Skip to content

Wiz: Upgrade multiple dependencies (resolves 23 findings)#47

Open
wiz-code-21c5ec5a85[bot] wants to merge 1 commit intomainfrom
wiz-auto-remediation-49b79f33dfa851d7
Open

Wiz: Upgrade multiple dependencies (resolves 23 findings)#47
wiz-code-21c5ec5a85[bot] wants to merge 1 commit intomainfrom
wiz-auto-remediation-49b79f33dfa851d7

Conversation

@wiz-code-21c5ec5a85
Copy link
Copy Markdown

Wiz Remediation Pull Request Banner

Wiz has created this PR to fix 23 findings detected in this project

Changes were made to the following file(s):

  • packages/nextjs/package.json

Vulnerabilities:

Component Findings Locations
@coinbase/wallet-sdk
4.2.3 → 2.14.11
High GHSA-8rgj-285w-qcq4 /packages/nextjs/package.json
@metamask/sdk
0.31.1 → 2.17.1
Medium GHSA-qj3p-xc97-xw74 /packages/nextjs/package.json
@metamask/sdk-communication-layer
0.31.0 → 2.17.1
Medium GHSA-qj3p-xc97-xw74 /packages/nextjs/package.json
@stablelib/ed25519
1.0.3 → 2.14.13
Medium GHSA-x3ff-w252-2g7j /packages/nextjs/package.json
bn.js
4.12.2 → 3.0.0
Medium CVE-2026-2739 /packages/nextjs/package.json
bn.js
5.2.2 → 3.0.0
Medium CVE-2026-2739 /packages/nextjs/package.json
defu
6.1.4 → 3.0.0
High CVE-2026-35209 /packages/nextjs/package.json
elliptic
6.6.1 → 2.14.16
Medium CVE-2025-14505 /packages/nextjs/package.json
h3
1.15.4 → 3.0.0
Critical CVE-2026-33128
Critical CVE-2026-23527
Medium GHSA-72gr-qfp7-vwhw
Medium GHSA-4hxc-9384-m385
Medium GHSA-wr4h-v87w-p3r7
/packages/nextjs/package.json
next
14.2.35 → 15.5.15
High CVE-2026-23869
High CVE-2025-59471
High CVE-2026-23864
Medium CVE-2026-29057
Medium CVE-2026-27980
/packages/nextjs/package.json
picomatch
2.3.1 → 3.0.0
High CVE-2026-33671
Medium CVE-2026-33672
/packages/nextjs/package.json
preact
10.27.2 → 2.15.7
High CVE-2026-22028 /packages/nextjs/package.json
socket.io-parser
4.2.4 → 3.0.0
High CVE-2026-33151 /packages/nextjs/package.json
ws
8.13.0 → 0.0.12
High CVE-2024-37890 /packages/nextjs/package.json

To detect these findings earlier in the dev lifecycle, try using Wiz Code VS Code Extension.

@wiz-code-21c5ec5a85
Copy link
Copy Markdown
Author

wiz-code-21c5ec5a85 Bot commented May 1, 2026

Wiz Scan Summary

Scanner Findings
Vulnerability Finding Vulnerabilities 1 High 3 Medium 1 Low
Data Finding Sensitive Data -
Secret Finding Secrets -
IaC Misconfiguration IaC Misconfigurations -
SAST Finding SAST Findings -
Software Management Finding Software Management Findings -
Total 1 High 3 Medium 1 Low

View scan details in Wiz

To detect these findings earlier in the dev lifecycle, try using Wiz Code VS Code Extension.

@wiz-code-21c5ec5a85
Copy link
Copy Markdown
Author

Wiz Scan Summary

Scanner Findings
Vulnerability Finding Vulnerabilities 1 High 3 Medium 1 Low
Data Finding Sensitive Data -
Secret Finding Secrets -
IaC Misconfiguration IaC Misconfigurations -
SAST Finding SAST Findings -
Software Management Finding Software Management Findings -
Total 1 High 3 Medium 1 Low

View scan details in Wiz

To detect these findings earlier in the dev lifecycle, try using Wiz Code VS Code Extension.

@wiz-code-21c5ec5a85
Copy link
Copy Markdown
Author

Wiz Scan Summary

Scanner Findings
Vulnerability Finding Vulnerabilities 1 High 3 Medium 1 Low
Data Finding Sensitive Data -
Secret Finding Secrets -
IaC Misconfiguration IaC Misconfigurations -
SAST Finding SAST Findings -
Software Management Finding Software Management Findings -
Total 1 High 3 Medium 1 Low

View scan details in Wiz

To detect these findings earlier in the dev lifecycle, try using Wiz Code VS Code Extension.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants