Skip to content

Wiz: Upgrade multiple dependencies (resolves 34 findings) - #3

Open
wiz-inc-fc6c1ee369[bot] wants to merge 1 commit into
mainfrom
wiz-auto-remediation-fd93e80b657e759a
Open

Wiz: Upgrade multiple dependencies (resolves 34 findings)#3
wiz-inc-fc6c1ee369[bot] wants to merge 1 commit into
mainfrom
wiz-auto-remediation-fd93e80b657e759a

Conversation

@wiz-inc-fc6c1ee369

Copy link
Copy Markdown

Wiz Remediation Pull Request Banner

Wiz has created this PR to fix 34 findings detected in this project

Changes were made to the following file(s):

  • references/cicd-pipeline/package-lock.json
  • references/cicd-pipeline/package.json
  • references/data-converters-shared-flow/package-lock.json
  • references/data-converters-shared-flow/package.json
  • references/js-callout/package-lock.json
  • references/js-callout/package.json
  • references/oidc-mock/package-lock.json
  • references/oidc-mock/package.json
  • tools/apigee-openlegacy/res/proxy/package-lock.json
  • tools/apigee-openlegacy/res/proxy/package.json
  • tools/oas-apigee-mock/package-lock.json
  • tools/oas-apigee-mock/package.json

Vulnerabilities:

Component Findings Locations
braces
2.3.2 → 27.0.0-next.0
High CVE-2024-4068 /references/js-callout/package.json
debug
3.2.6 → 8.3.0
Medium CVE-2017-16137 /references/cicd-pipeline/package.json
diff
3.5.0 → 10.6.0
Low CVE-2026-24001 /references/cicd-pipeline/package.json
diff
5.0.0 → 10.6.0
Low CVE-2026-24001 /references/data-converters-shared-flow/package.json
form-data
2.3.3 → 0.16.3
Critical CVE-2025-7783 /tools/apigee-openlegacy/res/proxy/package.json
/tools/oas-apigee-mock/package.json
js-yaml
3.13.1 → 10.6.0
Medium CVE-2025-64718 /references/cicd-pipeline/package.json
js-yaml
4.1.0 → 10.6.0
Medium CVE-2025-64718 /references/data-converters-shared-flow/package.json
jszip
2.5.0 → 0.15.2
High CVE-2022-48285
Medium CVE-2021-23413
/tools/apigee-openlegacy/res/proxy/package.json
/tools/oas-apigee-mock/package.json
micromatch
3.1.10 → 27.0.0-next.0
Medium CVE-2024-4067 /references/js-callout/package.json
minimatch
3.0.4 → 10.6.0
High CVE-2022-3517
High CVE-2026-26996
High CVE-2026-27904
High CVE-2026-27903
/references/cicd-pipeline/package.json
minimatch
4.2.1 → 10.6.0
High CVE-2026-26996
High CVE-2026-27904
High CVE-2026-27903
/references/data-converters-shared-flow/package.json
nanoid
3.3.1 → 10.3.0-preminor.0
Medium CVE-2024-55565 /references/data-converters-shared-flow/package.json
qs
6.5.5 → 0.16.3
Medium CVE-2025-15284 /tools/apigee-openlegacy/res/proxy/package.json
/tools/oas-apigee-mock/package.json
request
2.88.2 → 0.16.3
Medium CVE-2023-28155 /tools/apigee-openlegacy/res/proxy/package.json
/tools/oas-apigee-mock/package.json
serialize-javascript
6.0.0 → 12.0.0-beta-10
High CVE-2026-34043
Medium CVE-2024-11831
/references/data-converters-shared-flow/package.json
tar-fs
2.1.1 → 22.13.1
High CVE-2025-59343
High CVE-2025-48387
High CVE-2024-12905
/references/oidc-mock/package.json
tmp
0.0.29 → 8.2.7
Medium CVE-2025-54798 /tools/oas-apigee-mock/package.json
tough-cookie
2.5.0 → 0.16.3
Critical CVE-2023-26136 /tools/apigee-openlegacy/res/proxy/package.json
/tools/oas-apigee-mock/package.json
ws
8.5.0 → 22.11.2
High CVE-2024-37890 /references/oidc-mock/package.json

To detect these findings earlier in the dev lifecycle, try using Wiz Code VS Code Extension.

@wiz-inc-fc6c1ee369

wiz-inc-fc6c1ee369 Bot commented May 30, 2026

Copy link
Copy Markdown
Author

Wiz Scan Summary

Scanner Findings
Vulnerability Finding Vulnerabilities 2 High 1 Medium 3 Low
Data Finding Sensitive Data -
Secret Finding Secrets -
IaC Misconfiguration IaC Misconfigurations -
SAST Finding SAST Findings -
Software Management Finding Software Management Findings -
Total 2 High 1 Medium 3 Low

View scan details in Wiz

To detect these findings earlier in the dev lifecycle, try using Wiz Code VS Code Extension.

@wiz-inc-fc6c1ee369

Copy link
Copy Markdown
Author

Wiz Scan Summary

Scanner Findings
Vulnerability Finding Vulnerabilities 2 High 1 Medium 3 Low
Data Finding Sensitive Data -
Secret Finding Secrets -
IaC Misconfiguration IaC Misconfigurations -
SAST Finding SAST Findings -
Software Management Finding Software Management Findings -
Total 2 High 1 Medium 3 Low

View scan details in Wiz

To detect these findings earlier in the dev lifecycle, try using Wiz Code VS Code Extension.

@wiz-inc-fc6c1ee369

Copy link
Copy Markdown
Author

Wiz Scan Summary

Scanner Findings
Vulnerability Finding Vulnerabilities 2 High 1 Medium 3 Low
Data Finding Sensitive Data -
Secret Finding Secrets -
IaC Misconfiguration IaC Misconfigurations -
SAST Finding SAST Findings -
Software Management Finding Software Management Findings -
Total 2 High 1 Medium 3 Low

View scan details in Wiz

To detect these findings earlier in the dev lifecycle, try using Wiz Code VS Code Extension.

"dependencies": {
"apickli": "^3.0.1",
"apigeetool": "^0.10.0",
"apigeetool": "0.16.3",

Copy link
Copy Markdown
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

High Vulnerability Finding

More Details

Vulnerabilities [tmp:0.0.27]

Name Severity Source Fixed version CVSS score CVSS exploitability score Has public exploit Has CISA KEV exploit
CVE-2025-54798 Low https://github.com/advisories/GHSA-52f5-9888-hmc6 - 5.3 3.9 true false
CVE-2026-44705 High https://github.com/advisories/GHSA-ph9p-34f9-6g65 0.2.6 7.7 - false false
"@cucumber/cucumber": "7.3.0",
"apickli": "3.0.1",
"apigeetool": "^0.10.0",
"apigeetool": "0.16.3",

Copy link
Copy Markdown
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

High Vulnerability Finding

More Details

Vulnerabilities [tmp:0.0.27]

Name Severity Source Fixed version CVSS score CVSS exploitability score Has public exploit Has CISA KEV exploit
CVE-2025-54798 Low https://github.com/advisories/GHSA-52f5-9888-hmc6 - 5.3 3.9 true false
CVE-2026-44705 High https://github.com/advisories/GHSA-ph9p-34f9-6g65 0.2.6 7.7 - false false
"@cucumber/cucumber": "7.3.0",
"apickli": "3.0.1",
"apigeetool": "^0.10.0",
"apigeetool": "0.16.3",

Copy link
Copy Markdown
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

High Vulnerability Finding

More Details

Vulnerabilities [tmp:0.0.27]

Name Severity Source Fixed version CVSS score CVSS exploitability score Has public exploit Has CISA KEV exploit
CVE-2025-54798 Low https://github.com/advisories/GHSA-52f5-9888-hmc6 - 5.3 3.9 true false
CVE-2026-44705 High https://github.com/advisories/GHSA-ph9p-34f9-6g65 0.2.6 7.7 - false false
"dependencies": {
"apickli": "^3.0.1",
"apigeetool": "^0.10.0",
"apigeetool": "0.16.3",

Copy link
Copy Markdown
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

High Vulnerability Finding

More Details

Vulnerabilities [tmp:0.0.27]

Name Severity Source Fixed version CVSS score CVSS exploitability score Has public exploit Has CISA KEV exploit
CVE-2025-54798 Low https://github.com/advisories/GHSA-52f5-9888-hmc6 - 5.3 3.9 true false
CVE-2026-44705 High https://github.com/advisories/GHSA-ph9p-34f9-6g65 0.2.6 7.7 - false false
"@cucumber/cucumber": "7.3.0",
"apickli": "3.0.1",
"apigeetool": "^0.10.0",
"apigeetool": "0.16.3",

Copy link
Copy Markdown
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

High Vulnerability Finding

More Details

Vulnerabilities [tmp:0.0.27]

Name Severity Source Fixed version CVSS score CVSS exploitability score Has public exploit Has CISA KEV exploit
CVE-2025-54798 Low https://github.com/advisories/GHSA-52f5-9888-hmc6 - 5.3 3.9 true false
CVE-2026-44705 High https://github.com/advisories/GHSA-ph9p-34f9-6g65 0.2.6 7.7 - false false
"dependencies": {
"apickli": "^3.0.1",
"apigeetool": "^0.10.0",
"apigeetool": "0.16.3",

Copy link
Copy Markdown
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

High Vulnerability Finding

More Details

Vulnerabilities [tmp:0.0.27]

Name Severity Source Fixed version CVSS score CVSS exploitability score Has public exploit Has CISA KEV exploit
CVE-2025-54798 Low https://github.com/advisories/GHSA-52f5-9888-hmc6 - 5.3 3.9 true false
CVE-2026-44705 High https://github.com/advisories/GHSA-ph9p-34f9-6g65 0.2.6 7.7 - false false
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment