chore(dependency): update carbon-components-react version to remove wicg-inert security alert #11947
Security Report
You have successfully remediated 1 vulnerabilities, but introduced 5 new vulnerabilities in this branch.
❌ New vulnerabilities:
CVE | Severity | Vulnerable Library | Suggested Fix | Issue | |
---|---|---|---|---|---|
CVE-2024-4068Path to dependency file: /package.json Path to vulnerable library: /.yarn/cache/braces-npm-3.0.2-782240b28a-966b1fb48d.zip Dependency Hierarchy: -> @carbon/eslint-config-ibmdotcom-1.45.1.tgz (Root Library) -> parser-5.62.0.tgz -> typescript-estree-5.62.0.tgz -> globby-11.1.0.tgz -> fast-glob-3.3.2.tgz -> micromatch-4.0.5.tgz -> ❌ braces-3.0.2.tgz (Vulnerable Library) |
7.5 | braces-3.0.2.tgz | Upgrade to version: braces - 3.0.3 | None | |
CVE-2024-37890Path to dependency file: /package.json Path to vulnerable library: /.yarn/cache/ws-npm-8.14.2-b339ac47a2-815ff01d9b.zip Dependency Hierarchy: -> ibmdotcom-utilities-1.61.0.tgz (Root Library) -> isomorphic-dompurify-0.27.0.tgz -> jsdom-21.1.2.tgz -> ❌ ws-8.14.2.tgz (Vulnerable Library) |
7.5 | ws-8.14.2.tgz | Upgrade to version: ws - 5.2.4,6.2.3,7.5.10,8.17.1 | None | |
CVE-2024-28849Path to dependency file: /package.json Path to vulnerable library: /.yarn/cache/follow-redirects-npm-1.15.3-ca69c47b72-60d98693f4.zip Dependency Hierarchy: -> ibmdotcom-react-1.61.0.tgz (Root Library) -> ibmdotcom-services-1.54.0.tgz -> axios-1.6.2.tgz -> ❌ follow-redirects-1.15.3.tgz (Vulnerable Library) |
6.5 | follow-redirects-1.15.3.tgz | Upgrade to version: follow-redirects - 1.15.6 | None | |
CVE-2023-26159Path to dependency file: /package.json Path to vulnerable library: /.yarn/cache/follow-redirects-npm-1.15.3-ca69c47b72-60d98693f4.zip Dependency Hierarchy: -> ibmdotcom-react-1.61.0.tgz (Root Library) -> ibmdotcom-services-1.54.0.tgz -> axios-1.6.2.tgz -> ❌ follow-redirects-1.15.3.tgz (Vulnerable Library) |
6.1 | follow-redirects-1.15.3.tgz | Upgrade to version: follow-redirects - 1.15.4 | None | |
CVE-2024-4067Path to dependency file: /package.json Path to vulnerable library: /.yarn/cache/micromatch-npm-4.0.5-cfab5d7669-a749888789.zip Dependency Hierarchy: -> @carbon/eslint-config-ibmdotcom-1.45.1.tgz (Root Library) -> parser-5.62.0.tgz -> typescript-estree-5.62.0.tgz -> globby-11.1.0.tgz -> fast-glob-3.3.2.tgz -> ❌ micromatch-4.0.5.tgz (Vulnerable Library) |
5.3 | micromatch-4.0.5.tgz | Upgrade to version: micromatch - 4.0.6 | None |
✔️ Remediated vulnerabilities:
CVE | Vulnerable Library |
---|---|
CVE-2023-45857 | axios-0.27.2.tgz |
Base branch total remaining vulnerabilities: 8
Base branch commit: 98d3d24f5a32a3eaa656f67fb411f80066520079
Total libraries scanned: 523
Scan token: 9e1baccbe00f496697e5b561d638cc75