Skip to content

security: bump 2 package(s) in npm#3

Open
vtiwari-story wants to merge 1 commit into
mainfrom
depagent/sec-npm-20260519-232138
Open

security: bump 2 package(s) in npm#3
vtiwari-story wants to merge 1 commit into
mainfrom
depagent/sec-npm-20260519-232138

Conversation

@vtiwari-story

Copy link
Copy Markdown

Security dependency upgrade

This PR was opened by depagent to address 2 security alert(s) in the npm ecosystem.

Each package is pinned to exactly the patched version reported by Dependabot's first_patched_version — not a range. To restore a range constraint (e.g. ^x.y.z), edit the manifest after merge.

Alerts addressed

Sev Package Vulnerable range Patched CVE GHSA EPSS KEV
high lodash >= 4.0.0, <= 4.17.23 4.18.0 CVE-2026-4800 GHSA-r5fr-rjxr-66jc 0.00 no
high lodash < 4.17.21 4.17.21 CVE-2021-23337 GHSA-35jh-r3h4-6jhm 0.03 no

Notes

  • Some changes are package overrides for transitive vulnerable deps (pnpm.overrides / overrides / resolutions). The vulnerable package isn't declared directly in the manifest — the override pins it to the patched version across the entire dependency graph for that workspace.
  • regenerated yarn.lock

Generated by depagent — storyprotocol/splits-contracts.

@vtiwari-story vtiwari-story added security Created by depagent depagent Created by depagent labels May 19, 2026
@wiz-6cbc7756d1

Copy link
Copy Markdown

Wiz Scan Summary

Scanner Findings
Vulnerability Finding Vulnerabilities 1 High 2 Medium
Data Finding Sensitive Data -
Secret Finding Secrets -
IaC Misconfiguration IaC Misconfigurations -
SAST Finding SAST Findings -
Software Management Finding Software Management Findings -
Total 1 High 2 Medium

View scan details in Wiz

To detect these findings earlier in the dev lifecycle, try using Wiz Code VS Code Extension.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

depagent Created by depagent security Created by depagent

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant