Skip to content

Update dependency standard to ^12.0.1 - #243

Open
ghost wants to merge 1 commit into
masterfrom
whitesource-remediate/standard-12.x
Open

Update dependency standard to ^12.0.1#243
ghost wants to merge 1 commit into
masterfrom
whitesource-remediate/standard-12.x

Update dependency standard to ^12.0.1

96a513b
Select commit
Loading
Failed to load commit list.
Deleted GitHub App / Mend Security Check failed Jan 29, 2026 in 3m 36s

Security Report

The Security Check found 30 vulnerabilities.

Vulnerability Severity CVSS Score Exploit Maturity EPSS Vulnerable Library Direct Library Suggested Fix Issue
CVE-2025-13465

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> ❌ lodash-4.17.11.tgz (Vulnerable Library)

Critical 9.9 Not Defined 0.1% Direct lodash-4.17.11.tgz lodash-4.17.11.tgz lodash-amd - 4.17.23,lodash - 4.17.23,lodash-es - 4.17.23 None
CVE-2021-44906

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> couchbase-driver-0.5.2.tgz (Root Library)

   -> couchbase-2.6.5.tgz

     -> prebuild-install-5.3.0.tgz

       -> ❌ minimist-1.2.0.tgz (Vulnerable Library)

Critical 9.8 Not Defined 0.9% Transitive minimist-1.2.0.tgz couchbase-driver-0.5.2.tgz Transitive 0.2.4 None
CVE-2021-44906

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> couchbase-driver-0.5.2.tgz (Root Library)

   -> couchbase-2.6.5.tgz

     -> prebuild-install-5.3.0.tgz

       -> mkdirp-0.5.1.tgz

         -> ❌ minimist-0.0.8.tgz (Vulnerable Library)

Critical 9.8 Not Defined 0.9% Transitive minimist-0.0.8.tgz couchbase-driver-0.5.2.tgz Transitive 0.2.4 None
CVE-2021-3918

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> couchbase-driver-0.5.2.tgz (Root Library)

   -> couchbase-2.6.5.tgz

     -> request-2.88.0.tgz

       -> http-signature-1.2.0.tgz

         -> jsprim-1.4.1.tgz

           -> ❌ json-schema-0.2.3.tgz (Vulnerable Library)

Critical 9.8 Not Defined 1.2% Transitive json-schema-0.2.3.tgz couchbase-driver-0.5.2.tgz Transitive 0.4.0 None
CVE-2022-0355

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> couchbase-driver-0.5.2.tgz (Root Library)

   -> couchbase-2.6.5.tgz

     -> prebuild-install-5.3.0.tgz

       -> ❌ simple-get-2.8.1.tgz (Vulnerable Library)

High 8.8 Not Defined 0.5% Transitive simple-get-2.8.1.tgz couchbase-driver-0.5.2.tgz Transitive simple-get - 3.1.1,simple-get - 4.0.1,simple-get - 2.8.2 None
CVE-2025-7783

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> couchbase-driver-0.5.2.tgz (Root Library)

   -> couchbase-2.6.5.tgz

     -> request-2.88.0.tgz

       -> ❌ form-data-2.3.3.tgz (Vulnerable Library)

High 8.7 Not Defined 0.2% Transitive form-data-2.3.3.tgz couchbase-driver-0.5.2.tgz Transitive 2.5.4 None
CVE-2021-43138

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> couchbase-driver-0.5.2.tgz (Root Library)

   -> ❌ async-2.6.2.tgz (Vulnerable Library)

High 7.8 Not Defined 0.70000005% Transitive async-2.6.2.tgz couchbase-driver-0.5.2.tgz Transitive 2.6.4 None
WS-2021-0152

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> couchbase-driver-0.5.2.tgz (Root Library)

   -> couchbase-2.6.5.tgz

     -> winston-3.2.1.tgz

       -> diagnostics-1.1.1.tgz

         -> colorspace-1.1.2.tgz

           -> color-3.0.0.tgz

             -> ❌ color-string-1.5.3.tgz (Vulnerable Library)

High 7.5 Not Defined Transitive color-string-1.5.3.tgz couchbase-driver-0.5.2.tgz Transitive 1.5.5 None
CVE-2025-59343

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> couchbase-driver-0.5.2.tgz (Root Library)

   -> couchbase-2.6.5.tgz

     -> prebuild-install-5.3.0.tgz

       -> ❌ tar-fs-1.16.3.tgz (Vulnerable Library)

High 7.5 Not Defined 0.0% Transitive tar-fs-1.16.3.tgz couchbase-driver-0.5.2.tgz Transitive 1.16.6 None
CVE-2025-48387

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> couchbase-driver-0.5.2.tgz (Root Library)

   -> couchbase-2.6.5.tgz

     -> prebuild-install-5.3.0.tgz

       -> ❌ tar-fs-1.16.3.tgz (Vulnerable Library)

High 7.5 Not Defined 0.2% Transitive tar-fs-1.16.3.tgz couchbase-driver-0.5.2.tgz Transitive tar-fs - 1.16.5,https://github.com/mafintosh/tar-fs.git - v3.0.9,https://github.com/mafintosh/tar-fs.git - v1.16.5,tar-fs - 3.0.9,tar-fs - 2.1.3,https://github.com/mafintosh/tar-fs.git - v2.1.3 None
CVE-2025-15284

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> couchbase-driver-0.5.2.tgz (Root Library)

   -> couchbase-2.6.5.tgz

     -> request-2.88.0.tgz

       -> ❌ qs-6.5.2.tgz (Vulnerable Library)

High 7.5 Not Defined 0.2% Transitive qs-6.5.2.tgz couchbase-driver-0.5.2.tgz Transitive 6.14.1 None
CVE-2024-12905

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> couchbase-driver-0.5.2.tgz (Root Library)

   -> couchbase-2.6.5.tgz

     -> prebuild-install-5.3.0.tgz

       -> ❌ tar-fs-1.16.3.tgz (Vulnerable Library)

High 7.5 Not Defined 1.3000001% Transitive tar-fs-1.16.3.tgz couchbase-driver-0.5.2.tgz Transitive 1.16.4 None
CVE-2022-24999

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> couchbase-driver-0.5.2.tgz (Root Library)

   -> couchbase-2.6.5.tgz

     -> request-2.88.0.tgz

       -> ❌ qs-6.5.2.tgz (Vulnerable Library)

High 7.5 Not Defined 1.4000001% Transitive qs-6.5.2.tgz couchbase-driver-0.5.2.tgz Transitive 6.5.3 None
CVE-2021-3807

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> couchbase-driver-0.5.2.tgz (Root Library)

   -> couchbase-2.6.5.tgz

     -> prebuild-install-5.3.0.tgz

       -> npmlog-4.1.2.tgz

         -> gauge-2.7.4.tgz

           -> wide-align-1.1.3.tgz

             -> string-width-2.1.1.tgz

               -> strip-ansi-4.0.0.tgz

                 -> ❌ ansi-regex-3.0.0.tgz (Vulnerable Library)

High 7.5 Not Defined 0.2% Transitive ansi-regex-3.0.0.tgz couchbase-driver-0.5.2.tgz Transitive ansi-regex - 5.0.1,ansi-regex - 3.0.1,ansi-regex - 6.0.1,ansi-regex - 4.1.1 None
CVE-2020-8203

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> ❌ lodash-4.17.11.tgz (Vulnerable Library)

High 7.4 Not Defined 2.5% Direct lodash-4.17.11.tgz lodash-4.17.11.tgz 4.17.19 None
CVE-2020-7788

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> couchbase-driver-0.5.2.tgz (Root Library)

   -> couchbase-2.6.5.tgz

     -> prebuild-install-5.3.0.tgz

       -> rc-1.2.8.tgz

         -> ❌ ini-1.3.5.tgz (Vulnerable Library)

High 7.3 Proof of concept 0.3% Transitive ini-1.3.5.tgz couchbase-driver-0.5.2.tgz Transitive 1.3.6 None
CVE-2021-23337

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> ❌ lodash-4.17.11.tgz (Vulnerable Library)

High 7.2 Proof of concept 0.70000005% Direct lodash-4.17.11.tgz lodash-4.17.11.tgz 4.17.21 None
CVE-2023-26136

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> couchbase-driver-0.5.2.tgz (Root Library)

   -> couchbase-2.6.5.tgz

     -> request-2.88.0.tgz

       -> ❌ tough-cookie-2.4.3.tgz (Vulnerable Library)

Medium 6.5 Proof of concept 6.8999996% Transitive tough-cookie-2.4.3.tgz couchbase-driver-0.5.2.tgz Transitive 4.1.3 None
CVE-2020-8244

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> couchbase-driver-0.5.2.tgz (Root Library)

   -> couchbase-2.6.5.tgz

     -> prebuild-install-5.3.0.tgz

       -> tar-fs-1.16.3.tgz

         -> tar-stream-1.6.2.tgz

           -> ❌ bl-1.2.2.tgz (Vulnerable Library)

Medium 6.5 Not Defined 0.4% Transitive bl-1.2.2.tgz couchbase-driver-0.5.2.tgz Transitive 1.2.3 None
CVE-2023-28155

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> couchbase-driver-0.5.2.tgz (Root Library)

   -> couchbase-2.6.5.tgz

     -> ❌ request-2.88.0.tgz (Vulnerable Library)

Medium 6.1 Not Defined 0.6% Transitive request-2.88.0.tgz couchbase-driver-0.5.2.tgz Transitive @cypress/request - 3.0.0 None
CVE-2021-23438

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> ❌ mpath-0.6.0.tgz (Vulnerable Library)

Medium 5.6 Proof of concept 0.5% Direct mpath-0.6.0.tgz mpath-0.6.0.tgz 0.8.4 None
CVE-2020-7598

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> couchbase-driver-0.5.2.tgz (Root Library)

   -> couchbase-2.6.5.tgz

     -> prebuild-install-5.3.0.tgz

       -> ❌ minimist-1.2.0.tgz (Vulnerable Library)

Medium 5.6 Not Defined 0.3% Transitive minimist-1.2.0.tgz couchbase-driver-0.5.2.tgz Transitive 0.2.1 None
CVE-2020-7598

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> couchbase-driver-0.5.2.tgz (Root Library)

   -> couchbase-2.6.5.tgz

     -> prebuild-install-5.3.0.tgz

       -> mkdirp-0.5.1.tgz

         -> ❌ minimist-0.0.8.tgz (Vulnerable Library)

Medium 5.6 Not Defined 0.3% Transitive minimist-0.0.8.tgz couchbase-driver-0.5.2.tgz Transitive 0.2.1 None
CVE-2020-15366

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> couchbase-driver-0.5.2.tgz (Root Library)

   -> couchbase-2.6.5.tgz

     -> request-2.88.0.tgz

       -> har-validator-5.1.3.tgz

         -> ❌ ajv-6.10.0.tgz (Vulnerable Library)

Medium 5.6 Not Defined 0.4% Transitive ajv-6.10.0.tgz couchbase-driver-0.5.2.tgz Transitive 6.12.3 None
CVE-2022-25883

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> couchbase-driver-0.5.2.tgz (Root Library)

   -> ❌ semver-5.7.0.tgz (Vulnerable Library)

Medium 5.3 Proof of concept 0.6% Transitive semver-5.7.0.tgz couchbase-driver-0.5.2.tgz Transitive 5.7.2 None
CVE-2021-29060

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> couchbase-driver-0.5.2.tgz (Root Library)

   -> couchbase-2.6.5.tgz

     -> winston-3.2.1.tgz

       -> diagnostics-1.1.1.tgz

         -> colorspace-1.1.2.tgz

           -> color-3.0.0.tgz

             -> ❌ color-string-1.5.3.tgz (Vulnerable Library)

Medium 5.3 Not Defined 0.3% Transitive color-string-1.5.3.tgz couchbase-driver-0.5.2.tgz Transitive 1.5.5 None
CVE-2020-28500

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> ❌ lodash-4.17.11.tgz (Vulnerable Library)

Medium 5.3 Proof of concept 0.2% Direct lodash-4.17.11.tgz lodash-4.17.11.tgz lodash - 4.17.21,lodash-es - 4.17.21,lodash-rails - 4.17.21 None
CVE-2017-16137

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> couchbase-driver-0.5.2.tgz (Root Library)

   -> ❌ debug-3.2.6.tgz (Vulnerable Library)

Low 3.7 Not Defined 0.1% Transitive debug-3.2.6.tgz couchbase-driver-0.5.2.tgz Transitive 3.2.7 None
CVE-2017-16137

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> ❌ debug-4.1.1.tgz (Vulnerable Library)

Low 3.7 Not Defined 0.1% Direct debug-4.1.1.tgz debug-4.1.1.tgz 4.3.1 None
CVE-2024-27088

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> memoizee-0.4.14.tgz (Root Library)

   -> ❌ es5-ext-0.10.50.tgz (Vulnerable Library)

Low 0.0 Not Defined 1.8% Transitive es5-ext-0.10.50.tgz memoizee-0.4.14.tgz None

Total libraries scanned: 167
Scan token: 01ca6ea5fe9d43be8bad5e498271a3d5