Skip to content

fix: package.json & yarn.lock to reduce vulnerabilities

9cb43c1
Select commit
Loading
Failed to load commit list.
Open

[Snyk] Security upgrade lodash from 4.17.20 to 4.17.23 #26

fix: package.json & yarn.lock to reduce vulnerabilities
9cb43c1
Select commit
Loading
Failed to load commit list.
Mend Bolt for GitHub / WhiteSource Security Check failed Jan 28, 2026 in 4m 12s

Security Report

You have successfully remediated 31 vulnerabilities, but introduced 28 new vulnerabilities in this branch.

❌ New vulnerabilities:

Vulnerability Severity CVSS Score Vulnerable Library Direct Library Suggested Fix Issue
CVE-2021-42740

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> npm-run-all-4.1.5.tgz (Root Library)

   -> ❌ shell-quote-1.6.1.tgz (Vulnerable Library)

Critical 9.8 Transitive shell-quote-1.6.1.tgz npm-run-all-4.1.5.tgz Transitive 1.7.3 None
CVE-2024-48949

Path to dependency file: /server/package.json

Path to vulnerable library: /server/package.json

Dependency Hierarchy:

-> bitcoinjs-message-2.0.0.tgz (Root Library)

   -> secp256k1-3.7.0.tgz

     -> ❌ elliptic-6.4.1.tgz (Vulnerable Library)

Critical 9.1 Transitive elliptic-6.4.1.tgz bitcoinjs-message-2.0.0.tgz Transitive 6.5.6 None
CVE-2023-46233

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> ❌ crypto-js-3.1.9-1.tgz (Vulnerable Library)

Critical 9.1 Direct crypto-js-3.1.9-1.tgz crypto-js-3.1.9-1.tgz crypto-js - 4.2.0 None
WS-2025-0006

Path to dependency file: /server/package.json

Path to vulnerable library: /server/package.json

Dependency Hierarchy:

-> bitcoinjs-message-2.0.0.tgz (Root Library)

   -> secp256k1-3.7.0.tgz

     -> ❌ elliptic-6.4.1.tgz (Vulnerable Library)

High 8.6 Transitive elliptic-6.4.1.tgz bitcoinjs-message-2.0.0.tgz Transitive 6.6.1 None
CVE-2020-13822

Path to dependency file: /server/package.json

Path to vulnerable library: /server/package.json

Dependency Hierarchy:

-> bitcoinjs-message-2.0.0.tgz (Root Library)

   -> secp256k1-3.7.0.tgz

     -> ❌ elliptic-6.4.1.tgz (Vulnerable Library)

High 7.7 Transitive elliptic-6.4.1.tgz bitcoinjs-message-2.0.0.tgz Transitive 6.5.3 None
CVE-2025-27611

Path to dependency file: /server/package.json

Path to vulnerable library: /server/package.json

Dependency Hierarchy:

-> bitcoinjs-message-2.0.0.tgz (Root Library)

   -> bs58check-2.1.2.tgz

     -> bs58-4.0.1.tgz

       -> ❌ base-x-3.0.5.tgz (Vulnerable Library)

High 7.5 Transitive base-x-3.0.5.tgz bitcoinjs-message-2.0.0.tgz Transitive 3.0.11 None
CVE-2025-15284

Path to dependency file: /server/package.json

Path to vulnerable library: /server/package.json

Dependency Hierarchy:

-> express-4.16.4.tgz (Root Library)

   -> ❌ qs-6.5.2.tgz (Vulnerable Library)

High 7.5 Transitive qs-6.5.2.tgz express-4.16.4.tgz Transitive 6.14.1 None
CVE-2024-48930

Path to dependency file: /server/package.json

Path to vulnerable library: /server/package.json

Dependency Hierarchy:

-> bitcoinjs-message-2.0.0.tgz (Root Library)

   -> ❌ secp256k1-3.7.0.tgz (Vulnerable Library)

High 7.5 Transitive secp256k1-3.7.0.tgz bitcoinjs-message-2.0.0.tgz Transitive secp256k1 - 5.0.1,secp256k1 - 3.8.1,secp256k1 - 4.0.4 None
CVE-2024-45590

Path to dependency file: /server/package.json

Path to vulnerable library: /server/package.json

Dependency Hierarchy:

-> express-4.16.4.tgz (Root Library)

   -> ❌ body-parser-1.18.3.tgz (Vulnerable Library)

High 7.5 Transitive body-parser-1.18.3.tgz express-4.16.4.tgz Transitive 1.20.3 None
CVE-2022-31129

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> ❌ moment-2.24.0.tgz (Vulnerable Library)

High 7.5 Direct moment-2.24.0.tgz moment-2.24.0.tgz 2.29.4 None
CVE-2022-24999

Path to dependency file: /server/package.json

Path to vulnerable library: /server/package.json

Dependency Hierarchy:

-> express-4.16.4.tgz (Root Library)

   -> ❌ qs-6.5.2.tgz (Vulnerable Library)

High 7.5 Transitive qs-6.5.2.tgz express-4.16.4.tgz Transitive 6.5.3 None
CVE-2022-24785

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> ❌ moment-2.24.0.tgz (Vulnerable Library)

High 7.5 Direct moment-2.24.0.tgz moment-2.24.0.tgz 2.29.2 None
CVE-2020-28498

Path to dependency file: /server/package.json

Path to vulnerable library: /server/package.json

Dependency Hierarchy:

-> bitcoinjs-message-2.0.0.tgz (Root Library)

   -> secp256k1-3.7.0.tgz

     -> ❌ elliptic-6.4.1.tgz (Vulnerable Library)

Medium 6.8 Transitive elliptic-6.4.1.tgz bitcoinjs-message-2.0.0.tgz Transitive 6.5.4 None
CVE-2024-29041

Path to dependency file: /server/package.json

Path to vulnerable library: /server/package.json

Dependency Hierarchy:

-> ❌ express-4.16.4.tgz (Vulnerable Library)

Medium 6.1 Direct express-4.16.4.tgz express-4.16.4.tgz 4.19.0 None
WS-2019-0427

Path to dependency file: /server/package.json

Path to vulnerable library: /server/package.json

Dependency Hierarchy:

-> bitcoinjs-message-2.0.0.tgz (Root Library)

   -> secp256k1-3.7.0.tgz

     -> ❌ elliptic-6.4.1.tgz (Vulnerable Library)

Medium 5.9 Transitive elliptic-6.4.1.tgz bitcoinjs-message-2.0.0.tgz Transitive 6.5.2 None
WS-2019-0424

Path to dependency file: /server/package.json

Path to vulnerable library: /server/package.json

Dependency Hierarchy:

-> bitcoinjs-message-2.0.0.tgz (Root Library)

   -> secp256k1-3.7.0.tgz

     -> ❌ elliptic-6.4.1.tgz (Vulnerable Library)

Medium 5.9 Transitive elliptic-6.4.1.tgz bitcoinjs-message-2.0.0.tgz Transitive 6.5.3 None
CVE-2025-14505

Path to dependency file: /server/package.json

Path to vulnerable library: /server/package.json

Dependency Hierarchy:

-> bitcoinjs-message-2.0.0.tgz (Root Library)

   -> secp256k1-3.7.0.tgz

     -> ❌ elliptic-6.4.1.tgz (Vulnerable Library)

Medium 5.6 Transitive elliptic-6.4.1.tgz bitcoinjs-message-2.0.0.tgz None
CVE-2024-47764

Path to dependency file: /server/package.json

Path to vulnerable library: /server/package.json

Dependency Hierarchy:

-> express-4.16.4.tgz (Root Library)

   -> ❌ cookie-0.3.1.tgz (Vulnerable Library)

Medium 5.3 Transitive cookie-0.3.1.tgz express-4.16.4.tgz Transitive 0.7.0 None
CVE-2024-42461

Path to dependency file: /server/package.json

Path to vulnerable library: /server/package.json

Dependency Hierarchy:

-> bitcoinjs-message-2.0.0.tgz (Root Library)

   -> secp256k1-3.7.0.tgz

     -> ❌ elliptic-6.4.1.tgz (Vulnerable Library)

Medium 5.3 Transitive elliptic-6.4.1.tgz bitcoinjs-message-2.0.0.tgz Transitive elliptic - 6.5.7,elliptic - 6.5.7 None
CVE-2024-42460

Path to dependency file: /server/package.json

Path to vulnerable library: /server/package.json

Dependency Hierarchy:

-> bitcoinjs-message-2.0.0.tgz (Root Library)

   -> secp256k1-3.7.0.tgz

     -> ❌ elliptic-6.4.1.tgz (Vulnerable Library)

Medium 5.3 Transitive elliptic-6.4.1.tgz bitcoinjs-message-2.0.0.tgz Transitive elliptic - 6.5.7,elliptic - 6.5.7 None
CVE-2024-42459

Path to dependency file: /server/package.json

Path to vulnerable library: /server/package.json

Dependency Hierarchy:

-> bitcoinjs-message-2.0.0.tgz (Root Library)

   -> secp256k1-3.7.0.tgz

     -> ❌ elliptic-6.4.1.tgz (Vulnerable Library)

Medium 5.3 Transitive elliptic-6.4.1.tgz bitcoinjs-message-2.0.0.tgz Transitive elliptic - 6.5.7,elliptic - 6.5.7 None
CVE-2022-25883

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> npm-run-all-4.1.5.tgz (Root Library)

   -> read-pkg-3.0.0.tgz

     -> normalize-package-data-2.5.0.tgz

       -> ❌ semver-5.7.0.tgz (Vulnerable Library)

Medium 5.3 Transitive semver-5.7.0.tgz npm-run-all-4.1.5.tgz Transitive 5.7.2 None
CVE-2021-23362

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> npm-run-all-4.1.5.tgz (Root Library)

   -> read-pkg-3.0.0.tgz

     -> normalize-package-data-2.5.0.tgz

       -> ❌ hosted-git-info-2.7.1.tgz (Vulnerable Library)

Medium 5.3 Transitive hosted-git-info-2.7.1.tgz npm-run-all-4.1.5.tgz Transitive 2.8.9 None
CVE-2020-36732

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> ❌ crypto-js-3.1.9-1.tgz (Vulnerable Library)

Medium 5.3 Direct crypto-js-3.1.9-1.tgz crypto-js-3.1.9-1.tgz crypto-js - 3.2.1,crypto-js - 3.2.1 None
CVE-2024-43800

Path to dependency file: /server/package.json

Path to vulnerable library: /server/package.json

Dependency Hierarchy:

-> express-4.16.4.tgz (Root Library)

   -> ❌ serve-static-1.13.2.tgz (Vulnerable Library)

Medium 5.0 Transitive serve-static-1.13.2.tgz express-4.16.4.tgz Transitive 1.16.0 None
CVE-2024-43799

Path to dependency file: /server/package.json

Path to vulnerable library: /server/package.json

Dependency Hierarchy:

-> express-4.16.4.tgz (Root Library)

   -> ❌ send-0.16.2.tgz (Vulnerable Library)

Medium 5.0 Transitive send-0.16.2.tgz express-4.16.4.tgz Transitive 0.19.0 None
CVE-2024-43796

Path to dependency file: /server/package.json

Path to vulnerable library: /server/package.json

Dependency Hierarchy:

-> ❌ express-4.16.4.tgz (Vulnerable Library)

Medium 5.0 Direct express-4.16.4.tgz express-4.16.4.tgz 4.20.0 None
CVE-2024-48948

Path to dependency file: /server/package.json

Path to vulnerable library: /server/package.json

Dependency Hierarchy:

-> bitcoinjs-message-2.0.0.tgz (Root Library)

   -> secp256k1-3.7.0.tgz

     -> ❌ elliptic-6.4.1.tgz (Vulnerable Library)

Medium 4.8 Transitive elliptic-6.4.1.tgz bitcoinjs-message-2.0.0.tgz Transitive elliptic - 6.6.0 None

✔️ Remediated vulnerabilities:

Vulnerability Vulnerable Library
CVE-2025-14505 elliptic-6.5.3.tgz
CVE-2020-28469 glob-parent-3.1.0.tgz
CVE-2021-44906 minimist-1.2.5.tgz
CVE-2017-16137 debug-3.2.6.tgz
CVE-2025-13465 lodash-4.17.20.tgz
CVE-2021-23362 hosted-git-info-2.8.8.tgz
CVE-2024-47764 cookie-0.4.0.tgz
CVE-2021-3807 ansi-regex-3.0.0.tgz
CVE-2020-28498 elliptic-6.5.3.tgz
WS-2025-0006 elliptic-6.5.3.tgz
CVE-2021-23337 lodash-4.17.20.tgz
CVE-2024-43799 send-0.17.1.tgz
CVE-2022-25883 semver-5.7.1.tgz
CVE-2022-33987 got-6.7.1.tgz
CVE-2024-48930 secp256k1-3.8.0.tgz
CVE-2024-29041 express-4.17.1.tgz
CVE-2020-28500 lodash-4.17.20.tgz
CVE-2025-27611 base-x-3.0.8.tgz
CVE-2022-24785 moment-2.27.0.tgz
CVE-2022-31129 moment-2.27.0.tgz
CVE-2024-43800 serve-static-1.14.1.tgz
CVE-2024-21538 cross-spawn-5.1.0.tgz
CVE-2024-42460 elliptic-6.5.3.tgz
CVE-2022-38900 decode-uri-component-0.2.0.tgz
CVE-2021-42740 shell-quote-1.7.2.tgz
CVE-2024-42461 elliptic-6.5.3.tgz
CVE-2020-7788 ini-1.3.5.tgz
CVE-2024-42459 elliptic-6.5.3.tgz
CVE-2024-48948 elliptic-6.5.3.tgz
CVE-2024-43796 express-4.17.1.tgz
CVE-2024-48949 elliptic-6.5.3.tgz

Base branch total remaining vulnerabilities: 42
Base branch commit: null


Total libraries scanned: 174

Scan token: cbab00946cb3421792c78da39a1791a0