Skip to content

Bump brace-expansion from 2.0.1 to 2.0.2 in /chains/evm #1025

Bump brace-expansion from 2.0.1 to 2.0.2 in /chains/evm

Bump brace-expansion from 2.0.1 to 2.0.2 in /chains/evm #1025

Triggered via pull request September 12, 2025 16:52
Status Failure
Total duration 42s
Artifacts

dependency-review-vulnerability.yml Required

on: pull_request
Vulnerabilities
37s
Vulnerabilities
Fit to window
Zoom out
Zoom in

Annotations

1 error and 10 warnings
Vulnerabilities
Dependency review detected vulnerable packages.
OpenSSF Scorecard Warning
npm/inherits has an OpenSSF Scorecard of 2.6, which is less than this repository's threshold of 3.
OpenSSF Scorecard Warning
npm/hmac-drbg has an OpenSSF Scorecard of 2.6, which is less than this repository's threshold of 3.
OpenSSF Scorecard Warning
npm/hash.js has an OpenSSF Scorecard of 1.4, which is less than this repository's threshold of 3.
OpenSSF Scorecard Warning
npm/get-func-name has an OpenSSF Scorecard of 2.9, which is less than this repository's threshold of 3.
OpenSSF Scorecard Warning
npm/fs.realpath has an OpenSSF Scorecard of 2.5, which is less than this repository's threshold of 3.
OpenSSF Scorecard Warning
npm/find-yarn-workspace-root has an OpenSSF Scorecard of 2.5, which is less than this repository's threshold of 3.
OpenSSF Scorecard Warning
npm/elliptic has an OpenSSF Scorecard of 1.4, which is less than this repository's threshold of 3.
OpenSSF Scorecard Warning
npm/cross-spawn has an OpenSSF Scorecard of 2.9, which is less than this repository's threshold of 3.
OpenSSF Scorecard Warning
npm/brorand has an OpenSSF Scorecard of 2.6, which is less than this repository's threshold of 3.
OpenSSF Scorecard Warning
npm/better-ajv-errors has an OpenSSF Scorecard of 2.7, which is less than this repository's threshold of 3.