Update dependency tailwind-merge to v2.5.5 #43
Mend Bolt for GitHub / Mend Security Check
failed
Nov 24, 2024 in 54s
Security Report
2 new vulnerabilities were introduced in this branch.
❌ New vulnerabilities:
CVE | Severity | CVSS Score | Vulnerable Library | Suggested Fix | Issue |
---|---|---|---|---|---|
CVE-2024-4068Path to dependency file: /package.json Path to vulnerable library: /package.json Dependency Hierarchy: -> react-email-2.1.0.tgz (Root Library) -> chokidar-3.5.3.tgz -> ❌ braces-3.0.2.tgz (Vulnerable Library) |
High | 7.5 | braces-3.0.2.tgz | Upgrade to version: braces - 3.0.3 | #46 |
CVE-2024-4067Path to dependency file: /package.json Path to vulnerable library: /package.json Dependency Hierarchy: -> react-email-2.1.0.tgz (Root Library) -> tailwindcss-3.4.0.tgz -> ❌ micromatch-4.0.5.tgz (Vulnerable Library) |
Medium | 5.3 | micromatch-4.0.5.tgz | Upgrade to version: micromatch - 4.0.8 | #46 |
Base branch total remaining vulnerabilities: 13
Base branch commit: 0a578c23006241ccbac877d20ecb56bf1340ade9
Total libraries scanned: 694
Scan token: d3685ee1ca2a476da38f6376395a6778
Loading