Skip to content

Update dependency sanitize-html to v2

b0407dd
Select commit
Loading
Failed to load commit list.
Open

Update dependency sanitize-html to v2 #7

Update dependency sanitize-html to v2
b0407dd
Select commit
Loading
Failed to load commit list.
Dev - Mend for GitHub.com / Mend Security Check failed Feb 20, 2025 in 8m 10s

Security Report

You have successfully remediated 12 vulnerabilities, but introduced 1 new vulnerabilities in this branch.

❌ New vulnerabilities:

CVE Severity CVSS Score Vulnerable Library Suggested Fix Issue
CVE-2022-41940

Path to dependency file: /package.json

Path to vulnerable library: /node_modules/engine.io/package.json

Dependency Hierarchy:

-> socket.io-3.1.2.tgz (Root Library)

   -> ❌ engine.io-4.1.2.tgz (Vulnerable Library)

High 7.1 engine.io-4.1.2.tgz Upgrade to version: engine.io - 3.6.1,6.2.1 None

✔️ Remediated vulnerabilities:

CVE Vulnerable Library
CVE-2018-16487 lodash-2.4.2.tgz
CVE-2020-28500 lodash-2.4.2.tgz
CVE-2022-25887 sanitize-html-1.4.2.tgz
CVE-2016-1000237 sanitize-html-1.4.2.tgz
CVE-2019-1010266 lodash-2.4.2.tgz
CVE-2018-3721 lodash-2.4.2.tgz
CVE-2017-16016 sanitize-html-1.4.2.tgz
CVE-2020-8203 lodash-2.4.2.tgz
CVE-2021-26539 sanitize-html-1.4.2.tgz
CVE-2021-26540 sanitize-html-1.4.2.tgz
CVE-2019-10744 lodash-2.4.2.tgz
CVE-2021-23337 lodash-2.4.2.tgz

Base branch total remaining vulnerabilities: 45
Base branch commit: b5a6e98e08ef3426b759f7faaa628a5dc5eb1c26


Total libraries scanned: 983

Scan token: e8d196ae88404e8db8412042ecaee405