Skip to content

Wiz: Upgrade multiple dependencies (resolves 9 findings)#8

Open
wiz-betterup[bot] wants to merge 3 commits intomainfrom
wiz-remediation-2025-12-07-def1d3fc2ca9
Open

Wiz: Upgrade multiple dependencies (resolves 9 findings)#8
wiz-betterup[bot] wants to merge 3 commits intomainfrom
wiz-remediation-2025-12-07-def1d3fc2ca9

Conversation

@wiz-betterup
Copy link
Copy Markdown

@wiz-betterup wiz-betterup Bot commented Dec 7, 2025

Wiz Remediation Pull Request Banner

Wiz has created this PR to fix 9 findings detected in this project

Changes were made to the following file(s):

  • /api/package.json
  • /packages/data-provider/package.json
  • /packages/data-provider/react-query/package.json

Vulnerabilities:

Component Findings Locations
@node-saml/passport-saml
5.0.1 → 5.1.0
Critical CVE-2025-54419 /api/package.json
axios
1.9.0 → 1.12.0
High CVE-2025-58754 /packages/data-provider/react-query/package.json
js-yaml
4.1.0 → 4.1.1
Medium CVE-2025-64718 /api/package.json
/packages/data-provider/package.json
multer
2.0.1 → 2.0.2
High CVE-2025-7338 /api/package.json
nodemailer
6.10.1 → 7.0.11
High CVE-2025-13033
Low GHSA-rcmh-qjqh-p98v
/api/package.json
on-headers
1.0.2 → 1.18.2
Low CVE-2025-7339 /api/package.json

To detect these findings earlier in the dev lifecycle, try using Wiz Code VS Code Extension.

@github-actions
Copy link
Copy Markdown

github-actions Bot commented Dec 7, 2025

🚨 Unused i18next Keys Detected

The following translation keys are defined in translation.json but are not used in the codebase:

  • com_nav_commands
  • com_nav_help_faq
  • com_nav_setting_balance
  • com_nav_setting_beta
  • com_nav_setting_data
  • com_nav_setting_personalization

⚠️ Please remove these unused keys to keep the translation files clean.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants