chore(monorepo): update rust crate tracing-subscriber to v0.3.20 [security] - #26
chore(monorepo): update rust crate tracing-subscriber to v0.3.20 [security]#26renovate[bot] wants to merge 1 commit into
Security Report
35 new vulnerabilities were introduced in this branch.
❌ New vulnerabilities:
| Vulnerability | Severity | Vulnerable Library | Direct Library | Suggested Fix | Issue | |
|---|---|---|---|---|---|---|
CVE-2025-7783Path to dependency file: /package.json Path to vulnerable library: /package.json Dependency Hierarchy: -> verdaccio-5.31.1.tgz (Root Library) -> request-3.0.1.tgz -> ❌ form-data-2.3.3.tgz (Vulnerable Library) |
8.7 | Transitive form-data-2.3.3.tgz |
verdaccio-5.31.1.tgz | Transitive 2.5.4 |
None | |
CVE-2024-21529Path to dependency file: /package.json Path to vulnerable library: /package.json Dependency Hierarchy: -> eslint-0.68.4.tgz (Root Library) -> eslint-plugin-3.20.1.tgz -> graphql-config-4.5.0.tgz -> url-loader-7.17.18.tgz -> executor-http-0.1.10.tgz -> ❌ dset-3.1.3.tgz (Vulnerable Library) |
8.2 | Transitive dset-3.1.3.tgz |
eslint-0.68.4.tgz | Transitive dset - 3.1.4 |
None | |
CVE-2025-65945Path to dependency file: /package.json Path to vulnerable library: /package.json Dependency Hierarchy: -> verdaccio-5.31.1.tgz (Root Library) -> jsonwebtoken-9.0.2.tgz -> ❌ jws-3.2.2.tgz (Vulnerable Library) |
7.5 | Transitive jws-3.2.2.tgz |
verdaccio-5.31.1.tgz | Transitive 3.2.3 |
None | |
CVE-2025-64756Path to dependency file: /package.json Path to vulnerable library: /package.json Dependency Hierarchy: -> eslint-0.68.4.tgz (Root Library) -> eslint-plugin-next-14.2.4.tgz -> ❌ glob-10.3.10.tgz (Vulnerable Library) |
7.5 | Transitive glob-10.3.10.tgz |
eslint-0.68.4.tgz | Transitive 10.5.0 |
None | |
CVE-2025-15284Path to dependency file: /package.json Path to vulnerable library: /package.json Dependency Hierarchy: -> verdaccio-5.31.1.tgz (Root Library) -> express-4.19.2.tgz -> ❌ qs-6.11.0.tgz (Vulnerable Library) |
7.5 | Transitive qs-6.11.0.tgz |
verdaccio-5.31.1.tgz | Transitive 6.14.1 |
None | |
CVE-2025-15284Path to dependency file: /package.json Path to vulnerable library: /package.json Dependency Hierarchy: -> verdaccio-5.31.1.tgz (Root Library) -> request-3.0.1.tgz -> ❌ qs-6.10.4.tgz (Vulnerable Library) |
7.5 | Transitive qs-6.10.4.tgz |
verdaccio-5.31.1.tgz | Transitive 6.14.1 |
None | |
CVE-2025-12758Path to dependency file: /package.json Path to vulnerable library: /package.json Dependency Hierarchy: -> verdaccio-5.31.1.tgz (Root Library) -> ❌ validator-13.12.0.tgz (Vulnerable Library) |
7.5 | Transitive validator-13.12.0.tgz |
verdaccio-5.31.1.tgz | Transitive 13.15.22 |
None | |
CVE-2025-12758Path to dependency file: /package.json Path to vulnerable library: /package.json Dependency Hierarchy: -> verdaccio-5.31.1.tgz (Root Library) -> url-12.0.0-next-7.16.tgz -> ❌ validator-13.11.0.tgz (Vulnerable Library) |
7.5 | Transitive validator-13.11.0.tgz |
verdaccio-5.31.1.tgz | Transitive 13.15.22 |
None | |
CVE-2024-52798Path to dependency file: /package.json Path to vulnerable library: /package.json Dependency Hierarchy: -> verdaccio-5.31.1.tgz (Root Library) -> express-4.19.2.tgz -> ❌ path-to-regexp-0.1.7.tgz (Vulnerable Library) |
7.5 | Transitive path-to-regexp-0.1.7.tgz |
verdaccio-5.31.1.tgz | Transitive 0.1.12 |
None | |
CVE-2024-45590Path to dependency file: /package.json Path to vulnerable library: /package.json Dependency Hierarchy: -> verdaccio-5.31.1.tgz (Root Library) -> express-4.19.2.tgz -> ❌ body-parser-1.20.2.tgz (Vulnerable Library) |
7.5 | Transitive body-parser-1.20.2.tgz |
verdaccio-5.31.1.tgz | Transitive 1.20.3 |
None | |
CVE-2024-45296Path to dependency file: /package.json Path to vulnerable library: /package.json Dependency Hierarchy: -> verdaccio-5.31.1.tgz (Root Library) -> express-4.19.2.tgz -> ❌ path-to-regexp-0.1.7.tgz (Vulnerable Library) |
7.5 | Transitive path-to-regexp-0.1.7.tgz |
verdaccio-5.31.1.tgz | Transitive 0.1.10 |
None | |
CVE-2024-37890Path to dependency file: /package.json Path to vulnerable library: /package.json Dependency Hierarchy: -> eslint-0.68.4.tgz (Root Library) -> eslint-plugin-3.20.1.tgz -> graphql-config-4.5.0.tgz -> url-loader-7.17.18.tgz -> executor-graphql-ws-0.0.14.tgz -> ❌ ws-8.13.0.tgz (Vulnerable Library) |
7.5 | Transitive ws-8.13.0.tgz |
eslint-0.68.4.tgz | Transitive 8.17.1 |
None | |
CVE-2025-22150Path to dependency file: /package.json Path to vulnerable library: /package.json Dependency Hierarchy: -> container-metadata-6.0.2.tgz (Root Library) -> ci-context-6.0.1.tgz -> github-6.0.0.tgz -> http-client-2.2.3.tgz -> ❌ undici-5.28.4.tgz (Vulnerable Library) |
6.8 | Transitive undici-5.28.4.tgz |
container-metadata-6.0.2.tgz | Transitive 5.28.5 |
None | |
CVE-2024-43788Path to dependency file: /package.json Path to vulnerable library: /package.json Dependency Hierarchy: -> ts-loader-9.5.1.tgz (Root Library) -> ❌ webpack-5.93.0.tgz (Vulnerable Library) |
6.4 | Transitive webpack-5.93.0.tgz |
ts-loader-9.5.1.tgz | Transitive webpack - 5.94.0 |
None | |
CVE-2025-27789Path to dependency file: /package.json Path to vulnerable library: /package.json Dependency Hierarchy: -> js-19.7.3.tgz (Root Library) -> core-7.25.2.tgz -> ❌ helpers-7.25.0.tgz (Vulnerable Library) |
6.2 | Transitive helpers-7.25.0.tgz |
js-19.7.3.tgz | Transitive 7.26.10 |
None | |
CVE-2025-27789Path to dependency file: /package.json Path to vulnerable library: /package.json Dependency Hierarchy: -> js-19.7.3.tgz (Root Library) -> ❌ runtime-7.25.0.tgz (Vulnerable Library) |
6.2 | Transitive runtime-7.25.0.tgz |
js-19.7.3.tgz | Transitive 7.26.10 |
None | |
CVE-2025-27789Path to dependency file: /package.json Path to vulnerable library: /package.json Dependency Hierarchy: -> container-metadata-6.0.2.tgz (Root Library) -> pep440-1.0.0.tgz -> xregexp-4.4.1.tgz -> ❌ runtime-corejs3-7.25.6.tgz (Vulnerable Library) |
6.2 | Transitive runtime-corejs3-7.25.6.tgz |
container-metadata-6.0.2.tgz | Transitive 7.26.10 |
None | |
CVE-2025-56200Path to dependency file: /package.json Path to vulnerable library: /package.json Dependency Hierarchy: -> verdaccio-5.31.1.tgz (Root Library) -> ❌ validator-13.12.0.tgz (Vulnerable Library) |
6.1 | Transitive validator-13.12.0.tgz |
verdaccio-5.31.1.tgz | Transitive validator - 13.15.20 |
None | |
CVE-2025-56200Path to dependency file: /package.json Path to vulnerable library: /package.json Dependency Hierarchy: -> verdaccio-5.31.1.tgz (Root Library) -> url-12.0.0-next-7.16.tgz -> ❌ validator-13.11.0.tgz (Vulnerable Library) |
6.1 | Transitive validator-13.11.0.tgz |
verdaccio-5.31.1.tgz | Transitive validator - 13.15.20 |
None | |
CVE-2024-47068Path to dependency file: /package.json Path to vulnerable library: /package.json Dependency Hierarchy: -> workspace-tools-1.179.6.tgz (Root Library) -> ❌ rollup-4.18.0.tgz (Vulnerable Library) |
6.1 | Transitive rollup-4.18.0.tgz |
workspace-tools-1.179.6.tgz | Transitive 4.22.3 |
None | |
CVE-2025-25290Path to dependency file: /package.json Path to vulnerable library: /package.json Dependency Hierarchy: -> container-metadata-6.0.2.tgz (Root Library) -> ci-context-6.0.1.tgz -> github-6.0.0.tgz -> core-5.2.0.tgz -> ❌ request-8.4.0.tgz (Vulnerable Library) |
5.3 | Transitive request-8.4.0.tgz |
container-metadata-6.0.2.tgz | Transitive 8.4.1 |
None | |
CVE-2025-25289Path to dependency file: /package.json Path to vulnerable library: /package.json Dependency Hierarchy: -> container-metadata-6.0.2.tgz (Root Library) -> ci-context-6.0.1.tgz -> github-6.0.0.tgz -> core-5.2.0.tgz -> ❌ request-error-5.1.0.tgz (Vulnerable Library) |
5.3 | Transitive request-error-5.1.0.tgz |
container-metadata-6.0.2.tgz | Transitive @octokit/request-error - 5.1.1,6.1.7 |
None | |
CVE-2025-25288Path to dependency file: /package.json Path to vulnerable library: /package.json Dependency Hierarchy: -> container-metadata-6.0.2.tgz (Root Library) -> ci-context-6.0.1.tgz -> github-6.0.0.tgz -> ❌ plugin-paginate-rest-9.2.1.tgz (Vulnerable Library) |
5.3 | Transitive plugin-paginate-rest-9.2.1.tgz |
container-metadata-6.0.2.tgz | Transitive 9.2.2 |
None | |
CVE-2025-25285Path to dependency file: /package.json Path to vulnerable library: /package.json Dependency Hierarchy: -> container-metadata-6.0.2.tgz (Root Library) -> ci-context-6.0.1.tgz -> github-6.0.0.tgz -> core-5.2.0.tgz -> request-8.4.0.tgz -> ❌ endpoint-9.0.5.tgz (Vulnerable Library) |
5.3 | Transitive endpoint-9.0.5.tgz |
container-metadata-6.0.2.tgz | Transitive @octokit/endpoint - 9.0.6,10.1.3 |
None | |
CVE-2024-47764Path to dependency file: /package.json Path to vulnerable library: /package.json Dependency Hierarchy: -> verdaccio-5.31.1.tgz (Root Library) -> express-4.19.2.tgz -> ❌ cookie-0.6.0.tgz (Vulnerable Library) |
5.3 | Transitive cookie-0.6.0.tgz |
verdaccio-5.31.1.tgz | Transitive 0.7.0 |
None | |
CVE-2024-53384Path to dependency file: /package.json Path to vulnerable library: /package.json Dependency Hierarchy: -> workspace-tools-1.179.6.tgz (Root Library) -> ❌ tsup-8.0.0.tgz (Vulnerable Library) |
5.1 | Transitive tsup-8.0.0.tgz |
workspace-tools-1.179.6.tgz | None | ||
CVE-2024-43800Path to dependency file: /package.json Path to vulnerable library: /package.json Dependency Hierarchy: -> verdaccio-5.31.1.tgz (Root Library) -> express-4.19.2.tgz -> ❌ serve-static-1.15.0.tgz (Vulnerable Library) |
5.0 | Transitive serve-static-1.15.0.tgz |
verdaccio-5.31.1.tgz | Transitive 1.16.0 |
None | |
CVE-2024-43799Path to dependency file: /package.json Path to vulnerable library: /package.json Dependency Hierarchy: -> verdaccio-5.31.1.tgz (Root Library) -> express-4.19.2.tgz -> ❌ send-0.18.0.tgz (Vulnerable Library) |
5.0 | Transitive send-0.18.0.tgz |
verdaccio-5.31.1.tgz | Transitive 0.19.0 |
None | |
CVE-2024-43796Path to dependency file: /package.json Path to vulnerable library: /package.json Dependency Hierarchy: -> verdaccio-5.31.1.tgz (Root Library) -> ❌ express-4.19.2.tgz (Vulnerable Library) |
5.0 | Transitive express-4.19.2.tgz |
verdaccio-5.31.1.tgz | Transitive 4.20.0 |
None | |
CVE-2024-55565Path to dependency file: /package.json Path to vulnerable library: /package.json Dependency Hierarchy: -> workspace-tools-1.179.6.tgz (Root Library) -> esbuild-11.1.4.tgz -> ❌ nanoid-5.0.7.tgz (Vulnerable Library) |
4.3 | Transitive nanoid-5.0.7.tgz |
workspace-tools-1.179.6.tgz | Transitive 3.3.8 |
None | |
CVE-2024-55565Path to dependency file: /package.json Path to vulnerable library: /package.json Dependency Hierarchy: -> workspace-tools-1.179.6.tgz (Root Library) -> rollup-19.6.5.tgz -> postcss-8.4.45.tgz -> ❌ nanoid-3.3.7.tgz (Vulnerable Library) |
4.3 | Transitive nanoid-3.3.7.tgz |
workspace-tools-1.179.6.tgz | Transitive 3.3.8 |
None | |
CVE-2025-7339Path to dependency file: /package.json Path to vulnerable library: /package.json Dependency Hierarchy: -> verdaccio-5.31.1.tgz (Root Library) -> compression-1.7.4.tgz -> ❌ on-headers-1.0.2.tgz (Vulnerable Library) |
3.4 | Transitive on-headers-1.0.2.tgz |
verdaccio-5.31.1.tgz | Transitive 1.1.0 |
None | |
CVE-2025-47279Path to dependency file: /package.json Path to vulnerable library: /package.json Dependency Hierarchy: -> container-metadata-6.0.2.tgz (Root Library) -> ci-context-6.0.1.tgz -> github-6.0.0.tgz -> http-client-2.2.3.tgz -> ❌ undici-5.28.4.tgz (Vulnerable Library) |
3.1 | Transitive undici-5.28.4.tgz |
container-metadata-6.0.2.tgz | Transitive 5.29.0 |
None | |
CVE-2025-54798Path to dependency file: /package.json Path to vulnerable library: /package.json Dependency Hierarchy: -> nx-container-6.0.2.tgz (Root Library) -> ❌ tmp-0.2.3.tgz (Vulnerable Library) |
2.5 | Transitive tmp-0.2.3.tgz |
nx-container-6.0.2.tgz | Transitive 0.2.4 |
None | |
CVE-2025-54798Path to dependency file: /package.json Path to vulnerable library: /package.json Dependency Hierarchy: -> git-tools-2.58.3.tgz (Root Library) -> inquirer-9.2.23.tgz -> external-editor-3.1.0.tgz -> ❌ tmp-0.0.33.tgz (Vulnerable Library) |
2.5 | Transitive tmp-0.0.33.tgz |
git-tools-2.58.3.tgz | Transitive 0.2.4 |
None |
Base branch total remaining vulnerabilities: 15
Base branch commit: null
Total libraries scanned: 2196
Scan token: 3c8aa2ef8ed54689bd9132b1c3be1af8