Skip to content

Update dependency ejs to v3 (main) - #16

Open
mend-for-github-com[bot] wants to merge 1 commit into
mainfrom
whitesource-remediate/main-ejs-3.x
Open

Update dependency ejs to v3 (main)#16
mend-for-github-com[bot] wants to merge 1 commit into
mainfrom
whitesource-remediate/main-ejs-3.x

Update dependency ejs to v3

22d8408
Select commit
Loading
Failed to load commit list.
This check has been archived and is scheduled for deletion. Learn more about checks retention
Mend for GitHub.com / WhiteSource Security Check failed Aug 4, 2025 in 50m 20s

Security Report

You have successfully remediated 6 vulnerabilities, but introduced 1 new vulnerabilities in this branch.

❌ New vulnerabilities:

Vulnerability Severity CVSS Score Exploit Maturity EPSS Vulnerable Library Suggested Fix Issue Reachability
CVE-2024-43800

Path to dependency file: /package.json

Path to vulnerable library: /node_modules/serve-static/package.json

Dependency Hierarchy:

-> express-4.16.3.tgz (Root Library)

   -> ❌ serve-static-1.13.2.tgz (Vulnerable Library)

Medium 5.0 Not Defined 0.1% serve-static-1.13.2.tgz Upgrade to version: serve-static - 1.16.0,2.1.0 #4

Reachable

✔️ Remediated vulnerabilities:

Vulnerability Vulnerable Library
CVE-2021-3918 json-schema-0.2.3.tgz
CVE-2020-15366 ajv-6.12.2.tgz
CVE-2022-29078 ejs-2.6.1.tgz
WS-2021-0153 ejs-2.6.1.tgz
CVE-2022-25883 semver-5.7.1.tgz
CVE-2024-33883 ejs-2.6.1.tgz

Base branch total remaining vulnerabilities: 22
Base branch commit: null


Total libraries scanned: 126

Scan token: 3a973b63e7fe44dc824f3fbc7c8e3574