Update dependency @astrojs/starlight to ^0.32.0 - #3
Update dependency @astrojs/starlight to ^0.32.0#3dev-mend-for-github-com[bot] wants to merge 1 commit into
Security Report
You have successfully remediated 2 vulnerabilities, but introduced 15 new vulnerabilities in this branch.
❌ New vulnerabilities:
| Vulnerability | Severity | Vulnerable Library | Direct Library | Suggested Fix | Issue | |
|---|---|---|---|---|---|---|
CVE-2025-57820Path to dependency file: /docs/package.json Path to vulnerable library: /docs/package.json Dependency Hierarchy: -> starlight-0.32.6.tgz (Root Library) -> astro-5.3.0.tgz -> ❌ devalue-5.1.1.tgz (Vulnerable Library) | 10.0 | Transitive devalue-5.1.1.tgz | starlight-0.32.6.tgz | Transitive 5.3.2 | None | |
CVE-2025-64764Path to dependency file: /docs/package.json Path to vulnerable library: /docs/package.json Dependency Hierarchy: -> starlight-0.32.6.tgz (Root Library) -> ❌ astro-5.3.0.tgz (Vulnerable Library) | 7.1 | Transitive astro-5.3.0.tgz | starlight-0.32.6.tgz | Transitive astro - 5.15.8 | None | |
CVE-2025-64525Path to dependency file: /docs/package.json Path to vulnerable library: /docs/package.json Dependency Hierarchy: -> starlight-0.32.6.tgz (Root Library) -> ❌ astro-5.3.0.tgz (Vulnerable Library) | 6.5 | Transitive astro-5.3.0.tgz | starlight-0.32.6.tgz | Transitive astro - 5.15.5 | None | |
CVE-2025-62522Path to dependency file: /docs/package.json Path to vulnerable library: /docs/package.json Dependency Hierarchy: -> starlight-0.32.6.tgz (Root Library) -> astro-5.3.0.tgz -> ❌ vite-6.1.0.tgz (Vulnerable Library) | 6.5 | Transitive vite-6.1.0.tgz | starlight-0.32.6.tgz | Transitivehttps://gitlab.com/remram44/taguette.git - v1.5.0 | None | |
CVE-2025-61925Path to dependency file: /docs/package.json Path to vulnerable library: /docs/package.json Dependency Hierarchy: -> starlight-0.32.6.tgz (Root Library) -> ❌ astro-5.3.0.tgz (Vulnerable Library) | 6.5 | Transitive astro-5.3.0.tgz | starlight-0.32.6.tgz | Transitive astro - 5.14.3 | None | |
CVE-2025-32395Path to dependency file: /docs/package.json Path to vulnerable library: /docs/package.json Dependency Hierarchy: -> starlight-0.32.6.tgz (Root Library) -> astro-5.3.0.tgz -> ❌ vite-6.1.0.tgz (Vulnerable Library) | 6.5 | Transitive vite-6.1.0.tgz | starlight-0.32.6.tgz | Transitive 6.1.5 | None | |
CVE-2025-54793Path to dependency file: /docs/package.json Path to vulnerable library: /docs/package.json Dependency Hierarchy: -> starlight-0.32.6.tgz (Root Library) -> ❌ astro-5.3.0.tgz (Vulnerable Library) | 6.1 | Transitive astro-5.3.0.tgz | starlight-0.32.6.tgz | Transitive 5.12.8 | None | |
CVE-2025-65019Path to dependency file: /docs/package.json Path to vulnerable library: /docs/package.json Dependency Hierarchy: -> starlight-0.32.6.tgz (Root Library) -> ❌ astro-5.3.0.tgz (Vulnerable Library) | 5.4 | Transitive astro-5.3.0.tgz | starlight-0.32.6.tgz | Transitive astro - 5.15.9 | None | |
CVE-2026-24001Path to dependency file: /docs/package.json Path to vulnerable library: /docs/package.json Dependency Hierarchy: -> starlight-0.32.6.tgz (Root Library) -> astro-5.3.0.tgz -> ❌ diff-5.2.0.tgz (Vulnerable Library) | 5.3 | Transitive diff-5.2.0.tgz | starlight-0.32.6.tgz | Transitivehttps://github.com/kpdecker/jsdiff.git - v4.0.4,https://github.com/kpdecker/jsdiff.git - v5.2.2,https://github.com/kpdecker/jsdiff.git - v8.0.3 | None | |
CVE-2025-64765Path to dependency file: /docs/package.json Path to vulnerable library: /docs/package.json Dependency Hierarchy: -> starlight-0.32.6.tgz (Root Library) -> ❌ astro-5.3.0.tgz (Vulnerable Library) | 5.3 | Transitive astro-5.3.0.tgz | starlight-0.32.6.tgz | Transitive astro - 5.15.8 | None | |
CVE-2025-58752Path to dependency file: /docs/package.json Path to vulnerable library: /docs/package.json Dependency Hierarchy: -> starlight-0.32.6.tgz (Root Library) -> astro-5.3.0.tgz -> ❌ vite-6.1.0.tgz (Vulnerable Library) | 5.3 | Transitive vite-6.1.0.tgz | starlight-0.32.6.tgz | Transitive vite - 6.3.6,vite - 7.1.5,vite - 7.0.7,vite - 5.4.20 | None | |
CVE-2025-30208Path to dependency file: /docs/package.json Path to vulnerable library: /docs/package.json Dependency Hierarchy: -> starlight-0.32.6.tgz (Root Library) -> astro-5.3.0.tgz -> ❌ vite-6.1.0.tgz (Vulnerable Library) | 5.3 | Transitive vite-6.1.0.tgz | starlight-0.32.6.tgz | Transitive 6.1.2 | None | |
CVE-2025-58751Path to dependency file: /docs/package.json Path to vulnerable library: /docs/package.json Dependency Hierarchy: -> starlight-0.32.6.tgz (Root Library) -> astro-5.3.0.tgz -> ❌ vite-6.1.0.tgz (Vulnerable Library) | 4.3 | Transitive vite-6.1.0.tgz | starlight-0.32.6.tgz | Transitive 6.3.6 | None | |
CVE-2025-64757Path to dependency file: /docs/package.json Path to vulnerable library: /docs/package.json Dependency Hierarchy: -> starlight-0.32.6.tgz (Root Library) -> ❌ astro-5.3.0.tgz (Vulnerable Library) | 3.5 | Transitive astro-5.3.0.tgz | starlight-0.32.6.tgz | Transitive astro - 5.14.3 | None | |
CVE-2025-64745Path to dependency file: /docs/package.json Path to vulnerable library: /docs/package.json Dependency Hierarchy: -> starlight-0.32.6.tgz (Root Library) -> ❌ astro-5.3.0.tgz (Vulnerable Library) | 2.7 | Transitive astro-5.3.0.tgz | starlight-0.32.6.tgz | Transitive astro - 5.15.6 | None |
✔️ Remediated vulnerabilities:
| Vulnerability | Vulnerable Library |
|---|---|
| CVE-2025-4565 | protobuf-4.25.6-cp37-abi3-manylinux2014_x86_64.whl |
| CVE-2026-0994 | protobuf-4.25.6-cp37-abi3-manylinux2014_x86_64.whl |
Base branch total remaining vulnerabilities: 15
Base branch commit: 6703a1908524f677bf251e7e88d0cbd33021958a
Total libraries scanned: 653
Scan token: ab358a2092e44a34abbaaa01345dc89f