fix(deps): update dependency opentok to ^2.23.2 (main) - #399
fix(deps): update dependency opentok to ^2.23.2 (main)#399mend-for-github-com[bot] wants to merge 1 commit into
Security Report
❗️Scan Warnings: The scan completed with warnings. The integration encountered issues with one or more projects in this repository. Consequently, there may be gaps in the coverage of open-source dependencies used in the repository.
Scan Details Report
general
vcr.vonage.cloud
| Step | Level | Description | Details |
|---|---|---|---|
| Checking registry connectivity | ⚠Warn | Unsupported configuration was provided | unsupported host type docker, skipped |
❌ New vulnerabilities:
| Vulnerability | Severity | Exploit Maturity | EPSS | Vulnerable Library | Direct Library | Suggested Fix | Issue | Reachability | |
|---|---|---|---|---|---|---|---|---|---|
CVE-2026-41907Path to dependency file: /sample/SipInterconnect/package.json Path to vulnerable library: /sample/SipInterconnect/node_modules/@vonage/jwt/node_modules/uuid/package.json Dependency Hierarchy: -> opentok-2.23.2.tgz (Root Library) -> jwt-1.14.0.tgz -> ❌ uuid-13.0.0.tgz (Vulnerable Library) |
9.8 | Not Defined | 0.337% | Transitive uuid-13.0.0.tgz |
opentok-2.23.2.tgz | Transitive https://github.com/uuidjs/uuid.git - v11.1.1,https://github.com/uuidjs/uuid.git - v12.0.1,https://github.com/uuidjs/uuid.git - v13.0.1 |
None | ||
CVE-2026-41988Path to dependency file: /sample/SipInterconnect/package.json Path to vulnerable library: /sample/SipInterconnect/node_modules/@vonage/jwt/node_modules/uuid/package.json Dependency Hierarchy: -> opentok-2.23.2.tgz (Root Library) -> jwt-1.14.0.tgz -> ❌ uuid-13.0.0.tgz (Vulnerable Library) |
3.2 | Not Defined | 0.181% | Transitive uuid-13.0.0.tgz |
opentok-2.23.2.tgz | Transitive uuid - 11.1.1,uuid - 11.1.1,uuid - 12.0.1,uuid - 12.0.1 |
None |
✔️ Remediated vulnerabilities:
| Vulnerability | Vulnerable Library |
|---|---|
| CVE-2026-12590 | body-parser-1.20.5.tgz |
| CVE-2025-13465 | lodash-4.17.21.tgz |
| CVE-2026-2950 | lodash-4.17.21.tgz |
| CVE-2026-4800 | lodash-4.17.21.tgz |
Base branch total remaining vulnerabilities: 19
Base branch commit: e7db0761cc23ecb7ba50b19a8291cb1b91c9e94a
Total libraries scanned: 153
Scan token: e5a1f9153c694c348a0cf0c981346d65