Skip to content

chore(monorepo): update rust crate bytes to v1.11.1 [security] - #29

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/crate-bytes-vulnerability
Open

chore(monorepo): update rust crate bytes to v1.11.1 [security]#29
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/crate-bytes-vulnerability

chore(monorepo): update rust crate bytes to v1.11.1 [security]

b724184
Select commit
Loading
Failed to load commit list.
Mend Bolt for GitHub / Mend Security Check failed Feb 5, 2026 in 9m 41s

Security Report

48 new vulnerabilities were introduced in this branch.

❌ New vulnerabilities:

Vulnerability Severity CVSS Score Vulnerable Library Direct Library Suggested Fix Issue
CVE-2025-7783

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> verdaccio-5.31.1.tgz (Root Library)

   -> request-3.0.1.tgz

     -> ❌ form-data-2.3.3.tgz (Vulnerable Library)

High 8.7 Transitive form-data-2.3.3.tgz verdaccio-5.31.1.tgz Transitive 2.5.4 None
CVE-2024-21529

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> eslint-0.68.4.tgz (Root Library)

   -> eslint-plugin-3.20.1.tgz

     -> graphql-config-4.5.0.tgz

       -> url-loader-7.17.18.tgz

         -> executor-http-0.1.10.tgz

           -> ❌ dset-3.1.3.tgz (Vulnerable Library)

High 8.2 Transitive dset-3.1.3.tgz eslint-0.68.4.tgz Transitive dset - 3.1.4 None
CVE-2025-65945

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> verdaccio-5.31.1.tgz (Root Library)

   -> jsonwebtoken-9.0.2.tgz

     -> ❌ jws-3.2.2.tgz (Vulnerable Library)

High 7.5 Transitive jws-3.2.2.tgz verdaccio-5.31.1.tgz Transitive 3.2.3 None
CVE-2025-64756

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> eslint-0.68.4.tgz (Root Library)

   -> eslint-plugin-next-14.2.4.tgz

     -> ❌ glob-10.3.10.tgz (Vulnerable Library)

High 7.5 Transitive glob-10.3.10.tgz eslint-0.68.4.tgz Transitive 10.5.0 None
CVE-2025-15284

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> verdaccio-5.31.1.tgz (Root Library)

   -> request-3.0.1.tgz

     -> ❌ qs-6.10.4.tgz (Vulnerable Library)

High 7.5 Transitive qs-6.10.4.tgz verdaccio-5.31.1.tgz Transitive 6.14.1 None
CVE-2025-15284

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> verdaccio-5.31.1.tgz (Root Library)

   -> express-4.19.2.tgz

     -> ❌ qs-6.11.0.tgz (Vulnerable Library)

High 7.5 Transitive qs-6.11.0.tgz verdaccio-5.31.1.tgz Transitive 6.14.1 None
CVE-2025-12758

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> verdaccio-5.31.1.tgz (Root Library)

   -> ❌ validator-13.12.0.tgz (Vulnerable Library)

High 7.5 Transitive validator-13.12.0.tgz verdaccio-5.31.1.tgz Transitive 13.15.22 None
CVE-2025-12758

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> verdaccio-5.31.1.tgz (Root Library)

   -> url-12.0.0-next-7.16.tgz

     -> ❌ validator-13.11.0.tgz (Vulnerable Library)

High 7.5 Transitive validator-13.11.0.tgz verdaccio-5.31.1.tgz Transitive 13.15.22 None
CVE-2024-52798

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> verdaccio-5.31.1.tgz (Root Library)

   -> express-4.19.2.tgz

     -> ❌ path-to-regexp-0.1.7.tgz (Vulnerable Library)

High 7.5 Transitive path-to-regexp-0.1.7.tgz verdaccio-5.31.1.tgz Transitive 0.1.12 None
CVE-2024-45590

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> verdaccio-5.31.1.tgz (Root Library)

   -> express-4.19.2.tgz

     -> ❌ body-parser-1.20.2.tgz (Vulnerable Library)

High 7.5 Transitive body-parser-1.20.2.tgz verdaccio-5.31.1.tgz Transitive 1.20.3 None
CVE-2024-45296

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> verdaccio-5.31.1.tgz (Root Library)

   -> express-4.19.2.tgz

     -> ❌ path-to-regexp-0.1.7.tgz (Vulnerable Library)

High 7.5 Transitive path-to-regexp-0.1.7.tgz verdaccio-5.31.1.tgz Transitive 0.1.10 None
CVE-2024-37890

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> eslint-0.68.4.tgz (Root Library)

   -> eslint-plugin-3.20.1.tgz

     -> graphql-config-4.5.0.tgz

       -> url-loader-7.17.18.tgz

         -> executor-legacy-ws-0.0.11.tgz

           -> ❌ ws-8.13.0.tgz (Vulnerable Library)

High 7.5 Transitive ws-8.13.0.tgz eslint-0.68.4.tgz Transitive 8.17.1 None
CVE-2025-13465

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> verdaccio-5.31.1.tgz (Root Library)

   -> config-7.0.0-next-7.16.tgz

     -> yup-0.32.11.tgz

       -> ❌ lodash-es-4.17.21.tgz (Vulnerable Library)

High 7.2 Transitive lodash-es-4.17.21.tgz verdaccio-5.31.1.tgz Transitive lodash-amd - 4.17.23,lodash - 4.17.23,lodash-es - 4.17.23 None
CVE-2025-13465

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> verdaccio-5.31.1.tgz (Root Library)

   -> ❌ lodash-4.17.21.tgz (Vulnerable Library)

High 7.2 Transitive lodash-4.17.21.tgz verdaccio-5.31.1.tgz Transitive lodash-amd - 4.17.23,lodash - 4.17.23,lodash-es - 4.17.23 None
CVE-2025-13465

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> git-tools-2.58.3.tgz (Root Library)

   -> inquirer-9.2.23.tgz

     -> ❌ lodash-4.17.21.tgz (Vulnerable Library)

High 7.2 Transitive lodash-4.17.21.tgz git-tools-2.58.3.tgz Transitive lodash-amd - 4.17.23,lodash - 4.17.23,lodash-es - 4.17.23 None
CVE-2025-13465

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> eslint-0.68.4.tgz (Root Library)

   -> eslint-plugin-yml-1.14.0.tgz

     -> ❌ lodash-4.17.21.tgz (Vulnerable Library)

High 7.2 Transitive lodash-4.17.21.tgz eslint-0.68.4.tgz Transitive lodash-amd - 4.17.23,lodash - 4.17.23,lodash-es - 4.17.23 None
CVE-2025-13465

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> workspace-tools-1.179.6.tgz (Root Library)

   -> typia-6.0.6.tgz

     -> inquirer-8.2.6.tgz

       -> ❌ lodash-4.17.21.tgz (Vulnerable Library)

High 7.2 Transitive lodash-4.17.21.tgz workspace-tools-1.179.6.tgz Transitive lodash-amd - 4.17.23,lodash - 4.17.23,lodash-es - 4.17.23 None
CVE-2025-22150

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> container-metadata-6.0.2.tgz (Root Library)

   -> ci-context-6.0.1.tgz

     -> github-6.0.0.tgz

       -> http-client-2.2.3.tgz

         -> ❌ undici-5.28.4.tgz (Vulnerable Library)

Medium 6.8 Transitive undici-5.28.4.tgz container-metadata-6.0.2.tgz Transitive 5.28.5 None
CVE-2024-43788

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> ts-loader-9.5.1.tgz (Root Library)

   -> ❌ webpack-5.93.0.tgz (Vulnerable Library)

Medium 6.4 Transitive webpack-5.93.0.tgz ts-loader-9.5.1.tgz Transitive webpack - 5.94.0 None
CVE-2025-27789

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> js-19.7.3.tgz (Root Library)

   -> core-7.25.2.tgz

     -> ❌ helpers-7.25.0.tgz (Vulnerable Library)

Medium 6.2 Transitive helpers-7.25.0.tgz js-19.7.3.tgz Transitive 7.26.10 None
CVE-2025-27789

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> js-19.7.3.tgz (Root Library)

   -> ❌ runtime-7.25.0.tgz (Vulnerable Library)

Medium 6.2 Transitive runtime-7.25.0.tgz js-19.7.3.tgz Transitive 7.26.10 None
CVE-2025-27789

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> verdaccio-5.31.1.tgz (Root Library)

   -> config-7.0.0-next-7.16.tgz

     -> yup-0.32.11.tgz

       -> ❌ runtime-7.25.0.tgz (Vulnerable Library)

Medium 6.2 Transitive runtime-7.25.0.tgz verdaccio-5.31.1.tgz Transitive 7.26.10 None
CVE-2025-27789

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> container-metadata-6.0.2.tgz (Root Library)

   -> pep440-1.0.0.tgz

     -> xregexp-4.4.1.tgz

       -> ❌ runtime-corejs3-7.25.6.tgz (Vulnerable Library)

Medium 6.2 Transitive runtime-corejs3-7.25.6.tgz container-metadata-6.0.2.tgz Transitive 7.26.10 None
CVE-2025-27789

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> workspace-tools-1.179.6.tgz (Root Library)

   -> rollup-19.6.5.tgz

     -> js-19.6.5.tgz

       -> ❌ runtime-7.25.0.tgz (Vulnerable Library)

Medium 6.2 Transitive runtime-7.25.0.tgz workspace-tools-1.179.6.tgz Transitive 7.26.10 None
CVE-2025-56200

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> verdaccio-5.31.1.tgz (Root Library)

   -> ❌ validator-13.12.0.tgz (Vulnerable Library)

Medium 6.1 Transitive validator-13.12.0.tgz verdaccio-5.31.1.tgz Transitive validator - 13.15.20 None
CVE-2025-56200

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> verdaccio-5.31.1.tgz (Root Library)

   -> url-12.0.0-next-7.16.tgz

     -> ❌ validator-13.11.0.tgz (Vulnerable Library)

Medium 6.1 Transitive validator-13.11.0.tgz verdaccio-5.31.1.tgz Transitive validator - 13.15.20 None
CVE-2024-47068

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> workspace-tools-1.179.6.tgz (Root Library)

   -> ❌ rollup-4.18.0.tgz (Vulnerable Library)

Medium 6.1 Transitive rollup-4.18.0.tgz workspace-tools-1.179.6.tgz Transitive 4.22.3 None
CVE-2026-24001

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> ts-node-10.9.2.tgz (Root Library)

   -> ❌ diff-4.0.2.tgz (Vulnerable Library)

Medium 5.3 Transitive diff-4.0.2.tgz ts-node-10.9.2.tgz Transitive https://github.com/kpdecker/jsdiff.git - v4.0.4,https://github.com/kpdecker/jsdiff.git - v5.2.2,https://github.com/kpdecker/jsdiff.git - v8.0.3 None
CVE-2026-24001

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> js-19.7.3.tgz (Root Library)

   -> ts-node-10.9.1.tgz

     -> ❌ diff-4.0.2.tgz (Vulnerable Library)

Medium 5.3 Transitive diff-4.0.2.tgz js-19.7.3.tgz Transitive https://github.com/kpdecker/jsdiff.git - v4.0.4,https://github.com/kpdecker/jsdiff.git - v5.2.2,https://github.com/kpdecker/jsdiff.git - v8.0.3 None
CVE-2025-25290

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> container-metadata-6.0.2.tgz (Root Library)

   -> ci-context-6.0.1.tgz

     -> github-6.0.0.tgz

       -> core-5.2.0.tgz

         -> ❌ request-8.4.0.tgz (Vulnerable Library)

Medium 5.3 Transitive request-8.4.0.tgz container-metadata-6.0.2.tgz Transitive 8.4.1 None
CVE-2025-25289

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> container-metadata-6.0.2.tgz (Root Library)

   -> ci-context-6.0.1.tgz

     -> github-6.0.0.tgz

       -> core-5.2.0.tgz

         -> ❌ request-error-5.1.0.tgz (Vulnerable Library)

Medium 5.3 Transitive request-error-5.1.0.tgz container-metadata-6.0.2.tgz Transitive @octokit/request-error - 5.1.1,6.1.7 None
CVE-2025-25288

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> container-metadata-6.0.2.tgz (Root Library)

   -> ci-context-6.0.1.tgz

     -> github-6.0.0.tgz

       -> ❌ plugin-paginate-rest-9.2.1.tgz (Vulnerable Library)

Medium 5.3 Transitive plugin-paginate-rest-9.2.1.tgz container-metadata-6.0.2.tgz Transitive 9.2.2 None
CVE-2025-25285

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> container-metadata-6.0.2.tgz (Root Library)

   -> ci-context-6.0.1.tgz

     -> github-6.0.0.tgz

       -> core-5.2.0.tgz

         -> request-8.4.0.tgz

           -> ❌ endpoint-9.0.5.tgz (Vulnerable Library)

Medium 5.3 Transitive endpoint-9.0.5.tgz container-metadata-6.0.2.tgz Transitive @octokit/endpoint - 9.0.6,10.1.3 None
CVE-2024-47764

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> verdaccio-5.31.1.tgz (Root Library)

   -> express-4.19.2.tgz

     -> ❌ cookie-0.6.0.tgz (Vulnerable Library)

Medium 5.3 Transitive cookie-0.6.0.tgz verdaccio-5.31.1.tgz Transitive 0.7.0 None
CVE-2024-53384

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> workspace-tools-1.179.6.tgz (Root Library)

   -> ❌ tsup-8.0.0.tgz (Vulnerable Library)

Medium 5.1 Transitive tsup-8.0.0.tgz workspace-tools-1.179.6.tgz None
CVE-2024-43800

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> verdaccio-5.31.1.tgz (Root Library)

   -> express-4.19.2.tgz

     -> ❌ serve-static-1.15.0.tgz (Vulnerable Library)

Medium 5.0 Transitive serve-static-1.15.0.tgz verdaccio-5.31.1.tgz Transitive 1.16.0 None
CVE-2024-43799

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> verdaccio-5.31.1.tgz (Root Library)

   -> express-4.19.2.tgz

     -> ❌ send-0.18.0.tgz (Vulnerable Library)

Medium 5.0 Transitive send-0.18.0.tgz verdaccio-5.31.1.tgz Transitive 0.19.0 None
CVE-2024-43796

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> verdaccio-5.31.1.tgz (Root Library)

   -> ❌ express-4.19.2.tgz (Vulnerable Library)

Medium 5.0 Transitive express-4.19.2.tgz verdaccio-5.31.1.tgz Transitive 4.20.0 None
CVE-2024-55565

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> workspace-tools-1.179.6.tgz (Root Library)

   -> rollup-19.6.5.tgz

     -> postcss-8.4.45.tgz

       -> ❌ nanoid-3.3.7.tgz (Vulnerable Library)

Medium 4.3 Transitive nanoid-3.3.7.tgz workspace-tools-1.179.6.tgz Transitive 5.0.9 None
CVE-2024-55565

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> workspace-tools-1.179.6.tgz (Root Library)

   -> esbuild-11.1.4.tgz

     -> ❌ nanoid-5.0.7.tgz (Vulnerable Library)

Medium 4.3 Transitive nanoid-5.0.7.tgz workspace-tools-1.179.6.tgz Transitive 5.0.9 None
CVE-2025-7339

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> verdaccio-5.31.1.tgz (Root Library)

   -> compression-1.7.4.tgz

     -> ❌ on-headers-1.0.2.tgz (Vulnerable Library)

Low 3.4 Transitive on-headers-1.0.2.tgz verdaccio-5.31.1.tgz Transitive 1.1.0 None
CVE-2025-47279

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> container-metadata-6.0.2.tgz (Root Library)

   -> ci-context-6.0.1.tgz

     -> github-6.0.0.tgz

       -> http-client-2.2.3.tgz

         -> ❌ undici-5.28.4.tgz (Vulnerable Library)

Low 3.1 Transitive undici-5.28.4.tgz container-metadata-6.0.2.tgz Transitive 5.29.0 None
CVE-2025-54798

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> nx-container-6.0.2.tgz (Root Library)

   -> ❌ tmp-0.2.3.tgz (Vulnerable Library)

Low 2.5 Transitive tmp-0.2.3.tgz nx-container-6.0.2.tgz Transitive 0.2.4 None
CVE-2025-54798

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> git-tools-2.58.3.tgz (Root Library)

   -> inquirer-9.2.23.tgz

     -> external-editor-3.1.0.tgz

       -> ❌ tmp-0.0.33.tgz (Vulnerable Library)

Low 2.5 Transitive tmp-0.0.33.tgz git-tools-2.58.3.tgz Transitive 0.2.4 None
CVE-2025-54798

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> workspace-tools-1.179.6.tgz (Root Library)

   -> rollup-19.6.5.tgz

     -> devkit-19.6.5.tgz

       -> ❌ tmp-0.2.3.tgz (Vulnerable Library)

Low 2.5 Transitive tmp-0.2.3.tgz workspace-tools-1.179.6.tgz Transitive 0.2.4 None
CVE-2025-54798

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> rust-1.4.0.tgz (Root Library)

   -> nx-18.1.0-beta.2.tgz

     -> ❌ tmp-0.2.3.tgz (Vulnerable Library)

Low 2.5 Transitive tmp-0.2.3.tgz rust-1.4.0.tgz Transitive 0.2.4 #7
CVE-2025-54798

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> devkit-19.7.3.tgz (Root Library)

   -> ❌ tmp-0.2.3.tgz (Vulnerable Library)

Low 2.5 Transitive tmp-0.2.3.tgz devkit-19.7.3.tgz Transitive 0.2.4 None
CVE-2025-54798

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> nx-19.7.3.tgz (Root Library)

   -> ❌ tmp-0.2.3.tgz (Vulnerable Library)

Low 2.5 Transitive tmp-0.2.3.tgz nx-19.7.3.tgz Transitive 0.2.4 None

Base branch total remaining vulnerabilities: 20
Base branch commit: null


Total libraries scanned: 2196

Scan token: 22f536704f9c4c0faa8a1fa6a0e7f63c