Skip to content

Wiz: Upgrade multiple dependencies (resolves 9 findings)#9

Open
wiz-betterup[bot] wants to merge 3 commits intomainfrom
wiz-remediation-2025-12-13-452a8912694a
Open

Wiz: Upgrade multiple dependencies (resolves 9 findings)#9
wiz-betterup[bot] wants to merge 3 commits intomainfrom
wiz-remediation-2025-12-13-452a8912694a

Conversation

@wiz-betterup
Copy link
Copy Markdown

@wiz-betterup wiz-betterup Bot commented Dec 13, 2025

Wiz Remediation Pull Request Banner

Wiz has created this PR to fix 9 findings detected in this project

Changes were made to the following file(s):

  • /api/package.json
  • /packages/data-provider/package.json
  • /packages/data-provider/react-query/package.json

Vulnerabilities:

Component Findings Locations
@node-saml/passport-saml
5.0.1 → 5.1.0
Critical CVE-2025-54419 /api/package.json
axios
1.9.0 → 1.12.0
High CVE-2025-58754 /packages/data-provider/react-query/package.json
js-yaml
4.1.0 → 4.1.1
Medium CVE-2025-64718 /api/package.json
/packages/data-provider/package.json
multer
2.0.1 → 2.0.2
High CVE-2025-7338 /api/package.json
nodemailer
6.10.1 → 7.0.11
High CVE-2025-13033
Low GHSA-rcmh-qjqh-p98v
/api/package.json
on-headers
1.0.2 → 1.18.2
Low CVE-2025-7339 /api/package.json

To detect these findings earlier in the dev lifecycle, try using Wiz Code VS Code Extension.

@github-actions
Copy link
Copy Markdown

🚨 Unused i18next Keys Detected

The following translation keys are defined in translation.json but are not used in the codebase:

  • com_nav_commands
  • com_nav_help_faq
  • com_nav_setting_balance
  • com_nav_setting_beta
  • com_nav_setting_data
  • com_nav_setting_personalization

⚠️ Please remove these unused keys to keep the translation files clean.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants