Update dependency pg-promise to v10 #35
Open
Dev - Mend for GitHub.com / Mend Security Check
failed
Feb 25, 2026 in 52m 39s
Security Report
You have successfully remediated 4 vulnerabilities, but introduced 1 new vulnerabilities in this branch.
❌ New vulnerabilities:
| Vulnerability | Severity | Vulnerable Library | Direct Library | Suggested Fix | Issue | Reachability | |
|---|---|---|---|---|---|---|---|
CVE-2025-29744Path to dependency file: /package.json Path to vulnerable library: /node_modules/pg-promise/package.json Dependency Hierarchy: -> ❌ pg-promise-10.15.4.tgz (Vulnerable Library) |
5.4 | Direct pg-promise-10.15.4.tgz |
pg-promise-10.15.4.tgz | pg-promise - 11.5.5 | None |
✔️ Remediated vulnerabilities:
| Vulnerability | Vulnerable Library |
|---|---|
| CVE-2022-25883 | semver-4.3.2.tgz |
| CVE-2017-16137 | debug-2.2.0.tgz |
| CVE-2017-16082 | pg-5.1.0.tgz |
| CVE-2025-29744 | pg-promise-4.8.1.tgz |
Base branch total remaining vulnerabilities: 51
Base branch commit: 1bf1d83efeac9bd5edf365240449cfbdb7fa58b0
Total libraries scanned: 94
Scan token: 34d7127e339b41f7a43be79fa5360829
Loading