Skip to content

Wiz: Upgrade multiple dependencies (resolves 34 findings)#20

Open
wiz-code-21c5ec5a85[bot] wants to merge 1 commit into
mainfrom
wiz-auto-remediation-641b1553402c5194
Open

Wiz: Upgrade multiple dependencies (resolves 34 findings)#20
wiz-code-21c5ec5a85[bot] wants to merge 1 commit into
mainfrom
wiz-auto-remediation-641b1553402c5194

Conversation

@wiz-code-21c5ec5a85
Copy link
Copy Markdown

Wiz Remediation Pull Request Banner

Wiz has created this PR to fix 34 findings detected in this project

Changes were made to the following file(s):

  • plugins/elfaAiPlugin/package-lock.json
  • plugins/elfaAiPlugin/package.json
  • plugins/farcasterPlugin/package-lock.json
  • plugins/farcasterPlugin/package.json
  • plugins/onChainActionsPlugin/package.json
  • plugins/stateofmikaPlugin/package-lock.json
  • plugins/stateofmikaPlugin/package.json

Vulnerabilities:

Component Findings Locations
ajv
8.17.1 → 8.18.0
Low CVE-2025-69873 /plugins/onChainActionsPlugin/package.json
axios
0.27.2 → 0.31.1
Critical CVE-2026-42043
High CVE-2026-42038
High CVE-2026-42035
High CVE-2026-42033
High CVE-2025-27152
High CVE-2026-25639
Medium CVE-2023-45857
Medium CVE-2026-42034
Medium CVE-2026-42036
Medium CVE-2026-42039
Medium CVE-2026-42042
Medium CVE-2026-40175
Medium CVE-2025-62718
Medium CVE-2026-42041
Low CVE-2026-42040
/plugins/elfaAiPlugin/package.json
/plugins/stateofmikaPlugin/package.json
elliptic
6.6.1 → 0.2.3-nightly.20250308.29
Medium CVE-2025-14505 /plugins/farcasterPlugin/package.json
follow-redirects
1.15.11 → 1.15.0
Medium CVE-2026-40895 /plugins/elfaAiPlugin/package.json
/plugins/stateofmikaPlugin/package.json

To detect these findings earlier in the dev lifecycle, try using Wiz Code VS Code Extension.

@wiz-code-21c5ec5a85
Copy link
Copy Markdown
Author

⚠️ Lock file update issue

Please update the lock file manually before merging this PR.

plugins/onChainActionsPlugin/package-lock.json
Internal Error

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants