Skip to content

fix: package.json to reduce vulnerabilities

5c01c3d
Select commit
Loading
Failed to load commit list.
Open

[Snyk] Security upgrade web3 from 1.4.0 to 4.0.1 #47

fix: package.json to reduce vulnerabilities
5c01c3d
Select commit
Loading
Failed to load commit list.
Debricked / Vulnerability analysis failed Oct 4, 2025 in 24s

An automation triggered a pipeline failure

Found 14 vulnerabilities. An additional 0 vulnerabilities have been marked as unaffected.

Output from Automations

6 rules were checked:


If a new dependency is added where the license risk is at least medium

then notify all users in the group admins by email

✔️ The rule did not trigger. Manage rule



If there is a dependency where the license risk is at least high

then send a pipeline warning

✔️ The rule did not trigger. Manage rule



If a new dependency is added where the license risk is at least high

then fail pipeline

✔️ The rule did not trigger. Manage rule



If a dependency contains a vulnerability which has not been marked as unaffected and which has not triggered this rule for this dependency before

then notify all users in the group admins by email

📤 The rule triggered for the following vulnerabilities, causing an email notification. Manage rule

Vulnerability CVSS2 CVSS3 Dependency Dependency Licenses
CVE-2024-6485 N/A 6.4 bootstrap (npm) MIT


If a dependency contains a vulnerability which has not been marked as unaffected

then send a pipeline warning

⚠️ The rule triggered for the following vulnerabilities, causing a pipeline warning. Manage rule

Vulnerability CVSS2 CVSS3 Dependency Dependency Licenses
CVE-2018-16487 7.5 9.8 lodash (npm) Unknown License
CVE-2023-28154 N/A 9.8 webpack (npm) MIT
CVE-2019-10744 6.4 9.1 lodash (npm) Unknown License
CVE-2021-43138 6.8 7.8 async (npm) Unknown License
CVE-2020-8203 5.8 7.4 lodash (npm) Unknown License
CVE-2021-23337 6.5 7.2 lodash (npm) Unknown License
CVE-2018-3721 4 6.5 lodash (npm) Unknown License
CVE-2019-1010266 4 6.5 lodash (npm) Unknown License
CVE-2024-6485 N/A 6.4 bootstrap (npm) MIT
CVE-2024-43788 N/A 6.1 webpack (npm) MIT
CVE-2020-24025 5 5.3 node-sass (npm) MIT
CVE-2020-28500 5 5.3 lodash (npm) Unknown License
debricked-97165 N/A N/A lodash (npm) Unknown License
debricked-233766 N/A N/A lodash (npm) Unknown License


If a dependency contains a vulnerability which has not been marked as unaffected 
where CVSS is at least high (7.0-8.9)

then fail pipeline

❌ The rule triggered for the following vulnerabilities, causing a pipeline failure. Manage rule

Vulnerability CVSS2 CVSS3 Dependency Dependency Licenses
CVE-2018-16487 7.5 9.8 lodash (npm) Unknown License
CVE-2023-28154 N/A 9.8 webpack (npm) MIT
CVE-2019-10744 6.4 9.1 lodash (npm) Unknown License
CVE-2021-43138 6.8 7.8 async (npm) Unknown License
CVE-2020-8203 5.8 7.4 lodash (npm) Unknown License
CVE-2021-23337 6.5 7.2 lodash (npm) Unknown License