Skip to content

Bump js-yaml

bd4b938
Select commit
Loading
Failed to load commit list.
Open

Bump js-yaml #75

Bump js-yaml
bd4b938
Select commit
Loading
Failed to load commit list.
Appcues WSS / WhiteSource Security Check failed Nov 17, 2025 in 1m 8s

Security Report

You have successfully remediated 2 vulnerabilities, but introduced 1 new vulnerabilities in this branch.

❌ New vulnerabilities:

CVE Severity CVSS Score Vulnerable Library Suggested Fix Issue
CVE-2025-64718

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> react-scripts-5.0.1.tgz (Root Library)

   -> webpack-5.5.0.tgz

     -> plugin-svgo-5.5.0.tgz

       -> svgo-1.3.2.tgz

         -> ❌ js-yaml-3.14.2.tgz (Vulnerable Library)

Medium 5.3 js-yaml-3.14.2.tgz Upgrade to version: js-yaml - 4.1.1 None

✔️ Remediated vulnerabilities:

CVE Vulnerable Library
CVE-2025-64718 js-yaml-3.14.1.tgz
CVE-2025-64718 js-yaml-4.1.0.tgz

Base branch total remaining vulnerabilities: 19
Base branch commit: f7bab02437561d607542ea96c6131b0b66364ade


Total libraries scanned: 1264

Scan token: 1299881797984eb58ce8d65ad28f4650