Bump js-yaml #75
Open
Bump js-yaml #75
Appcues WSS / WhiteSource Security Check
failed
Nov 17, 2025 in 1m 8s
Security Report
You have successfully remediated 2 vulnerabilities, but introduced 1 new vulnerabilities in this branch.
❌ New vulnerabilities:
| CVE | Severity | Vulnerable Library | Suggested Fix | Issue | |
|---|---|---|---|---|---|
CVE-2025-64718Path to dependency file: /package.json Path to vulnerable library: /package.json Dependency Hierarchy: -> react-scripts-5.0.1.tgz (Root Library) -> webpack-5.5.0.tgz -> plugin-svgo-5.5.0.tgz -> svgo-1.3.2.tgz -> ❌ js-yaml-3.14.2.tgz (Vulnerable Library) |
5.3 | js-yaml-3.14.2.tgz | Upgrade to version: js-yaml - 4.1.1 | None |
✔️ Remediated vulnerabilities:
| CVE | Vulnerable Library |
|---|---|
| CVE-2025-64718 | js-yaml-3.14.1.tgz |
| CVE-2025-64718 | js-yaml-4.1.0.tgz |
Base branch total remaining vulnerabilities: 19
Base branch commit: f7bab02437561d607542ea96c6131b0b66364ade
Total libraries scanned: 1264
Scan token: 1299881797984eb58ce8d65ad28f4650
Loading