.0 <= 15.4.4
Addressed by lock regeneration Issue 41 Moderate Runtime
next >= 0.9.9 < 14.2.32
>= 15.0.0-canary.0 < 15.4.7
Addressed by lock regeneration Issue 42 Moderate Runtime
js-yaml < 3.14.2
>= 4.0.0 < 4.1.1
Addressed by lock regeneration Issue 62 Moderate Development

⚠️ NOTE: This pull request failed to address the following vulnerabilities. You can still merge this pull request, but will need to take other steps to resolve these vulnerabilities.

Package Vulnerable Versions Message Issue Severity Scope Status
glob >= 10.2.0 < 10.5.0
>= 11.0.0 < 11.1.0
Not adding override for "@next/eslint-plugin-next@14.2.5" Issue 66 High Development
Operations
[2025-11-28T19:04:01.834Z]	Reset package-lock.json
[2025-11-28T19:04:23.486Z]	Created package-lock.json
[2025-11-28T19:04:23.547Z]	Not adding override for "@next/eslint-plugin-next@14.2.5"

Updates to web/package-lock.json

This pull request contains updates to web/package-lock.json. If you do not wish to accept one or more of these changes, please close the Dependabot issue. The vulnerabillity patcher will then update this pull request the next time it runs against this repository.

👍 This pull request only regenerated the file referenced above. No other updates were applied.

Package Vulnerable Versions Message Issue Severity Scope Status
brace-expansion >= 1.0.0 <= 1.1.11
>= 2.0.0 <= 2.0.1
= 3.0.0
= 4.0.0
Addressed by lock regeneration Issue 28 Low Runtime
next >= 0.9.9 < 14.2.31
>= 15.0.0 <= 15.4.4
Addressed by lock regeneration Issue 33 Moderate Runtime
next >= 0.9.9 < 14.2.31
>= 15.0.0 <= 15.4.4
Addressed by lock regeneration Issue 34 Moderate Runtime
next >= 0.9.9 < 14.2.32
>= 15.0.0-canary.0 < 15.4.7
Addressed by lock regeneration Issue 35 Moderate Runtime
playwright < 1.55.1 Addressed by lock regeneration Issue 51 High Development
js-yaml < 3.14.2
>= 4.0.0 < 4.1.1
Addressed by lock regeneration Issue 61 Moderate Development
js-yaml < 3.14.2
>= 4.0.0 < 4.1.1
Addressed by lock regeneration Issue 63 Moderate Development

⚠️ NOTE: This pull request failed to address the following vulnerabilities. You can still merge this pull request, but will need to take other steps to resolve these vulnerabilities.

Package Vulnerable Versions Message Issue Severity Scope Status
glob >= 10.2.0 < 10.5.0
>= 11.0.0 < 11.1.0
Not adding override for "npm@10.9.4" Issue 67 High Runtime
glob >= 10.2.0 < 10.5.0
>= 11.0.0 < 11.1.0
Not adding override for "@npmcli/map-workspaces@4.0.2" Issue 67 High Runtime
glob >= 10.2.0 < 10.5.0
>= 11.0.0 < 11.1.0
Not adding override for "@npmcli/package-json@6.2.0" Issue 67 High Runtime
glob >= 10.2.0 < 10.5.0
>= 11.0.0 < 11.1.0
Not adding override for "cacache@19.0.1" Issue 67 High Runtime
glob >= 10.2.0 < 10.5.0
>= 11.0.0 < 11.1.0
Not adding override for "@next/eslint-plugin-next@14.2.33" Issue 67 High Runtime
Operations
[2025-11-28T19:04:23.550Z]	Reset package-lock.json
[2025-11-28T19:06:01.658Z]	Created package-lock.json
[2025-11-28T19:06:02.115Z]	Not adding override for "npm@10.9.4"
[2025-11-28T19:06:02.115Z]	Not adding override for "@npmcli/map-workspaces@4.0.2"
[2025-11-28T19:06:02.115Z]	Not adding override for "@npmcli/package-json@6.2.0"
[2025-11-28T19:06:02.115Z]	Not adding override for "cacache@19.0.1"
[2025-11-28T19:06:02.115Z]	Not adding override for "@next/eslint-plugin-next@14.2.33"

@orm-vulnerabilityscanner orm-vulnerabilityscanner added the maintenance Relates to project upkeep or maintenance label Jul 27, 2025
@orm-vulnerabilityscanner orm-vulnerabilityscanner force-pushed the orm-vulnerability-patcher/patches-low branch 23 times, most recently from 0fbc11f to 542ba08 Compare August 4, 2025 00:35
@orm-vulnerabilityscanner orm-vulnerabilityscanner force-pushed the orm-vulnerability-patcher/patches-low branch 6 times, most recently from a0f0f87 to d042d6c Compare August 5, 2025 12:38
@orm-vulnerabilityscanner orm-vulnerabilityscanner force-pushed the orm-vulnerability-patcher/patches-low branch 21 times, most recently from 3781445 to 0461e02 Compare November 26, 2025 19:16
@orm-vulnerabilityscanner orm-vulnerabilityscanner force-pushed the orm-vulnerability-patcher/patches-low branch 7 times, most recently from e85eef7 to fba5823 Compare November 28, 2025 13:03
@orm-vulnerabilityscanner orm-vulnerabilityscanner force-pushed the orm-vulnerability-patcher/patches-low branch from fba5823 to bd47838 Compare November 28, 2025 19:06
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

maintenance Relates to project upkeep or maintenance

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant