Update dependency sanitize-html to v2 #7
Dev - Mend for GitHub.com / Mend Security Check
failed
Feb 20, 2025 in 8m 10s
Security Report
You have successfully remediated 12 vulnerabilities, but introduced 1 new vulnerabilities in this branch.
❌ New vulnerabilities:
| CVE | Severity | Vulnerable Library | Suggested Fix | Issue | |
|---|---|---|---|---|---|
CVE-2022-41940Path to dependency file: /package.json Path to vulnerable library: /node_modules/engine.io/package.json Dependency Hierarchy: -> socket.io-3.1.2.tgz (Root Library) -> ❌ engine.io-4.1.2.tgz (Vulnerable Library) |
7.1 | engine.io-4.1.2.tgz | Upgrade to version: engine.io - 3.6.1,6.2.1 | None |
✔️ Remediated vulnerabilities:
| CVE | Vulnerable Library |
|---|---|
| CVE-2018-16487 | lodash-2.4.2.tgz |
| CVE-2020-28500 | lodash-2.4.2.tgz |
| CVE-2022-25887 | sanitize-html-1.4.2.tgz |
| CVE-2016-1000237 | sanitize-html-1.4.2.tgz |
| CVE-2019-1010266 | lodash-2.4.2.tgz |
| CVE-2018-3721 | lodash-2.4.2.tgz |
| CVE-2017-16016 | sanitize-html-1.4.2.tgz |
| CVE-2020-8203 | lodash-2.4.2.tgz |
| CVE-2021-26539 | sanitize-html-1.4.2.tgz |
| CVE-2021-26540 | sanitize-html-1.4.2.tgz |
| CVE-2019-10744 | lodash-2.4.2.tgz |
| CVE-2021-23337 | lodash-2.4.2.tgz |
Base branch total remaining vulnerabilities: 45
Base branch commit: b5a6e98e08ef3426b759f7faaa628a5dc5eb1c26
Total libraries scanned: 983
Scan token: e8d196ae88404e8db8412042ecaee405
Loading