Skip to content

Wiz: Upgrade multiple dependencies (resolves 30 findings)#50

Open
wiz-code-21c5ec5a85[bot] wants to merge 1 commit intomainfrom
wiz-auto-remediation-9661bd8c0ad4335c
Open

Wiz: Upgrade multiple dependencies (resolves 30 findings)#50
wiz-code-21c5ec5a85[bot] wants to merge 1 commit intomainfrom
wiz-auto-remediation-9661bd8c0ad4335c

Conversation

@wiz-code-21c5ec5a85
Copy link
Copy Markdown

Wiz Remediation Pull Request Banner

Wiz has created this PR to fix 30 findings detected in this project

Changes were made to the following file(s):

  • package.json

Vulnerabilities:

Component Findings Locations
@metamask/sdk
0.32.0 → 2.17.1
Medium GHSA-qj3p-xc97-xw74 /package.json
@metamask/sdk-communication-layer
0.32.0 → 2.17.1
Medium GHSA-qj3p-xc97-xw74 /package.json
bn.js
5.2.2 → 3.0.0
Medium CVE-2026-2739 /package.json
defu
6.1.4 → 3.0.0
High CVE-2026-35209 /package.json
h3
1.15.4 → 3.0.0
Critical CVE-2026-33128
Critical CVE-2026-23527
Medium GHSA-4hxc-9384-m385
Medium GHSA-72gr-qfp7-vwhw
Medium GHSA-wr4h-v87w-p3r7
/package.json
next
14.2.4 → 15.5.15
Critical CVE-2025-29927
High CVE-2024-46982
High CVE-2025-59471
High CVE-2025-57822
High CVE-2026-23864
High CVE-2024-51479
High CVE-2025-55184
High CVE-2025-67779
High CVE-2024-47831
High CVE-2026-23869
Medium CVE-2024-56332
Medium CVE-2025-57752
Medium CVE-2025-55173
Medium CVE-2026-29057
Medium CVE-2026-27980
Low CVE-2025-48068
Low CVE-2025-32421
/package.json
picomatch
2.3.1 → 3.0.0
High CVE-2026-33671
Medium CVE-2026-33672
/package.json
preact
10.27.2 → 2.15.7
High CVE-2026-22028 /package.json
socket.io-parser
4.2.4 → 3.0.0
High CVE-2026-33151 /package.json

To detect these findings earlier in the dev lifecycle, try using Wiz Code VS Code Extension.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants