Skip to content

[Snyk] Security upgrade node-gyp from 8.4.1 to 11.0.0 - #327

Open
codecakes wants to merge 1 commit into
developfrom
snyk-fix-33aa79767947d4639445e0e8c365b1a7
Open

codecakes wants to merge 1 commit into
developfrom
snyk-fix-33aa79767947d4639445e0e8c365b1a7

fix: package.json to reduce vulnerabilities

928bcb8
Select commit
Loading
Failed to load commit list.
Mend Bolt for GitHub / WhiteSource Security Check failed Jan 23, 2026 in 29m 40s

Security Report

You have successfully remediated 69 vulnerabilities, but introduced 12 new vulnerabilities in this branch.

❌ New vulnerabilities:

Vulnerability Severity CVSS Score Vulnerable Library Direct Library Suggested Fix Issue
CVE-2026-23950

Path to dependency file: /package.json

Path to vulnerable library: /node_modules/node-sass/node_modules/tar/package.json

Dependency Hierarchy:

-> node-sass-7.0.3.tgz (Root Library)

   -> node-gyp-8.4.1.tgz

     -> ❌ tar-6.2.1.tgz (Vulnerable Library)

High 8.8 Transitive tar-6.2.1.tgz node-sass-7.0.3.tgz Transitive 7.5.4 None
CVE-2018-11694

Path to dependency file: /package.json

Path to vulnerable library: /node_modules/node-sass/package.json

Dependency Hierarchy:

-> ❌ node-sass-7.0.3.tgz (Vulnerable Library)

High 8.8 Direct node-sass-7.0.3.tgz node-sass-7.0.3.tgz Fable.Template.Elmish.React - 0.1.6;GR.PageRender.Razor - 1.8.0;MIDIator.WebClient - 1.0.105 #35
CVE-2026-23745

Path to dependency file: /package.json

Path to vulnerable library: /node_modules/node-sass/node_modules/tar/package.json

Dependency Hierarchy:

-> node-sass-7.0.3.tgz (Root Library)

   -> node-gyp-8.4.1.tgz

     -> ❌ tar-6.2.1.tgz (Vulnerable Library)

High 7.1 Transitive tar-6.2.1.tgz node-sass-7.0.3.tgz Transitive https://github.com/isaacs/node-tar.git - v7.5.3 None
CVE-2025-30360

Path to dependency file: /package.json

Path to vulnerable library: /node_modules/webpack-dev-server/package.json

Dependency Hierarchy:

-> react-scripts-5.0.1.tgz (Root Library)

   -> ❌ webpack-dev-server-4.15.2.tgz (Vulnerable Library)

Medium 6.5 Transitive webpack-dev-server-4.15.2.tgz react-scripts-5.0.1.tgz Transitive 5.2.1 None
CVE-2019-6286

Path to dependency file: /package.json

Path to vulnerable library: /node_modules/node-sass/package.json

Dependency Hierarchy:

-> ❌ node-sass-7.0.3.tgz (Vulnerable Library)

Medium 6.5 Direct node-sass-7.0.3.tgz node-sass-7.0.3.tgz Fable.Template.Elmish.React - 0.1.6;GR.PageRender.Razor - 1.8.0;MIDIator.WebClient - 1.0.105 #34
CVE-2019-6283

Path to dependency file: /package.json

Path to vulnerable library: /node_modules/node-sass/package.json

Dependency Hierarchy:

-> ❌ node-sass-7.0.3.tgz (Vulnerable Library)

Medium 6.5 Direct node-sass-7.0.3.tgz node-sass-7.0.3.tgz Fable.Template.Elmish.React - 0.1.6;GR.PageRender.Razor - 1.8.0;MIDIator.WebClient - 1.0.105 #32
CVE-2018-20821

Path to dependency file: /package.json

Path to vulnerable library: /node_modules/node-sass/package.json

Dependency Hierarchy:

-> ❌ node-sass-7.0.3.tgz (Vulnerable Library)

Medium 6.5 Direct node-sass-7.0.3.tgz node-sass-7.0.3.tgz Fable.Template.Elmish.React - 0.1.6;GR.PageRender.Razor - 1.8.0;MIDIator.WebClient - 1.0.105 #39
CVE-2018-20190

Path to dependency file: /package.json

Path to vulnerable library: /node_modules/node-sass/package.json

Dependency Hierarchy:

-> ❌ node-sass-7.0.3.tgz (Vulnerable Library)

Medium 6.5 Direct node-sass-7.0.3.tgz node-sass-7.0.3.tgz GR.PageRender.Razor - 1.8.0;Fable.Template.Elmish.React - 0.1.6 #38
CVE-2018-19827

Path to dependency file: /package.json

Path to vulnerable library: /node_modules/node-sass/package.json

Dependency Hierarchy:

-> ❌ node-sass-7.0.3.tgz (Vulnerable Library)

Medium 5.6 Direct node-sass-7.0.3.tgz node-sass-7.0.3.tgz GR.PageRender.Razor - 1.8.0;Fable.Template.Elmish.React - 0.1.6 #36
CVE-2025-30359

Path to dependency file: /package.json

Path to vulnerable library: /node_modules/webpack-dev-server/package.json

Dependency Hierarchy:

-> react-scripts-5.0.1.tgz (Root Library)

   -> ❌ webpack-dev-server-4.15.2.tgz (Vulnerable Library)

Medium 5.3 Transitive webpack-dev-server-4.15.2.tgz react-scripts-5.0.1.tgz Transitive https://github.com/webpack/webpack-dev-server.git - v5.2.1,webpack-dev-server - 5.2.1 None
CVE-2018-19839

Path to dependency file: /package.json

Path to vulnerable library: /node_modules/node-sass/package.json

Dependency Hierarchy:

-> ❌ node-sass-7.0.3.tgz (Vulnerable Library)

Low 3.7 Direct node-sass-7.0.3.tgz node-sass-7.0.3.tgz Fable.Template.Elmish.React - 0.1.6;GR.PageRender.Razor - 1.8.0;MIDIator.WebClient - 1.0.105 #37
CVE-2018-19797

Path to dependency file: /package.json

Path to vulnerable library: /node_modules/node-sass/package.json

Dependency Hierarchy:

-> ❌ node-sass-7.0.3.tgz (Vulnerable Library)

Low 3.7 Direct node-sass-7.0.3.tgz node-sass-7.0.3.tgz Fable.Template.Elmish.React - 0.1.6;GR.PageRender.Razor - 1.8.0;MIDIator.WebClient - 1.0.105 #29

✔️ Remediated vulnerabilities:

Vulnerability Vulnerable Library
CVE-2022-37603 loader-utils-3.2.0.tgz
CVE-2018-20190 node-sass-7.0.1.tgz
CVE-2024-29041 express-4.18.1.tgz
CVE-2022-25881 http-cache-semantics-4.1.0.tgz
CVE-2022-25883 semver-7.3.7.tgz
CVE-2018-11694 node-sass-7.0.1.tgz
CVE-2023-42282 ip-2.0.0.tgz
CVE-2024-45296 path-to-regexp-1.8.0.tgz
CVE-2024-45590 body-parser-1.20.0.tgz
CVE-2022-46175 json5-1.0.1.tgz
CVE-2025-12816 node-forge-1.3.1.tgz
CVE-2023-26159 follow-redirects-1.15.1.tgz
CVE-2024-43788 webpack-5.74.0.tgz
CVE-2025-30360 webpack-dev-server-4.10.0.tgz
CVE-2018-19839 node-sass-7.0.1.tgz
CVE-2025-66031 node-forge-1.3.1.tgz
CVE-2024-28863 tar-6.1.11.tgz
CVE-2023-26115 word-wrap-1.2.3.tgz
CVE-2025-30359 webpack-dev-server-4.10.0.tgz
CVE-2024-29415 ip-2.0.0.tgz
CVE-2024-55565 nanoid-3.3.4.tgz
CVE-2019-6283 node-sass-7.0.1.tgz
CVE-2023-48631 css-tools-4.0.1.tgz
CVE-2024-28849 follow-redirects-1.15.1.tgz
CVE-2024-37890 ws-7.5.9.tgz
CVE-2026-23950 tar-6.1.11.tgz
CVE-2022-37599 loader-utils-2.0.2.tgz
CVE-2018-19827 node-sass-7.0.1.tgz
CVE-2022-25883 semver-6.3.0.tgz
CVE-2024-47764 cookie-0.5.0.tgz
CVE-2025-5889 brace-expansion-2.0.1.tgz
CVE-2025-15284 qs-6.10.3.tgz
CVE-2024-45296 path-to-regexp-0.1.7.tgz
CVE-2023-28154 webpack-5.74.0.tgz
CVE-2025-32997 http-proxy-middleware-2.0.6.tgz
CVE-2022-37603 loader-utils-2.0.2.tgz
CVE-2024-11831 serialize-javascript-6.0.0.tgz
CVE-2022-37599 loader-utils-3.2.0.tgz
CVE-2025-5889 brace-expansion-1.1.11.tgz
CVE-2025-64718 js-yaml-3.14.1.tgz
CVE-2025-27789 helpers-7.18.9.tgz
CVE-2018-19797 node-sass-7.0.1.tgz
CVE-2024-33883 ejs-3.1.8.tgz
CVE-2022-25883 semver-5.7.1.tgz
CVE-2026-23745 tar-6.1.11.tgz
CVE-2024-43796 express-4.18.1.tgz
CVE-2024-21538 cross-spawn-7.0.3.tgz
CVE-2025-32996 http-proxy-middleware-2.0.6.tgz
CVE-2022-46175 json5-2.2.1.tgz
CVE-2018-20821 node-sass-7.0.1.tgz
CVE-2022-25758 scss-tokenizer-0.3.0.tgz
CVE-2025-59436 ip-2.0.0.tgz
CVE-2022-25883 semver-7.0.0.tgz
CVE-2025-59437 ip-2.0.0.tgz
CVE-2023-26364 css-tools-4.0.1.tgz
CVE-2024-21536 http-proxy-middleware-2.0.6.tgz
CVE-2022-25927 ua-parser-js-0.7.31.tgz
CVE-2025-27789 runtime-corejs3-7.18.9.tgz
CVE-2023-26136 tough-cookie-4.0.0.tgz
CVE-2022-37601 loader-utils-2.0.2.tgz
CVE-2019-6286 node-sass-7.0.1.tgz
CVE-2025-7783 form-data-3.0.1.tgz
CVE-2024-52798 path-to-regexp-0.1.7.tgz
CVE-2025-66030 node-forge-1.3.1.tgz
CVE-2025-27789 runtime-7.18.9.tgz
CVE-2024-43800 serve-static-1.15.0.tgz
CVE-2024-37890 ws-8.8.1.tgz
CVE-2025-64718 js-yaml-4.1.0.tgz
CVE-2024-43799 send-0.18.0.tgz

Base branch total remaining vulnerabilities: 83
Base branch commit: null


Total libraries scanned: 1579

Scan token: fe3d0ab25fd5424298e9d4844451f3d6