Bump js-yaml from 3.14.1 to 3.14.2 #210
Open
Appcues WSS / WhiteSource Security Check
failed
Nov 17, 2025 in 3m 8s
Security Report
You have successfully remediated 1 vulnerabilities, but introduced 1 new vulnerabilities in this branch.
❌ New vulnerabilities:
| CVE | Severity | Vulnerable Library | Suggested Fix | Issue | |
|---|---|---|---|---|---|
CVE-2025-64718Path to dependency file: /package.json Path to vulnerable library: /package.json Dependency Hierarchy: -> appcues-react-native-example-5.0.1.tgz (Root Library) -> react-native-0.77.0.tgz -> community-cli-plugin-0.77.0.tgz -> metro-config-0.81.1.tgz -> cosmiconfig-5.2.1.tgz -> ❌ js-yaml-3.14.2.tgz (Vulnerable Library) |
5.3 | js-yaml-3.14.2.tgz | Upgrade to version: js-yaml - 4.1.1 | None |
✔️ Remediated vulnerabilities:
| CVE | Vulnerable Library |
|---|---|
| CVE-2025-64718 | js-yaml-3.14.1.tgz |
Base branch total remaining vulnerabilities: 8
Base branch commit: 6726b200a858008f073f989f1eae61d9b9e9a6d9
Total libraries scanned: 768
Scan token: fde3bf655f1a4fe7bfeab95d14e0d7db
Loading