Update dependency commons-io:commons-io to v2.14.0 #508
Mend for GitHub.com / WhiteSource Security Check
failed
Oct 10, 2024 in 3m 31s
Security Report
You have successfully remediated 2 vulnerabilities, but introduced 1 new vulnerabilities in this branch.
❌ New vulnerabilities:
CVE | Severity | CVSS Score | Vulnerable Library | Suggested Fix | Issue |
---|---|---|---|---|---|
CVE-2024-6484Path to dependency file: /api/pacman-api-auth/pom.xml Path to vulnerable library: /api/pacman-api-auth/pom.xml Dependency Hierarchy: -> ❌ bootstrap-3.3.2.jar (Vulnerable Library) |
Medium | 6.4 | bootstrap-3.3.2.jar | Upgrade to version: org.webjars.npm:bootstrap - 4.0.0-alpha.2;bootstrap.sass - 4.0.0-alpha;twbs/bootstrap - dev-dependabot/npm_and_yarn/rtlcss-3.1.1,dev-dependabot/npm_and_yarn/nodemon-3.1.3,dev-XhmikosR-patch-3,dev-dependabot/npm_and_yarn/rtlcss-3.4.0,dev-dependabot/npm_and_yarn/find-unused-sass-variables-3.1.0,dev-dependabot/npm_and_yarn/linkinator-2.4.0,dev-dependabot/npm_and_yarn/rollup-3.5.0,dev-dependabot/npm_and_yarn/nodemon-3.0.1,dev-dependabot/npm_and_yarn/rollup-3.2.5,dev-dependabot/npm_and_yarn/nodemon-3.0.2,dev-dependabot/npm_and_yarn/nodemon-3.0.3;bootstrap - 4.0.0;bootstrap - 3.3.6-jQuery3,4.0.0-alpha;org.webjars:bootstrap - 4.0.0-alpha | None |
✔️ Remediated vulnerabilities:
CVE | Vulnerable Library |
---|---|
CVE-2021-29425 | commons-io-2.5.jar |
CVE-2024-47554 | commons-io-2.5.jar |
Base branch total remaining vulnerabilities: 474
Base branch commit: acf9a0620c1a37cee4f2896d71e1c3731c5c7b06
Total libraries scanned: 377
Scan token: e90480fd79764ede9804ebea1550ac73
Loading