Skip to content

fix: package.json & package-lock.json to reduce vulnerabilities

73b6986
Select commit
Loading
Failed to load commit list.
Open

[Snyk] Security upgrade @actions/cache from 2.0.2 to 4.0.0 #5

fix: package.json & package-lock.json to reduce vulnerabilities
73b6986
Select commit
Loading
Failed to load commit list.
Debricked / Vulnerability analysis completed Jul 25, 2025 in 25s

An automation triggered a pipeline warning

Found 27 vulnerabilities. An additional 0 vulnerabilities have been marked as unaffected.

Output from Automations

4 rules were checked:


If a new dependency is added where the license risk is at least medium

then notify all users in the group admins by email

✔️ The rule did not trigger. Manage rule



If a dependency contains a vulnerability which has not been marked as unaffected and which has not triggered this rule for this dependency before

then notify all users in the group admins by email

✔️ The rule did not trigger. Manage rule



If there is a dependency where the license risk is at least high

then send a pipeline warning

✔️ The rule did not trigger. Manage rule



If a dependency contains a vulnerability which has not been marked as unaffected

then send a pipeline warning

⚠️ The rule triggered for the following vulnerabilities, causing a pipeline warning. Manage rule

Vulnerability CVSS2 CVSS3 Dependency Dependency Licenses
CVE-2023-26136 N/A 9.8 tough-cookie (npm) BSD-3-Clause
debricked-233443 10 9.8 execa (npm) MIT
CVE-2023-45133 N/A 8.8 @babel/traverse (npm) MIT
CVE-2022-46175 N/A 8.8 json5 (npm) MIT
CVE-2023-26115 N/A 7.5 word-wrap (npm) MIT
CVE-2024-21538 N/A 7.5 cross-spawn (npm) MIT
CVE-2022-3517 N/A 7.5 minimatch (npm) ISC
CVE-2024-4068 N/A 7.5 braces (npm) MIT
CVE-2024-45590 N/A 7.5 body-parser (npm) MIT
CVE-2024-37890 N/A 7.5 ws (npm) MIT
CVE-2022-25883 N/A 7.5 semver (npm) ISC
CVE-2022-24999 N/A 7.5 express (npm) MIT
CVE-2022-24999 N/A 7.5 qs (npm) BSD-3-Clause
CVE-2024-45296 N/A 7.5 path-to-regexp (npm) MIT
CVE-2020-8203 5.8 7.4 lodash.set (npm) MIT
CVE-2025-27789 N/A 6.2 @babel/helpers (npm) MIT
CVE-2024-29041 N/A 6.1 express (npm) MIT
CVE-2025-25289 N/A 5.3 @octokit/request-error (npm) MIT
CVE-2025-25290 N/A 5.3 @octokit/request (npm) MIT
CVE-2024-4067 N/A 5.3 micromatch (npm) MIT
CVE-2023-0842 N/A 5.3 xml2js (npm) MIT
CVE-2024-43796 N/A 4.7 express (npm) MIT
CVE-2024-43799 N/A 4.7 send (npm) MIT
CVE-2024-43800 N/A 4.7 serve-static (npm) MIT
CVE-2025-5889 2.1 3.1 brace-expansion (npm) MIT
debricked-97165 N/A N/A lodash.set (npm) MIT
CVE-2024-52798 N/A N/A path-to-regexp (npm) MIT
CVE-2024-47764 N/A N/A cookie (npm) MIT