Auto Compress Images #492
Auto Compress Images #492
Security Report
You have successfully remediated 46 vulnerabilities, but introduced 3 new vulnerabilities in this branch.
❌ New vulnerabilities:
CVE | Severity | CVSS Score | Vulnerable Library | Suggested Fix | Issue |
---|---|---|---|---|---|
CVE-2024-35195Path to dependency file: /docs/requirements.txt Path to vulnerable library: /docs/requirements.txt Dependency Hierarchy: -> cookiecutter-2.6.0-py3-none-any.whl (Root Library) -> ❌ requests-2.31.0-py3-none-any.whl (Vulnerable Library) |
Medium | 5.6 | requests-2.31.0-py3-none-any.whl | Upgrade to version: requests - 2.32.2 | None |
CVE-2024-37891Path to dependency file: /docs/requirements.txt Path to vulnerable library: /docs/requirements.txt Dependency Hierarchy: -> cookiecutter-2.6.0-py3-none-any.whl (Root Library) -> requests-2.31.0-py3-none-any.whl -> ❌ urllib3-2.0.7-py3-none-any.whl (Vulnerable Library) |
Medium | 4.4 | urllib3-2.0.7-py3-none-any.whl | Upgrade to version: urllib3 - 1.26.19,2.2.2 | None |
CVE-2024-5569Path to dependency file: /docs/requirements.txt Path to vulnerable library: /docs/requirements.txt Dependency Hierarchy: -> Markdown-3.4.4-py3-none-any.whl (Root Library) -> importlib_metadata-6.7.0-py3-none-any.whl -> ❌ zipp-3.15.0-py3-none-any.whl (Vulnerable Library) |
Low | 3.3 | zipp-3.15.0-py3-none-any.whl | Upgrade to version: zipp - 3.19.1 | None |
✔️ Remediated vulnerabilities:
CVE | Vulnerable Library |
---|---|
CVE-2022-33987 | got-9.6.0.tgz |
CVE-2018-16487 | lodash-2.4.2.tgz |
CVE-2023-43804 | urllib3-1.26.7-py2.py3-none-any.whl |
CVE-2022-2216 | parse-url-6.0.0.tgz |
WS-2022-0238 | parse-url-6.0.0.tgz |
CVE-2021-44906 | minimist-1.2.5.tgz |
CVE-2022-21670 | markdown-it-12.0.4.tgz |
CVE-2022-25881 | http-cache-semantics-4.1.0.tgz |
CVE-2022-0144 | shelljs-0.8.4.tgz |
CVE-2021-3795 | semver-regex-1.0.0.tgz |
CVE-2023-37920 | certifi-2021.10.8-py2.py3-none-any.whl |
CVE-2020-28500 | lodash-2.4.2.tgz |
CVE-2022-0235 | node-fetch-2.6.6.tgz |
CVE-2024-37891 | urllib3-1.26.7-py2.py3-none-any.whl |
CVE-2022-2218 | parse-url-6.0.0.tgz |
CVE-2022-23491 | certifi-2021.10.8-py2.py3-none-any.whl |
CVE-2022-25883 | semver-5.7.1.tgz |
CVE-2022-46175 | json5-2.2.0.tgz |
CVE-2023-45803 | urllib3-1.26.7-py2.py3-none-any.whl |
CVE-2022-0624 | parse-path-4.0.3.tgz |
CVE-2023-44270 | postcss-7.0.39.tgz |
CVE-2022-0722 | parse-url-6.0.0.tgz |
WS-2022-0239 | parse-url-6.0.0.tgz |
CVE-2021-43308 | markdown-link-extractor-1.3.0.tgz |
CVE-2022-25883 | semver-7.3.5.tgz |
CVE-2022-2900 | parse-url-6.0.0.tgz |
CVE-2023-26115 | word-wrap-1.2.3.tgz |
CVE-2019-1010266 | lodash-2.4.2.tgz |
CVE-2021-23358 | underscore-1.6.0.tgz |
CVE-2022-33987 | got-11.8.3.tgz |
WS-2022-0237 | parse-url-6.0.0.tgz |
CVE-2022-21803 | nconf-0.10.0.tgz |
CVE-2022-38900 | decode-uri-component-0.2.0.tgz |
CVE-2018-3721 | lodash-2.4.2.tgz |
CVE-2020-8203 | lodash-2.4.2.tgz |
CVE-2022-24065 | cookiecutter-1.7.3-py2.py3-none-any.whl |
CVE-2022-3224 | parse-url-6.0.0.tgz |
CVE-2021-43307 | semver-regex-1.0.0.tgz |
CVE-2022-25883 | semver-6.3.0.tgz |
CVE-2024-39689 | certifi-2021.10.8-py2.py3-none-any.whl |
CVE-2022-24999 | qs-6.10.1.tgz |
CVE-2022-2217 | parse-url-6.0.0.tgz |
CVE-2022-3517 | minimatch-3.0.4.tgz |
CVE-2019-10744 | lodash-2.4.2.tgz |
CVE-2021-23337 | lodash-2.4.2.tgz |
CVE-2020-7753 | trim-0.0.1.tgz |
Base branch total remaining vulnerabilities: 46
Base branch commit: null
Total libraries scanned: 56
Scan token: c24d583f253f432caf6778bf89ff16b0