Skip to content

chore(monorepo): update rust crate tracing-subscriber to v0.3.20 [security] - #26

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/crate-tracing-subscriber-vulnerability
Open

chore(monorepo): update rust crate tracing-subscriber to v0.3.20 [security]#26
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/crate-tracing-subscriber-vulnerability

chore(monorepo): update rust crate tracing-subscriber to v0.3.20 [sec…

875daa6
Select commit
Loading
Failed to load commit list.
Mend Bolt for GitHub / Mend Security Check failed Jan 1, 2026 in 1m 26s

Security Report

35 new vulnerabilities were introduced in this branch.

❌ New vulnerabilities:

Vulnerability Severity CVSS Score Vulnerable Library Direct Library Suggested Fix Issue
CVE-2025-7783

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> verdaccio-5.31.1.tgz (Root Library)

   -> request-3.0.1.tgz

     -> ❌ form-data-2.3.3.tgz (Vulnerable Library)

High 8.7 Transitive form-data-2.3.3.tgz verdaccio-5.31.1.tgz Transitive 2.5.4 None
CVE-2024-21529

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> eslint-0.68.4.tgz (Root Library)

   -> eslint-plugin-3.20.1.tgz

     -> graphql-config-4.5.0.tgz

       -> url-loader-7.17.18.tgz

         -> executor-http-0.1.10.tgz

           -> ❌ dset-3.1.3.tgz (Vulnerable Library)

High 8.2 Transitive dset-3.1.3.tgz eslint-0.68.4.tgz Transitive dset - 3.1.4 None
CVE-2025-65945

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> verdaccio-5.31.1.tgz (Root Library)

   -> jsonwebtoken-9.0.2.tgz

     -> ❌ jws-3.2.2.tgz (Vulnerable Library)

High 7.5 Transitive jws-3.2.2.tgz verdaccio-5.31.1.tgz Transitive 3.2.3 None
CVE-2025-64756

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> eslint-0.68.4.tgz (Root Library)

   -> eslint-plugin-next-14.2.4.tgz

     -> ❌ glob-10.3.10.tgz (Vulnerable Library)

High 7.5 Transitive glob-10.3.10.tgz eslint-0.68.4.tgz Transitive 10.5.0 None
CVE-2025-15284

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> verdaccio-5.31.1.tgz (Root Library)

   -> express-4.19.2.tgz

     -> ❌ qs-6.11.0.tgz (Vulnerable Library)

High 7.5 Transitive qs-6.11.0.tgz verdaccio-5.31.1.tgz Transitive 6.14.1 None
CVE-2025-15284

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> verdaccio-5.31.1.tgz (Root Library)

   -> request-3.0.1.tgz

     -> ❌ qs-6.10.4.tgz (Vulnerable Library)

High 7.5 Transitive qs-6.10.4.tgz verdaccio-5.31.1.tgz Transitive 6.14.1 None
CVE-2025-12758

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> verdaccio-5.31.1.tgz (Root Library)

   -> ❌ validator-13.12.0.tgz (Vulnerable Library)

High 7.5 Transitive validator-13.12.0.tgz verdaccio-5.31.1.tgz Transitive 13.15.22 None
CVE-2025-12758

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> verdaccio-5.31.1.tgz (Root Library)

   -> url-12.0.0-next-7.16.tgz

     -> ❌ validator-13.11.0.tgz (Vulnerable Library)

High 7.5 Transitive validator-13.11.0.tgz verdaccio-5.31.1.tgz Transitive 13.15.22 None
CVE-2024-52798

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> verdaccio-5.31.1.tgz (Root Library)

   -> express-4.19.2.tgz

     -> ❌ path-to-regexp-0.1.7.tgz (Vulnerable Library)

High 7.5 Transitive path-to-regexp-0.1.7.tgz verdaccio-5.31.1.tgz Transitive 0.1.12 None
CVE-2024-45590

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> verdaccio-5.31.1.tgz (Root Library)

   -> express-4.19.2.tgz

     -> ❌ body-parser-1.20.2.tgz (Vulnerable Library)

High 7.5 Transitive body-parser-1.20.2.tgz verdaccio-5.31.1.tgz Transitive 1.20.3 None
CVE-2024-45296

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> verdaccio-5.31.1.tgz (Root Library)

   -> express-4.19.2.tgz

     -> ❌ path-to-regexp-0.1.7.tgz (Vulnerable Library)

High 7.5 Transitive path-to-regexp-0.1.7.tgz verdaccio-5.31.1.tgz Transitive 0.1.10 None
CVE-2024-37890

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> eslint-0.68.4.tgz (Root Library)

   -> eslint-plugin-3.20.1.tgz

     -> graphql-config-4.5.0.tgz

       -> url-loader-7.17.18.tgz

         -> executor-graphql-ws-0.0.14.tgz

           -> ❌ ws-8.13.0.tgz (Vulnerable Library)

High 7.5 Transitive ws-8.13.0.tgz eslint-0.68.4.tgz Transitive 8.17.1 None
CVE-2025-22150

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> container-metadata-6.0.2.tgz (Root Library)

   -> ci-context-6.0.1.tgz

     -> github-6.0.0.tgz

       -> http-client-2.2.3.tgz

         -> ❌ undici-5.28.4.tgz (Vulnerable Library)

Medium 6.8 Transitive undici-5.28.4.tgz container-metadata-6.0.2.tgz Transitive 5.28.5 None
CVE-2024-43788

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> ts-loader-9.5.1.tgz (Root Library)

   -> ❌ webpack-5.93.0.tgz (Vulnerable Library)

Medium 6.4 Transitive webpack-5.93.0.tgz ts-loader-9.5.1.tgz Transitive webpack - 5.94.0 None
CVE-2025-27789

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> js-19.7.3.tgz (Root Library)

   -> core-7.25.2.tgz

     -> ❌ helpers-7.25.0.tgz (Vulnerable Library)

Medium 6.2 Transitive helpers-7.25.0.tgz js-19.7.3.tgz Transitive 7.26.10 None
CVE-2025-27789

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> js-19.7.3.tgz (Root Library)

   -> ❌ runtime-7.25.0.tgz (Vulnerable Library)

Medium 6.2 Transitive runtime-7.25.0.tgz js-19.7.3.tgz Transitive 7.26.10 None
CVE-2025-27789

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> container-metadata-6.0.2.tgz (Root Library)

   -> pep440-1.0.0.tgz

     -> xregexp-4.4.1.tgz

       -> ❌ runtime-corejs3-7.25.6.tgz (Vulnerable Library)

Medium 6.2 Transitive runtime-corejs3-7.25.6.tgz container-metadata-6.0.2.tgz Transitive 7.26.10 None
CVE-2025-56200

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> verdaccio-5.31.1.tgz (Root Library)

   -> ❌ validator-13.12.0.tgz (Vulnerable Library)

Medium 6.1 Transitive validator-13.12.0.tgz verdaccio-5.31.1.tgz Transitive validator - 13.15.20 None
CVE-2025-56200

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> verdaccio-5.31.1.tgz (Root Library)

   -> url-12.0.0-next-7.16.tgz

     -> ❌ validator-13.11.0.tgz (Vulnerable Library)

Medium 6.1 Transitive validator-13.11.0.tgz verdaccio-5.31.1.tgz Transitive validator - 13.15.20 None
CVE-2024-47068

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> workspace-tools-1.179.6.tgz (Root Library)

   -> ❌ rollup-4.18.0.tgz (Vulnerable Library)

Medium 6.1 Transitive rollup-4.18.0.tgz workspace-tools-1.179.6.tgz Transitive 4.22.3 None
CVE-2025-25290

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> container-metadata-6.0.2.tgz (Root Library)

   -> ci-context-6.0.1.tgz

     -> github-6.0.0.tgz

       -> core-5.2.0.tgz

         -> ❌ request-8.4.0.tgz (Vulnerable Library)

Medium 5.3 Transitive request-8.4.0.tgz container-metadata-6.0.2.tgz Transitive 8.4.1 None
CVE-2025-25289

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> container-metadata-6.0.2.tgz (Root Library)

   -> ci-context-6.0.1.tgz

     -> github-6.0.0.tgz

       -> core-5.2.0.tgz

         -> ❌ request-error-5.1.0.tgz (Vulnerable Library)

Medium 5.3 Transitive request-error-5.1.0.tgz container-metadata-6.0.2.tgz Transitive @octokit/request-error - 5.1.1,6.1.7 None
CVE-2025-25288

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> container-metadata-6.0.2.tgz (Root Library)

   -> ci-context-6.0.1.tgz

     -> github-6.0.0.tgz

       -> ❌ plugin-paginate-rest-9.2.1.tgz (Vulnerable Library)

Medium 5.3 Transitive plugin-paginate-rest-9.2.1.tgz container-metadata-6.0.2.tgz Transitive 9.2.2 None
CVE-2025-25285

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> container-metadata-6.0.2.tgz (Root Library)

   -> ci-context-6.0.1.tgz

     -> github-6.0.0.tgz

       -> core-5.2.0.tgz

         -> request-8.4.0.tgz

           -> ❌ endpoint-9.0.5.tgz (Vulnerable Library)

Medium 5.3 Transitive endpoint-9.0.5.tgz container-metadata-6.0.2.tgz Transitive @octokit/endpoint - 9.0.6,10.1.3 None
CVE-2024-47764

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> verdaccio-5.31.1.tgz (Root Library)

   -> express-4.19.2.tgz

     -> ❌ cookie-0.6.0.tgz (Vulnerable Library)

Medium 5.3 Transitive cookie-0.6.0.tgz verdaccio-5.31.1.tgz Transitive 0.7.0 None
CVE-2024-53384

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> workspace-tools-1.179.6.tgz (Root Library)

   -> ❌ tsup-8.0.0.tgz (Vulnerable Library)

Medium 5.1 Transitive tsup-8.0.0.tgz workspace-tools-1.179.6.tgz None
CVE-2024-43800

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> verdaccio-5.31.1.tgz (Root Library)

   -> express-4.19.2.tgz

     -> ❌ serve-static-1.15.0.tgz (Vulnerable Library)

Medium 5.0 Transitive serve-static-1.15.0.tgz verdaccio-5.31.1.tgz Transitive 1.16.0 None
CVE-2024-43799

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> verdaccio-5.31.1.tgz (Root Library)

   -> express-4.19.2.tgz

     -> ❌ send-0.18.0.tgz (Vulnerable Library)

Medium 5.0 Transitive send-0.18.0.tgz verdaccio-5.31.1.tgz Transitive 0.19.0 None
CVE-2024-43796

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> verdaccio-5.31.1.tgz (Root Library)

   -> ❌ express-4.19.2.tgz (Vulnerable Library)

Medium 5.0 Transitive express-4.19.2.tgz verdaccio-5.31.1.tgz Transitive 4.20.0 None
CVE-2024-55565

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> workspace-tools-1.179.6.tgz (Root Library)

   -> esbuild-11.1.4.tgz

     -> ❌ nanoid-5.0.7.tgz (Vulnerable Library)

Medium 4.3 Transitive nanoid-5.0.7.tgz workspace-tools-1.179.6.tgz Transitive 3.3.8 None
CVE-2024-55565

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> workspace-tools-1.179.6.tgz (Root Library)

   -> rollup-19.6.5.tgz

     -> postcss-8.4.45.tgz

       -> ❌ nanoid-3.3.7.tgz (Vulnerable Library)

Medium 4.3 Transitive nanoid-3.3.7.tgz workspace-tools-1.179.6.tgz Transitive 3.3.8 None
CVE-2025-7339

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> verdaccio-5.31.1.tgz (Root Library)

   -> compression-1.7.4.tgz

     -> ❌ on-headers-1.0.2.tgz (Vulnerable Library)

Low 3.4 Transitive on-headers-1.0.2.tgz verdaccio-5.31.1.tgz Transitive 1.1.0 None
CVE-2025-47279

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> container-metadata-6.0.2.tgz (Root Library)

   -> ci-context-6.0.1.tgz

     -> github-6.0.0.tgz

       -> http-client-2.2.3.tgz

         -> ❌ undici-5.28.4.tgz (Vulnerable Library)

Low 3.1 Transitive undici-5.28.4.tgz container-metadata-6.0.2.tgz Transitive 5.29.0 None
CVE-2025-54798

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> nx-container-6.0.2.tgz (Root Library)

   -> ❌ tmp-0.2.3.tgz (Vulnerable Library)

Low 2.5 Transitive tmp-0.2.3.tgz nx-container-6.0.2.tgz Transitive 0.2.4 None
CVE-2025-54798

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> git-tools-2.58.3.tgz (Root Library)

   -> inquirer-9.2.23.tgz

     -> external-editor-3.1.0.tgz

       -> ❌ tmp-0.0.33.tgz (Vulnerable Library)

Low 2.5 Transitive tmp-0.0.33.tgz git-tools-2.58.3.tgz Transitive 0.2.4 None

Base branch total remaining vulnerabilities: 15
Base branch commit: null


Total libraries scanned: 2196

Scan token: 3c8aa2ef8ed54689bd9132b1c3be1af8