Update dependency @astrojs/starlight to ^0.32.0 #3
Security Report
You have successfully remediated 2 vulnerabilities, but introduced 15 new vulnerabilities in this branch.
❌ New vulnerabilities:
| Vulnerability | Severity | Vulnerable Library | Direct Library | Suggested Fix | Issue | |
|---|---|---|---|---|---|---|
CVE-2025-57820Path to dependency file: /docs/package.json Path to vulnerable library: /docs/package.json Dependency Hierarchy: -> starlight-0.32.6.tgz (Root Library) -> astro-5.3.0.tgz -> ❌ devalue-5.1.1.tgz (Vulnerable Library) |
10.0 | Transitive devalue-5.1.1.tgz |
starlight-0.32.6.tgz | Transitive 5.3.2 |
None | |
CVE-2025-64764Path to dependency file: /docs/package.json Path to vulnerable library: /docs/package.json Dependency Hierarchy: -> starlight-0.32.6.tgz (Root Library) -> ❌ astro-5.3.0.tgz (Vulnerable Library) |
7.1 | Transitive astro-5.3.0.tgz |
starlight-0.32.6.tgz | Transitive astro - 5.15.8 |
None | |
CVE-2025-64525Path to dependency file: /docs/package.json Path to vulnerable library: /docs/package.json Dependency Hierarchy: -> starlight-0.32.6.tgz (Root Library) -> ❌ astro-5.3.0.tgz (Vulnerable Library) |
6.5 | Transitive astro-5.3.0.tgz |
starlight-0.32.6.tgz | Transitive astro - 5.15.5 |
None | |
CVE-2025-62522Path to dependency file: /docs/package.json Path to vulnerable library: /docs/package.json Dependency Hierarchy: -> starlight-0.32.6.tgz (Root Library) -> astro-5.3.0.tgz -> ❌ vite-6.1.0.tgz (Vulnerable Library) |
6.5 | Transitive vite-6.1.0.tgz |
starlight-0.32.6.tgz | Transitive https://gitlab.com/remram44/taguette.git - v1.5.0 |
None | |
CVE-2025-61925Path to dependency file: /docs/package.json Path to vulnerable library: /docs/package.json Dependency Hierarchy: -> starlight-0.32.6.tgz (Root Library) -> ❌ astro-5.3.0.tgz (Vulnerable Library) |
6.5 | Transitive astro-5.3.0.tgz |
starlight-0.32.6.tgz | Transitive astro - 5.14.3 |
None | |
CVE-2025-32395Path to dependency file: /docs/package.json Path to vulnerable library: /docs/package.json Dependency Hierarchy: -> starlight-0.32.6.tgz (Root Library) -> astro-5.3.0.tgz -> ❌ vite-6.1.0.tgz (Vulnerable Library) |
6.5 | Transitive vite-6.1.0.tgz |
starlight-0.32.6.tgz | Transitive 6.1.5 |
None | |
CVE-2025-54793Path to dependency file: /docs/package.json Path to vulnerable library: /docs/package.json Dependency Hierarchy: -> starlight-0.32.6.tgz (Root Library) -> ❌ astro-5.3.0.tgz (Vulnerable Library) |
6.1 | Transitive astro-5.3.0.tgz |
starlight-0.32.6.tgz | Transitive 5.12.8 |
None | |
CVE-2025-65019Path to dependency file: /docs/package.json Path to vulnerable library: /docs/package.json Dependency Hierarchy: -> starlight-0.32.6.tgz (Root Library) -> ❌ astro-5.3.0.tgz (Vulnerable Library) |
5.4 | Transitive astro-5.3.0.tgz |
starlight-0.32.6.tgz | Transitive astro - 5.15.9 |
None | |
CVE-2026-24001Path to dependency file: /docs/package.json Path to vulnerable library: /docs/package.json Dependency Hierarchy: -> starlight-0.32.6.tgz (Root Library) -> astro-5.3.0.tgz -> ❌ diff-5.2.0.tgz (Vulnerable Library) |
5.3 | Transitive diff-5.2.0.tgz |
starlight-0.32.6.tgz | Transitive https://github.com/kpdecker/jsdiff.git - v4.0.4,https://github.com/kpdecker/jsdiff.git - v5.2.2,https://github.com/kpdecker/jsdiff.git - v8.0.3 |
None | |
CVE-2025-64765Path to dependency file: /docs/package.json Path to vulnerable library: /docs/package.json Dependency Hierarchy: -> starlight-0.32.6.tgz (Root Library) -> ❌ astro-5.3.0.tgz (Vulnerable Library) |
5.3 | Transitive astro-5.3.0.tgz |
starlight-0.32.6.tgz | Transitive astro - 5.15.8 |
None | |
CVE-2025-58752Path to dependency file: /docs/package.json Path to vulnerable library: /docs/package.json Dependency Hierarchy: -> starlight-0.32.6.tgz (Root Library) -> astro-5.3.0.tgz -> ❌ vite-6.1.0.tgz (Vulnerable Library) |
5.3 | Transitive vite-6.1.0.tgz |
starlight-0.32.6.tgz | Transitive vite - 6.3.6,vite - 7.1.5,vite - 7.0.7,vite - 5.4.20 |
None | |
CVE-2025-30208Path to dependency file: /docs/package.json Path to vulnerable library: /docs/package.json Dependency Hierarchy: -> starlight-0.32.6.tgz (Root Library) -> astro-5.3.0.tgz -> ❌ vite-6.1.0.tgz (Vulnerable Library) |
5.3 | Transitive vite-6.1.0.tgz |
starlight-0.32.6.tgz | Transitive 6.1.2 |
None | |
CVE-2025-58751Path to dependency file: /docs/package.json Path to vulnerable library: /docs/package.json Dependency Hierarchy: -> starlight-0.32.6.tgz (Root Library) -> astro-5.3.0.tgz -> ❌ vite-6.1.0.tgz (Vulnerable Library) |
4.3 | Transitive vite-6.1.0.tgz |
starlight-0.32.6.tgz | Transitive 6.3.6 |
None | |
CVE-2025-64757Path to dependency file: /docs/package.json Path to vulnerable library: /docs/package.json Dependency Hierarchy: -> starlight-0.32.6.tgz (Root Library) -> ❌ astro-5.3.0.tgz (Vulnerable Library) |
3.5 | Transitive astro-5.3.0.tgz |
starlight-0.32.6.tgz | Transitive astro - 5.14.3 |
None | |
CVE-2025-64745Path to dependency file: /docs/package.json Path to vulnerable library: /docs/package.json Dependency Hierarchy: -> starlight-0.32.6.tgz (Root Library) -> ❌ astro-5.3.0.tgz (Vulnerable Library) |
2.7 | Transitive astro-5.3.0.tgz |
starlight-0.32.6.tgz | Transitive astro - 5.15.6 |
None |
✔️ Remediated vulnerabilities:
| Vulnerability | Vulnerable Library |
|---|---|
| CVE-2025-4565 | protobuf-4.25.6-cp37-abi3-manylinux2014_x86_64.whl |
| CVE-2026-0994 | protobuf-4.25.6-cp37-abi3-manylinux2014_x86_64.whl |
Base branch total remaining vulnerabilities: 15
Base branch commit: 6703a1908524f677bf251e7e88d0cbd33021958a
Total libraries scanned: 653
Scan token: ab358a2092e44a34abbaaa01345dc89f