Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
28 changes: 14 additions & 14 deletions package-lock.json

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Plerion found 32 security issues.

These do not block merging, but we recommend reviewing and resolving them:

Vulnerability ID Issue Affected version Remediation
Severity: Critical undici - undici: Information disclosure and Denial of Service via malformed Cache-Control directives undici@7.28.0 Upgrade to 7.29.0, 8.9.0 or higher
Severity: High brace-expansion - Brace-expansion: Denial of Service due to exponential-time complexity brace-expansion@5.0.6 Upgrade to 5.0.7, 1.1.16, 2.1.2 or higher
Severity: High fast-uri - fast-uri: Security policy bypass due to improper Unicode hostname canonicalization fast-uri@3.1.2 Upgrade to 4.0.1, 3.1.3, 2.4.2 or higher
Severity: High brace-expansion - Brace-expansion: Denial of Service via memory exhaustion in expand() function brace-expansion@5.0.6 Upgrade to 5.0.8, 3.0.3, 2.1.3, 1.1.17 or higher
Severity: High undici - undici: Cross-user information disclosure due to improper Cache-Control directive parsing undici@7.28.0 Upgrade to 7.29.0, 8.9.0 or higher
Show 27 more issues
Vulnerability ID Issue Affected version Remediation
Severity: High fast-uri - fast-uri versions from 2.3.1 through 4.1.0 (including the 3.x ... fast-uri@3.1.2 Upgrade to 2.4.3, 3.1.4, 4.1.1 or higher
Severity: High fast-uri - fast-uri: Host confusion vulnerability via backslash in URI authority fast-uri@3.1.2 Upgrade to 2.4.4, 3.1.5, 4.1.2 or higher
Severity: High js-yaml - js-yaml: Denial of Service via crafted YAML documents js-yaml@4.2.0 Upgrade to 3.15.0, 4.3.0 or higher
Severity: High tar - node-tar: Denial of Service due to incorrect PAX path handling tar@7.5.16 Upgrade to 7.5.18 or higher
Severity: High tar - node-tar: Denial of Service via crafted gzip bomb tar@7.5.16 Upgrade to 7.5.19 or higher
Severity: High tar - Node-tar: Denial of Service via malformed tar archive header tar@7.5.16 Upgrade to 7.5.18 or higher
Severity: High immutable - Immutable.js provides many Persistent Immutable data structures. Prior ... immutable@5.1.6 Upgrade to 4.3.9, 5.1.8 or higher
Severity: High immutable - Immutable.js provides many Persistent Immutable data structures. Prior ... immutable@5.1.6 Upgrade to 4.3.9, 5.1.8 or higher
Severity: High brace-expansion - brace-expansion: Denial of Service via unbounded intermediate arrays brace-expansion@5.0.6 Upgrade to 1.1.18, 2.1.4, 3.0.6, 5.0.9 or higher
Severity: High svgo - SVGO removeScripts plugin leaves some executable scripts intact svgo@3.3.3 Upgrade to 2.8.3, 3.3.4, 4.0.2 or higher
Severity: High svgo - SVGO removeScripts plugin leaves some executable scripts intact svgo@4.0.1 Upgrade to 2.8.3, 3.3.4, 4.0.2 or higher
Severity: High fast-xml-parser - Repeated DOCTYPE declarations reset entity expansion limits fast-xml-parser@5.9.3 Upgrade to 5.10.1 or higher
Severity: High sharp - CVE-2026-33327, CVE-2026-33328, CVE-2026-35590, CVE-2026-35591 sharp@0.34.5 Upgrade to 0.35.0 or higher
Severity: High postcss - Path Traversal in Previous Source Map Auto-Loading (sourceMappingURL) leads to Arbitrary .map File Disclosure postcss@8.5.15 Upgrade to 8.5.18 or higher
Severity: Medium undici - undici: HTTP header injection via unvalidated blob-like body type property undici@7.28.0 Upgrade to 6.28.0, 7.29.0, 8.9.0 or higher
Severity: Medium undici - undici: Response desynchronization via retry interceptor with mismatched Content-Length undici@7.28.0 Upgrade to 6.28.0, 7.29.0, 8.9.0 or higher
Severity: Medium undici - Undici: Cookie attribute injection allows bypassing security protections undici@7.28.0 Upgrade to 6.28.0, 7.29.0, 8.9.0 or higher
Severity: Medium yaml - yaml: Denial of Service via deeply nested YAML document parsing yaml@2.7.1 Upgrade to 2.8.3, 1.10.3 or higher
Severity: Medium @astrojs/rss - XML Injection via Unescaped RSS Feed Fields @astrojs/rss@4.0.18 Upgrade to 4.0.19 or higher
Severity: Medium astro - XSS via unescaped spread attribute names in renderHTMLElement (incomplete fix for CVE-2026-54298) astro@7.0.0 Upgrade to 7.0.6 or higher
Severity: Medium tar - node-tar: Denial of Service via crafted archive with NUL bytes in metadata tar@7.5.16 Upgrade to 7.5.17 or higher
Severity: Medium postcss - PostCSS: Information disclosure via crafted sourceMappingURL postcss@8.5.15 Upgrade to 8.5.23 or higher
Severity: Medium astro - Reflected XSS via unescaped View Transition animation properties astro@7.0.0 Upgrade to 7.1.0 or higher
Severity: Medium astro - composable astro/hono pipeline bypasses security.checkOrigin when middleware() is absent or misordered astro@7.0.0 Upgrade to 7.0.6 or higher
Severity: Medium tar - Uncontrolled recursion in mapHas/filesFilter allows uncatchable stack-overflow DoS via crafted long-path tar with member selection tar@7.5.16 Upgrade to 7.5.21 or higher
Severity: Low astro - Cross-site scripting via unescaped transition:* directive values on hydrated islands astro@7.0.0 Upgrade to 7.0.4 or higher
Severity: Low dompurify - CUSTOM_ELEMENT_HANDLING bypasses afterSanitizeElements for allowed custom elements. dompurify@3.4.11 Upgrade to 3.4.12 or higher

View in Plerion

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

2 changes: 1 addition & 1 deletion package.json
Original file line number Diff line number Diff line change
Expand Up @@ -60,7 +60,7 @@
"marked": "^14.0.0",
"marked-highlight": "^2.2.4",
"medium-zoom": "^1.1.0",
"mermaid": "^11.15.0",
"mermaid": "^11.16.1",
"oxfmt": "^0.55.0",
"oxlint": "^1.70.0",
"posthog-js": "^1.391.7",
Expand Down
Loading