Skip to content

fix(deps): update dependency opentok to ^2.23.2 (main) - #399

Open
mend-for-github-com[bot] wants to merge 1 commit into
mainfrom
whitesource-remediate/main-opentok-2.x
Open

fix(deps): update dependency opentok to ^2.23.2 (main)#399
mend-for-github-com[bot] wants to merge 1 commit into
mainfrom
whitesource-remediate/main-opentok-2.x

fix(deps): update dependency opentok to ^2.23.2

0757458
Select commit
Loading
Failed to load commit list.
Mend for GitHub.com / WhiteSource Security Check failed Jul 12, 2026 in 1m 56s

Security Report

❗️Scan Warnings: The scan completed with warnings. The integration encountered issues with one or more projects in this repository. Consequently, there may be gaps in the coverage of open-source dependencies used in the repository.

Scan Details Report

general

vcr.vonage.cloud

Step Level Description Details
Checking registry connectivity ⚠Warn Unsupported configuration was provided unsupported host type docker, skipped

You have successfully remediated 4 vulnerabilities, but introduced 2 new vulnerabilities in this branch.

❌ New vulnerabilities:
Vulnerability Severity CVSS Score Exploit Maturity EPSS Vulnerable Library Direct Library Suggested Fix Issue Reachability
CVE-2026-41907

Path to dependency file: /sample/SipInterconnect/package.json

Path to vulnerable library: /sample/SipInterconnect/node_modules/@⁠vonage/jwt/node_modules/uuid/package.json

Dependency Hierarchy:

-> opentok-2.23.2.tgz (Root Library)

   -> jwt-1.14.0.tgz

     -> ❌ uuid-13.0.0.tgz (Vulnerable Library)

Critical 9.8 Not Defined 0.337% Transitive uuid-13.0.0.tgz opentok-2.23.2.tgz Transitive https://github.com/uuidjs/uuid.git - v11.1.1,https://github.com/uuidjs/uuid.git - v12.0.1,https://github.com/uuidjs/uuid.git - v13.0.1 None

Unreachable

CVE-2026-41988

Path to dependency file: /sample/SipInterconnect/package.json

Path to vulnerable library: /sample/SipInterconnect/node_modules/@⁠vonage/jwt/node_modules/uuid/package.json

Dependency Hierarchy:

-> opentok-2.23.2.tgz (Root Library)

   -> jwt-1.14.0.tgz

     -> ❌ uuid-13.0.0.tgz (Vulnerable Library)

Low 3.2 Not Defined 0.181% Transitive uuid-13.0.0.tgz opentok-2.23.2.tgz Transitive uuid - 11.1.1,uuid - 11.1.1,uuid - 12.0.1,uuid - 12.0.1 None

Unreachable

✔️ Remediated vulnerabilities:

Vulnerability Vulnerable Library
CVE-2026-12590 body-parser-1.20.5.tgz
CVE-2025-13465 lodash-4.17.21.tgz
CVE-2026-2950 lodash-4.17.21.tgz
CVE-2026-4800 lodash-4.17.21.tgz

Base branch total remaining vulnerabilities: 19
Base branch commit: e7db0761cc23ecb7ba50b19a8291cb1b91c9e94a


Total libraries scanned: 153

Scan token: e5a1f9153c694c348a0cf0c981346d65