### Target `bun.lock` #### ⚠️ Vulnerabilities (9) | Package | ID | Severity | Installed Version | Fixed Version | Links | |---------|----|---------:|------------------:|--------------|-------| | `astro` | CVE-2026-59729 | **MEDIUM** | 7.0.4 | 7.0.6 |[🔗](https://github.com/withastro/astro) [🔗](https://github.com/withastro/astro/commit/5240e26c9dd91f9bc7140dcfacdb48d5a132830d) [🔗](https://github.com/withastro/astro/pull/17251) [🔗](https://github.com/withastro/astro/releases/tag/astro@7.0.6) [🔗](https://github.com/withastro/astro/security/advisories/GHSA-f48w-9m4c-m7f5) | | `astro` | GHSA-4g3v-8h47-v7g6 | **MEDIUM** | 7.0.4 | 7.1.0 |[🔗](https://github.com/withastro/astro) [🔗](https://github.com/withastro/astro/commit/092da560eea77ee63a3e2c583c80d8238544e42b) [🔗](https://github.com/withastro/astro/pull/17393) [🔗](https://github.com/withastro/astro/releases/tag/astro@7.1.0) [🔗](https://github.com/withastro/astro/security/advisories/GHSA-4g3v-8h47-v7g6) | | `astro` | GHSA-8mv7-9c27-98vc | **MEDIUM** | 7.0.4 | 7.0.6 |[🔗](https://github.com/withastro/astro) [🔗](https://github.com/withastro/astro/commit/0b30b35f864310bee8485c952d1877e82e2b9b1a) [🔗](https://github.com/withastro/astro/pull/17250) [🔗](https://github.com/withastro/astro/releases/tag/astro@7.0.6) [🔗](https://github.com/withastro/astro/security/advisories/GHSA-8mv7-9c27-98vc) | | `dompurify` | CVE-2026-65898 | **MEDIUM** | 3.4.10 | 3.4.11 |[🔗](https://github.com/cure53/DOMPurify) [🔗](https://github.com/cure53/DOMPurify/commit/011bc3b2fcc4be17aa76f9030e8668207717acb9) [🔗](https://github.com/cure53/DOMPurify/pull/1482) [🔗](https://github.com/cure53/DOMPurify/releases/tag/3.4.11) [🔗](https://github.com/cure53/DOMPurify/security/advisories/GHSA-cmwh-pvxp-8882) [🔗](https://www.vulncheck.com/advisories/dompurify-before-permanent-attribute-allowlist-pollution-via-setconfig) | | `dompurify` | GHSA-c2j3-45gr-mqc4 | **LOW** | 3.4.10 | 3.4.12 |[🔗](https://github.com/cure53/DOMPurify) [🔗](https://github.com/cure53/DOMPurify/commit/a9ca1e537422319a557a9a2aa61f003b23b4a197) [🔗](https://github.com/cure53/DOMPurify/pull/1537) [🔗](https://github.com/cure53/DOMPurify/releases/tag/3.4.12) [🔗](https://github.com/cure53/DOMPurify/security/advisories/GHSA-c2j3-45gr-mqc4) | | `js-yaml` | CVE-2026-59869 | **HIGH** | 4.2.0 | 3.15.0, 4.3.0 |[🔗](https://access.redhat.com/security/cve/CVE-2026-59869) [🔗](https://github.com/nodeca/js-yaml) [🔗](https://github.com/nodeca/js-yaml/commit/24f13e79ee1343a7e30bd6f6c9d9cdbf0ac9b2b7) [🔗](https://github.com/nodeca/js-yaml/commit/59423c6f8cdc78742ac00e25a4dd39ef16b702e4) [🔗](https://github.com/nodeca/js-yaml/releases/tag/3.15.0) [🔗](https://github.com/nodeca/js-yaml/releases/tag/4.3.0) [🔗](https://github.com/nodeca/js-yaml/security/advisories/GHSA-52cp-r559-cp3m) [🔗](https://nvd.nist.gov/vuln/detail/CVE-2026-59869) [🔗](https://www.cve.org/CVERecord?id=CVE-2026-59869) | | `postcss` | GHSA-r28c-9q8g-f849 | **HIGH** | 8.5.15 | 8.5.18 |[🔗](https://github.com/postcss/postcss) [🔗](https://github.com/postcss/postcss/commit/95663d3eb7ba26f4854dd19d3b4f4425760cf56c) [🔗](https://github.com/postcss/postcss/releases/tag/8.5.18) [🔗](https://github.com/postcss/postcss/security/advisories/GHSA-r28c-9q8g-f849) | | `postcss` | CVE-2026-69153 | **MEDIUM** | 8.5.15 | 8.5.23 |[🔗](https://access.redhat.com/security/cve/CVE-2026-69153) [🔗](https://github.com/postcss/postcss) [🔗](https://github.com/postcss/postcss/commit/7beca139e70f9075c6b19700fcb00dd8033e5da8) [🔗](https://github.com/postcss/postcss/releases/tag/8.5.19) [🔗](https://github.com/postcss/postcss/security/advisories/GHSA-fxqj-rqcc-2cmp) [🔗](https://nvd.nist.gov/vuln/detail/CVE-2026-69153) [🔗](https://www.cve.org/CVERecord?id=CVE-2026-69153) | | `svgo` | GHSA-2p49-hgcm-8545 | **HIGH** | 4.0.1 | 2.8.3, 3.3.4, 4.0.2 |[🔗](https://github.com/svg/svgo) [🔗](https://github.com/svg/svgo/commit/628e3bc7336625a30365d0a9b60185307d852466) [🔗](https://github.com/svg/svgo/commit/72a23886b4698b27624b936f3a15a80afd36d75f) [🔗](https://github.com/svg/svgo/commit/f529cfccc6c154d6f6eabe276ec637a8c5db6763) [🔗](https://github.com/svg/svgo/releases/tag/v2.8.3) [🔗](https://github.com/svg/svgo/releases/tag/v3.3.4) [🔗](https://github.com/svg/svgo/releases/tag/v4.0.2) [🔗](https://github.com/svg/svgo/security/advisories/GHSA-2p49-hgcm-8545) | #### ✅ No Misconfigurations found ### Target `pnpm-lock.yaml` #### ✅ No Vulnerabilities found #### ✅ No Misconfigurations found
Target
bun.lockastroastroastrodompurifydompurifyjs-yamlpostcsspostcsssvgo✅ No Misconfigurations found
Target
pnpm-lock.yaml✅ No Vulnerabilities found
✅ No Misconfigurations found