Bump brace-expansion from 2.0.1 to 2.0.2 in /chains/evm #1025
dependency-review-vulnerability.yml Required
on: pull_request
Vulnerabilities
37s
Annotations
1 error and 10 warnings
Vulnerabilities
Dependency review detected vulnerable packages.
|
OpenSSF Scorecard Warning
npm/inherits has an OpenSSF Scorecard of 2.6, which is less than this repository's threshold of 3.
|
OpenSSF Scorecard Warning
npm/hmac-drbg has an OpenSSF Scorecard of 2.6, which is less than this repository's threshold of 3.
|
OpenSSF Scorecard Warning
npm/hash.js has an OpenSSF Scorecard of 1.4, which is less than this repository's threshold of 3.
|
OpenSSF Scorecard Warning
npm/get-func-name has an OpenSSF Scorecard of 2.9, which is less than this repository's threshold of 3.
|
OpenSSF Scorecard Warning
npm/fs.realpath has an OpenSSF Scorecard of 2.5, which is less than this repository's threshold of 3.
|
OpenSSF Scorecard Warning
npm/find-yarn-workspace-root has an OpenSSF Scorecard of 2.5, which is less than this repository's threshold of 3.
|
OpenSSF Scorecard Warning
npm/elliptic has an OpenSSF Scorecard of 1.4, which is less than this repository's threshold of 3.
|
OpenSSF Scorecard Warning
npm/cross-spawn has an OpenSSF Scorecard of 2.9, which is less than this repository's threshold of 3.
|
OpenSSF Scorecard Warning
npm/brorand has an OpenSSF Scorecard of 2.6, which is less than this repository's threshold of 3.
|
OpenSSF Scorecard Warning
npm/better-ajv-errors has an OpenSSF Scorecard of 2.7, which is less than this repository's threshold of 3.
|