-
Dependency advisory GHSA-qffp-2rhf-9h96:pkg:b8a9dfa218123c667676179f applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason: osv-structured-advisory · Execution scope: unknown
Source: package-lock.json
-
Dependency advisory GHSA-89xv-2m56-2m9x:pkg:5b1ac1fd9db08f5b86ebaafe applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason: osv-structured-advisory · Execution scope: unknown
Source: package-lock.json
-
Dependency advisory GHSA-8h8q-6873-q5fj:pkg:f77a6eb5f2ac7549ef4877f3 applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason: osv-structured-advisory · Execution scope: unknown
Source: package-lock.json
-
Dependency advisory GHSA-c4j6-fc7j-m34r:pkg:bdac127f23e350f80a3d1dbd applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason: osv-structured-advisory · Execution scope: unknown
Source: package-lock.json
-
Dependency advisory GHSA-mg66-mrh9-m8jx:pkg:4cf9e9e6591eaa696b5e4a33 applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason: osv-structured-advisory · Execution scope: unknown
Source: package-lock.json
-
Dependency advisory GHSA-3x4c-7xq6-9pq8:pkg:4b733a691492176e97e3f072 applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason: osv-structured-advisory · Execution scope: unknown
Source: package-lock.json
-
Dependency advisory GHSA-p9j2-gv94-2wf4:pkg:1d22bffd3d5eac077b08ffa7 applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason: osv-structured-advisory · Execution scope: unknown
Source: package-lock.json
-
Dependency advisory GHSA-gx5p-jg67-6x7h:pkg:d57da893be68205fe3b77c3e applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason: osv-structured-advisory · Execution scope: unknown
Source: package-lock.json
-
Dependency advisory GHSA-83g3-92jg-28cx:pkg:36f09712c5b19d62e2f59e39 applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason: osv-structured-advisory · Execution scope: unknown
Source: package-lock.json
-
Dependency advisory GHSA-ffhc-5mcf-pf4q:pkg:372ee89e8a3bfd1d98f225e9 applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason: osv-structured-advisory · Execution scope: unknown
Source: package-lock.json
-
Dependency advisory GHSA-vfv6-92ff-j949:pkg:2554c23a948730e2e9cefe59 applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason: osv-structured-advisory · Execution scope: unknown
Source: package-lock.json
-
Dependency advisory GHSA-w8wr-v893-vjvp:pkg:7da9495751fdc3bf9c299678 applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason: osv-structured-advisory · Execution scope: unknown
Source: package-lock.json
-
Dependency advisory GHSA-fxqj-rqcc-2cmp:pkg:7959fb9a1bc8af5373375c68 applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason: osv-structured-advisory · Execution scope: unknown
Source: package-lock.json
-
Dependency advisory GHSA-r28c-9q8g-f849:pkg:360555c0ae88de313e4744d6 applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason: osv-structured-advisory · Execution scope: unknown
Source: package-lock.json
-
Dependency advisory GHSA-wfc6-r584-vfw7:pkg:5df144f11378a6de2a304d35 applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason: osv-structured-advisory · Execution scope: unknown
Source: package-lock.json
-
Dependency advisory GHSA-r292-9mhp-454m:pkg:8aad2ce7479d51345c7e63a2 applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason: osv-structured-advisory · Execution scope: unknown
Source: package-lock.json
-
zizmor reported unpinned-uses · zizmor 1.28.0
The code has a known weakness, though this scan does not show that anyone can exploit it here.
Policy reason: zizmor-known-workflow-rule · Execution scope: automation
Source: .github/workflows/code-quality.yml:14
-
Dependency advisory GHSA-hmw2-7cc7-3qxx:pkg:3e7f45362673a63a999c49dc applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason: osv-structured-advisory · Execution scope: unknown
Source: package-lock.json
-
Dependency advisory GHSA-r28c-9q8g-f849:pkg:70fb8de3530fd7e78865a130 applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason: osv-structured-advisory · Execution scope: unknown
Source: package-lock.json
-
zizmor reported excessive-permissions · zizmor 1.28.0
The code has a known weakness, though this scan does not show that anyone can exploit it here.
Policy reason: zizmor-known-workflow-rule · Execution scope: automation
Source: .github/workflows/code-quality.yml:8-17
-
Dependency advisory GHSA-ggv3-7p47-pfv8:pkg:b3e02dfcc9fde865a31a9192 applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason: osv-structured-advisory · Execution scope: unknown
Source: package-lock.json
-
Dependency advisory GHSA-267c-6grr-h53f:pkg:7b05c31c29a7d4d0e079950b applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason: osv-structured-advisory · Execution scope: unknown
Source: package-lock.json
-
Dependency advisory GHSA-36qx-fr4f-26g5:pkg:1a7f97cc5949b4d6e6094cc2 applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason: osv-structured-advisory · Execution scope: unknown
Source: package-lock.json
-
Dependency advisory GHSA-34x7-hfp2-rc4v:pkg:7d77323718139b4267d31b2f applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason: osv-structured-advisory · Execution scope: unknown
Source: package-lock.json
-
Dependency advisory GHSA-qx2v-qp2m-jg93:pkg:e21c031ac1b5a36fba7dab3b applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason: osv-structured-advisory · Execution scope: unknown
Source: package-lock.json
-
Dependency advisory GHSA-fxqj-rqcc-2cmp:pkg:38ebb15695df9277a6893d88 applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason: osv-structured-advisory · Execution scope: unknown
Source: package-lock.json
-
zizmor reported unpinned-uses · zizmor 1.28.0
The code has a known weakness, though this scan does not show that anyone can exploit it here.
Policy reason: zizmor-known-workflow-rule · Execution scope: automation
Source: .github/workflows/code-quality.yml:12
-
Dependency advisory GHSA-r6q2-hw4h-h46w:pkg:2f480be16e90e43ab1f41308 applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason: osv-structured-advisory · Execution scope: unknown
Source: package-lock.json
-
Dependency advisory GHSA-955p-x3mx-jcvp:pkg:59ac450044b7d40ca1fa6b7e applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason: osv-structured-advisory · Execution scope: unknown
Source: package-lock.json
-
Dependency advisory GHSA-8x88-c5mf-7j5w:pkg:b62ceba241cb26d52e12cb4d applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason: osv-structured-advisory · Execution scope: unknown
Source: package-lock.json
-
Dependency advisory GHSA-6g55-p6wh-862q:pkg:a8b590e130400cc9d5d7c34a applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason: osv-structured-advisory · Execution scope: unknown
Source: package-lock.json
-
Dependency advisory GHSA-9qr9-h5gf-34mp:pkg:3ae60a5607057aa4655e7779 applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason: osv-structured-advisory · Execution scope: unknown
Source: package-lock.json
-
Dependency advisory GHSA-f88m-g3jw-g9cj:pkg:ec0392f9cb3406d583b7ad8b applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason: osv-structured-advisory · Execution scope: unknown
Source: package-lock.json
-
Dependency advisory GHSA-6g55-p6wh-862q:pkg:1462d68968dddb5a77b9811d applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason: osv-structured-advisory · Execution scope: unknown
Source: package-lock.json
-
Dependency advisory GHSA-mwv6-3258-q52c:pkg:d51f28e828662666bae1f821 applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason: osv-structured-advisory · Execution scope: unknown
Source: package-lock.json
-
Dependency advisory GHSA-r5fr-rjxr-66jc:pkg:acc54e333efad0fdcbcc3646 applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason: osv-structured-advisory · Execution scope: unknown
Source: package-lock.json
-
Dependency advisory GHSA-gvwx-54wh-qm9j:pkg:9f7caa8dc32d63903b95a9a9 applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason: osv-structured-advisory · Execution scope: unknown
Source: package-lock.json
-
Dependency advisory GHSA-26hh-7cqf-hhc6:pkg:ca74400e969a6ca7726763b5 applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason: osv-structured-advisory · Execution scope: unknown
Source: package-lock.json
-
Dependency advisory GHSA-9ppj-qmqm-q256:pkg:1639a1de3213e0c21e655085 applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason: osv-structured-advisory · Execution scope: unknown
Source: package-lock.json
-
Dependency advisory GHSA-4fh9-h7wg-q85m:pkg:4d8459dc2ecf00c2431e57c8 applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason: osv-structured-advisory · Execution scope: unknown
Source: package-lock.json
-
Dependency advisory GHSA-w37m-7fhw-fmv9:pkg:41fc7a0f6f66d267193d1861 applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason: osv-structured-advisory · Execution scope: unknown
Source: package-lock.json
-
Dependency advisory GHSA-4633-3j49-mh5q:pkg:64a25a01f17e6e83f0dd52e3 applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason: osv-structured-advisory · Execution scope: unknown
Source: package-lock.json
-
Dependency advisory GHSA-28wg-ghj8-5hjv:pkg:006e2a19c763cc0fc17b9679 applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason: osv-structured-advisory · Execution scope: unknown
Source: package-lock.json
-
Dependency advisory GHSA-q4gf-8mx6-v5v3:pkg:f3eeaa8a565065e473679cd5 applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason: osv-structured-advisory · Execution scope: unknown
Source: package-lock.json
-
Dependency advisory GHSA-vmf3-w455-68vh:pkg:dd6d5893824d975d2c6210e6 applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason: osv-structured-advisory · Execution scope: unknown
Source: package-lock.json
-
Dependency advisory GHSA-m99w-x7hq-7vfj:pkg:4595a0ef7c52b552590f1790 applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason: osv-structured-advisory · Execution scope: unknown
Source: package-lock.json
-
Dependency advisory GHSA-2v37-7h3g-55p8:pkg:a9b17cadf83e3a5de547592b applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason: osv-structured-advisory · Execution scope: unknown
Source: package-lock.json
-
Dependency advisory GHSA-h64f-5h5j-jqjh:pkg:7d307610f7130aa3b7143037 applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason: osv-structured-advisory · Execution scope: unknown
Source: package-lock.json
-
Dependency advisory GHSA-xxjr-mmjv-4gpg:pkg:e49a21569220bc1e9110dc78 applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason: osv-structured-advisory · Execution scope: unknown
Source: package-lock.json
-
Dependency advisory GHSA-9g9p-9gw9-jx7f:pkg:672999e862e7cb864158084e applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason: osv-structured-advisory · Execution scope: unknown
Source: package-lock.json
-
Dependency advisory GHSA-4c39-4ccg-62r3:pkg:6bd4d03d799f2e8456398f1e applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason: osv-structured-advisory · Execution scope: unknown
Source: package-lock.json
-
Dependency advisory GHSA-c2c7-rcm5-vvqj:pkg:09f761f2e2a83fdc7890eb5a applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason: osv-structured-advisory · Execution scope: unknown
Source: package-lock.json
-
Dependency advisory GHSA-23hp-3jrh-7fpw:pkg:d289a4bb35ce0915785e983b applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason: osv-structured-advisory · Execution scope: unknown
Source: package-lock.json
-
Dependency advisory GHSA-h25m-26qc-wcjf:pkg:5a8b9d46861e3d04fe3dd2d6 applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason: osv-structured-advisory · Execution scope: unknown
Source: package-lock.json
-
Dependency advisory GHSA-3v7f-55p6-f55p:pkg:972939a004a2a625fbda61c7 applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason: osv-structured-advisory · Execution scope: unknown
Source: package-lock.json
-
Dependency advisory GHSA-68g3-v927-f742:pkg:f3e6099978d352bf35aca521 applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason: osv-structured-advisory · Execution scope: unknown
Source: package-lock.json
-
Dependency advisory GHSA-qx2v-qp2m-jg93:pkg:09f18d20b7749a3207eefd02 applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason: osv-structured-advisory · Execution scope: unknown
Source: package-lock.json
-
Dependency advisory GHSA-8qq5-rm4j-mr97:pkg:710f4f4c5e1ba205aa530c13 applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason: osv-structured-advisory · Execution scope: unknown
Source: package-lock.json
-
Dependency advisory GHSA-f23m-r3pf-42rh:pkg:bf40c9910aa3de0f3855d6c9 applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason: osv-structured-advisory · Execution scope: unknown
Source: package-lock.json
-
Dependency advisory GHSA-3g8h-86w9-wvmq:pkg:a2084b16e1bbcb64748fe80b applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason: osv-structured-advisory · Execution scope: unknown
Source: package-lock.json
-
zizmor reported artipacked · zizmor 1.28.0
The code has a known weakness, though this scan does not show that anyone can exploit it here.
Policy reason: zizmor-known-workflow-rule · Execution scope: automation
Source: .github/workflows/code-quality.yml:11-12
-
Dependency advisory GHSA-492v-c6pp-mqqv:pkg:d992343c14ae361674c2ac9a applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason: osv-structured-advisory · Execution scope: unknown
Source: package-lock.json