Skip to content

Bump aws-sdk version to 1.12.797

b426dd2
Select commit
Loading
Failed to load commit list.
Open

Bump aws-sdk version to 1.12.797 #1213

Bump aws-sdk version to 1.12.797
b426dd2
Select commit
Loading
Failed to load commit list.
Mend for GitHub.com / Mend Security Check failed Apr 21, 2026 in 4m 20s

Security Report

15 new vulnerabilities were introduced in this branch.

❌ New vulnerabilities:

Vulnerability Severity CVSS Score Vulnerable Library Direct Library Suggested Fix Issue
CVE-2025-7783

Path to dependency file: /dashboards-notifications/package.json

Path to vulnerable library: /dashboards-notifications/package.json

Dependency Hierarchy:

-> cypress-6.9.1.tgz (Root Library)

   -> request-2.88.10.tgz

     -> ❌ form-data-2.3.3.tgz (Vulnerable Library)

High 8.7 Transitive form-data-2.3.3.tgz cypress-6.9.1.tgz Transitive 2.5.4 None
CVE-2026-4800

Path to dependency file: /dashboards-notifications/package.json

Path to vulnerable library: /dashboards-notifications/package.json

Dependency Hierarchy:

-> cypress-6.9.1.tgz (Root Library)

   -> ❌ lodash-4.17.21.tgz (Vulnerable Library)

High 8.1 Transitive lodash-4.17.21.tgz cypress-6.9.1.tgz Transitive lodash-amd - 4.18.0,lodash - 4.18.0,lodash.template - 4.18.0,lodash-es - 4.18.0 None
CVE-2026-27904

Path to dependency file: /dashboards-notifications/package.json

Path to vulnerable library: /dashboards-notifications/package.json

Dependency Hierarchy:

-> cypress-6.9.1.tgz (Root Library)

   -> tmp-0.2.1.tgz

     -> rimraf-3.0.2.tgz

       -> glob-7.2.0.tgz

         -> ❌ minimatch-3.1.2.tgz (Vulnerable Library)

High 7.5 Transitive minimatch-3.1.2.tgz cypress-6.9.1.tgz Transitive 3.1.4 None
CVE-2026-27903

Path to dependency file: /dashboards-notifications/package.json

Path to vulnerable library: /dashboards-notifications/package.json

Dependency Hierarchy:

-> cypress-6.9.1.tgz (Root Library)

   -> tmp-0.2.1.tgz

     -> rimraf-3.0.2.tgz

       -> glob-7.2.0.tgz

         -> ❌ minimatch-3.1.2.tgz (Vulnerable Library)

High 7.5 Transitive minimatch-3.1.2.tgz cypress-6.9.1.tgz Transitive https://github.com/isaacs/minimatch.git - v7.4.8,https://github.com/isaacs/minimatch.git - v8.0.6,https://github.com/isaacs/minimatch.git - v9.0.7,https://github.com/isaacs/minimatch.git - v5.1.8,https://github.com/isaacs/minimatch.git - v10.2.3,https://github.com/isaacs/minimatch.git - v6.2.2,https://github.com/isaacs/minimatch.git - v4.2.5,https://github.com/isaacs/minimatch.git - v3.1.3 None
CVE-2026-26996

Path to dependency file: /dashboards-notifications/package.json

Path to vulnerable library: /dashboards-notifications/package.json

Dependency Hierarchy:

-> cypress-6.9.1.tgz (Root Library)

   -> tmp-0.2.1.tgz

     -> rimraf-3.0.2.tgz

       -> glob-7.2.0.tgz

         -> ❌ minimatch-3.1.2.tgz (Vulnerable Library)

High 7.5 Transitive minimatch-3.1.2.tgz cypress-6.9.1.tgz Transitive https://github.com/isaacs/minimatch.git - v10.2.1,https://github.com/isaacs/minimatch.git - v7.4.7,https://github.com/isaacs/minimatch.git - v6.2.1,https://github.com/isaacs/minimatch.git - v9.0.6,https://github.com/isaacs/minimatch.git - v8.0.5,https://github.com/isaacs/minimatch.git - v3.1.3,https://github.com/isaacs/minimatch.git - v4.2.4,https://github.com/isaacs/minimatch.git - v5.1.7 None
CVE-2024-21538

Path to dependency file: /dashboards-notifications/package.json

Path to vulnerable library: /dashboards-notifications/package.json

Dependency Hierarchy:

-> cypress-6.9.1.tgz (Root Library)

   -> execa-4.1.0.tgz

     -> ❌ cross-spawn-7.0.3.tgz (Vulnerable Library)

High 7.5 Transitive cross-spawn-7.0.3.tgz cypress-6.9.1.tgz Transitive 7.0.5 None
CVE-2025-13465

Path to dependency file: /dashboards-notifications/package.json

Path to vulnerable library: /dashboards-notifications/package.json

Dependency Hierarchy:

-> cypress-6.9.1.tgz (Root Library)

   -> ❌ lodash-4.17.21.tgz (Vulnerable Library)

High 7.2 Transitive lodash-4.17.21.tgz cypress-6.9.1.tgz Transitive lodash-amd - 4.17.23,lodash - 4.17.23,lodash-es - 4.17.23 None
CVE-2026-33750

Path to dependency file: /dashboards-notifications/package.json

Path to vulnerable library: /dashboards-notifications/package.json

Dependency Hierarchy:

-> cypress-6.9.1.tgz (Root Library)

   -> tmp-0.2.1.tgz

     -> rimraf-3.0.2.tgz

       -> glob-7.2.0.tgz

         -> minimatch-3.1.2.tgz

           -> ❌ brace-expansion-1.1.11.tgz (Vulnerable Library)

Medium 6.5 Transitive brace-expansion-1.1.11.tgz cypress-6.9.1.tgz Transitive https://github.com/juliangruber/brace-expansion.git - v2.0.3,https://github.com/juliangruber/brace-expansion.git - v3.0.2,https://github.com/juliangruber/brace-expansion.git - v5.0.5,https://github.com/juliangruber/brace-expansion.git - v1.1.13 None
CVE-2026-2950

Path to dependency file: /dashboards-notifications/package.json

Path to vulnerable library: /dashboards-notifications/package.json

Dependency Hierarchy:

-> cypress-6.9.1.tgz (Root Library)

   -> ❌ lodash-4.17.21.tgz (Vulnerable Library)

Medium 6.5 Transitive lodash-4.17.21.tgz cypress-6.9.1.tgz Transitive 4.17.23 None
CVE-2023-26136

Path to dependency file: /dashboards-notifications/package.json

Path to vulnerable library: /dashboards-notifications/package.json

Dependency Hierarchy:

-> cypress-6.9.1.tgz (Root Library)

   -> request-2.88.10.tgz

     -> ❌ tough-cookie-2.5.0.tgz (Vulnerable Library)

Medium 6.5 Transitive tough-cookie-2.5.0.tgz cypress-6.9.1.tgz Transitive 4.1.3 None
CVE-2023-28155

Path to dependency file: /dashboards-notifications/package.json

Path to vulnerable library: /dashboards-notifications/package.json

Dependency Hierarchy:

-> cypress-6.9.1.tgz (Root Library)

   -> ❌ request-2.88.10.tgz (Vulnerable Library)

Medium 6.1 Transitive request-2.88.10.tgz cypress-6.9.1.tgz Transitive 3.0.0 None
CVE-2026-2391

Path to dependency file: /dashboards-notifications/package.json

Path to vulnerable library: /dashboards-notifications/package.json

Dependency Hierarchy:

-> cypress-6.9.1.tgz (Root Library)

   -> request-2.88.10.tgz

     -> ❌ qs-6.5.3.tgz (Vulnerable Library)

Low 3.7 Transitive qs-6.5.3.tgz cypress-6.9.1.tgz Transitive 6.14.2 None
CVE-2025-15284

Path to dependency file: /dashboards-notifications/package.json

Path to vulnerable library: /dashboards-notifications/package.json

Dependency Hierarchy:

-> cypress-6.9.1.tgz (Root Library)

   -> request-2.88.10.tgz

     -> ❌ qs-6.5.3.tgz (Vulnerable Library)

Low 3.7 Transitive qs-6.5.3.tgz cypress-6.9.1.tgz Transitive 6.14.1 None
CVE-2025-5889

Path to dependency file: /dashboards-notifications/package.json

Path to vulnerable library: /dashboards-notifications/package.json

Dependency Hierarchy:

-> cypress-6.9.1.tgz (Root Library)

   -> tmp-0.2.1.tgz

     -> rimraf-3.0.2.tgz

       -> glob-7.2.0.tgz

         -> minimatch-3.1.2.tgz

           -> ❌ brace-expansion-1.1.11.tgz (Vulnerable Library)

Low 3.1 Transitive brace-expansion-1.1.11.tgz cypress-6.9.1.tgz Transitive 1.1.12 None
CVE-2025-54798

Path to dependency file: /dashboards-notifications/package.json

Path to vulnerable library: /dashboards-notifications/package.json

Dependency Hierarchy:

-> cypress-6.9.1.tgz (Root Library)

   -> ❌ tmp-0.2.1.tgz (Vulnerable Library)

Low 2.5 Transitive tmp-0.2.1.tgz cypress-6.9.1.tgz Transitive 0.2.4 None

Base branch total remaining vulnerabilities: 0
Base branch commit: 56c7b6b172d1d74634d40bf755f0b80ca4fc477d


Total libraries scanned: 207

Scan token: d74306adc6154d7795c1d734145fd013