Skip to content

Conversation

@wiz-5e8b1019be
Copy link

Wiz Remediation Pull Request Banner

Wiz has created this PR to fix 111 findings detected in this project

Changes were made to the following file(s):

  • package.json
  • packages/react-router-native/android/build.gradle
  • website/package.json
  • yarn.lock

Vulnerabilities:

Component Findings Locations
@octokit/plugin-paginate-rest
1.1.2 → 8.2.1
Medium CVE-2025-25288 /package.json
@octokit/request-error
1.2.1 → 8.2.1
Medium CVE-2025-25289 /package.json
@octokit/request-error
2.1.0 → 8.2.1
Medium CVE-2025-25289 /package.json
ajv
5.5.2 → 1.0.0-beta.0
Medium CVE-2020-15366 /website/package.json
babel-traverse
6.26.0 → 2.0.0-alpha.1
High CVE-2023-45133 /website/package.json
braces
2.3.2 → 27.0.0-next.0
High CVE-2024-4068 /package.json
/website/package.json
com.google.guava:guava
17.0 → 8.5.0-alpha07
High CVE-2023-2976
Medium CVE-2018-10237
Low CVE-2020-8908
/packages/react-router-native/android/build.gradle
cross-spawn
5.1.0 → 2.0.0
High CVE-2024-21538 /package.json
form-data
2.3.3 → 5.0.0-alpha.0
Critical CVE-2025-7783 /package.json
hermes-engine
0.2.1 → 0.67.0-rc.4
Critical CVE-2020-1911
Critical CVE-2020-1914
Critical CVE-2021-24044
Critical CVE-2021-24037
High CVE-2020-1912
High CVE-2020-1915
High CVE-2020-1913
/package.json
highlight.js
9.18.5 → 1.0.0
Medium GHSA-7wwv-vh3v-89cq /package.json
html-minifier
3.5.21 → 4.0.0-beta.10
High CVE-2022-37620 /website/package.json
http-cache-semantics
3.8.1 → 4.0.0
High CVE-2022-25881 /package.json
ip
1.1.5 → 4.0.0
Critical CVE-2023-42282
High CVE-2024-29415
/package.json
ip
1.1.9 → 4.8.0
High CVE-2024-29415 /website/package.json
json5
0.5.1 → 4.0.0-alpha
High CVE-2022-46175 /website/package.json
loader-utils
1.1.0 → 1.4.2
Critical CVE-2022-37601
High CVE-2022-37599
High CVE-2022-37603
/website/package.json
lodash.pick
4.4.0 → 1.0.0-rc.1
High CVE-2020-8203 /website/package.json
lodash.set
4.3.2 → 4.0.0
High CVE-2020-8203 /package.json
lodash.template
4.5.0 → 5.1.2
High CVE-2021-23337 /package.json
markdown-it
7.0.1 → 12.3.2
Medium CVE-2022-21670 /website/package.json
mem
1.1.0 → 1.0.0
Medium GHSA-4xcv-9jjx-gfj3 /package.json
node-fetch
1.7.3 → 3.0.0
Medium CVE-2022-0235 /package.json
/website/package.json
node-forge
0.10.0 → 4.7.3
High CVE-2022-24771
High CVE-2022-24772
Medium CVE-2022-0122
Medium CVE-2022-24773
Low GHSA-gf8q-jrpm-jvxq
Low GHSA-5rrq-pxf6-6jx5
/website/package.json
node-notifier
5.4.5 → 26.0.0-alpha.0
Medium CVE-2020-7789 /package.json
nth-check
1.0.2 → 1.0.0-rc.5
High CVE-2021-3803 /website/package.json
org.apache.commons:commons-compress
1.8.1 → 9.0.0-alpha01
High CVE-2021-35517
High CVE-2021-35515
High CVE-2021-36090
High CVE-2021-35516
Medium CVE-2024-25710
Medium CVE-2018-11771
/packages/react-router-native/android/build.gradle
org.apache.httpcomponents:httpclient
4.1.1 → 3.2.0-alpha06
Medium CVE-2014-3577
Medium CVE-2012-6153
Medium CVE-2015-5262
/packages/react-router-native/android/build.gradle
org.bouncycastle:bcprov-jdk15on
1.48 → 8.9.0-alpha04
High CVE-2016-1000343
High CVE-2016-1000342
High CVE-2024-29857
High CVE-2016-1000344
High CVE-2018-1000180
High CVE-2016-1000352
High CVE-2016-1000338
Medium CVE-2020-26939
Medium CVE-2018-5382
Medium CVE-2016-1000345
Medium CVE-2016-1000339
Medium CVE-2015-7940
Medium CVE-2023-33202
Medium CVE-2024-30171
Medium CVE-2020-15522
Medium CVE-2016-1000341
Low CVE-2016-1000346
/packages/react-router-native/android/build.gradle
parse-path
4.0.4 → 5.1.8
High CVE-2022-0624 /package.json
postcss
6.0.23 → 4.0.0
High CVE-2021-23382
Medium CVE-2023-44270
/website/package.json
postcss
7.0.39 → 5.0.0
Medium CVE-2023-44270 /website/package.json
react-native
0.61.5 → 0.62.3
High CVE-2020-1920 /package.json
rollup
1.32.1 → 2.79.2
Medium CVE-2024-47068 /package.json
serialize-javascript
1.9.1 → 5.1.2
High CVE-2020-7660
Medium CVE-2019-16769
/website/package.json
ssri
5.3.0 → 5.0.0
High CVE-2021-27290 /website/package.json
tar
4.4.19 → 5.0.0-alpha.0
Medium CVE-2024-28863 /package.json
tmp
0.0.33 → 7.3.0
Medium CVE-2025-54798 /package.json
/website/package.json
tough-cookie
2.5.0 → 5.0.0-alpha.0
Critical CVE-2023-26136 /package.json
trim-newlines
1.0.0 → 4.0.0
High CVE-2021-33623 /package.json
trim-newlines
2.0.0 → 4.0.0
High CVE-2021-33623 /package.json
webpack-dev-middleware
3.7.3 → 4.0.0-rc.0
High CVE-2024-29180 /website/package.json
webpack-dev-server
3.11.3 → 5.2.1
Medium CVE-2025-30359
Medium CVE-2025-30360
/website/package.json
ws
3.3.3 → 0.62.0-rc.0
High CVE-2024-37890 /package.json
yargs-parser
7.0.0 → 0.62.0-rc.2
Medium CVE-2020-7608 /package.json
yargs-parser
8.1.0 → 1.0.0
Medium CVE-2020-7608 /package.json
yargs-parser
9.0.2 → 1.0.0
Medium CVE-2020-7608 /package.json
yargs-parser
11.1.1 → 0.62.0-rc.2
Medium CVE-2020-7608 /package.json

To detect these findings earlier in the dev lifecycle, try using Wiz Code VS Code Extension.

@wiz-5e8b1019be
Copy link
Author

Lock file update issue

Please update the lock file manually before merging this PR.

website/yarn.lock
Internal Error

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant