Skip to content

chore(deps): update dependency marked to v4 - #175

Open
dev-mend-for-github-com[bot] wants to merge 1 commit into
electron-upgradefrom
whitesource-remediate/marked-4.x
Open

chore(deps): update dependency marked to v4#175
dev-mend-for-github-com[bot] wants to merge 1 commit into
electron-upgradefrom
whitesource-remediate/marked-4.x

chore(deps): update dependency marked to v4

5de5fd2
Select commit
Loading
Failed to load commit list.
Dev - Mend for GitHub.com / Mend Security Check failed Oct 28, 2025 in 6m 11s

Security Report

❗️Scan Incomplete: The scan completed with partial failure. The integration encountered issues with one or more projects in this repository, preventing their scan. The errors occurred in the following package managers: npm. Consequently, there may be gaps in the coverage of open-source dependencies used in the repository.

Scan Details Report

npm

/tmp/ws-scm/atom/spec/fixtures/packages/package-with-broken-package-json/package.json

StepLevelDescriptionDetails
Preparing the project for scan⚠WarnOne or more of the installations failedFail to run npm install:
npm error code EJSONPARSE
npm error JSON.parse Invalid package.json: JSONParseError: Unexpected token "I" (0x49), "INVALID
npm error JSON.parse " is not valid JSON while parsing 'INVALID
npm error JSON.parse '
npm error JSON.parse Failed to parse JSON data.
npm error JSON.parse Note: package.json must be actual JSON, not just JavaScript.
npm error
Resolving the project❌ErrorFailure to perform the resolution operation due to an issue parsing a fileInvalid package.json file: /tmp/ws-scm/atom/spec/fixtures/packages/package-with-broken-package-json/package.json

You have successfully remediated 21 vulnerabilities, but introduced 7 new vulnerabilities in this branch.

❌ New vulnerabilities:
VulnerabilitySeverity CVSS ScoreVulnerable LibraryDirect LibrarySuggested FixIssueReachability
CVE-952079-685214

Path to dependency file: /script/vsts/package.json

Path to vulnerable library: /script/vsts/package.json

Dependency Hierarchy:

-> rest-15.9.5.tgz (Root Library)

-> ❌ node-fetch-2.6.7.tgz (Vulnerable Library)

Critical9.8Transitive node-fetch-2.6.7.tgzrest-15.9.5.tgz#45
CVE-893166-217151

Path to dependency file: /package.json

Path to vulnerable library: /package.json,/apm/package.json,/script/package.json

Dependency Hierarchy:

-> settings-view-https://www.atom.io/api/packages/settings-view/versions/0.261.3/tarball.tgz (Root Library)

-> request-2.88.0.tgz

-> ❌ form-data-2.3.3.tgz (Vulnerable Library)

Critical9.8Transitive form-data-2.3.3.tgzsettings-view-https://www.atom.io/api/packages/settings-view/versions/0.261.3/tarball.tgz#34
CVE-893166-217151

Path to dependency file: /package.json

Path to vulnerable library: /package.json,/apm/package.json,/script/package.json

Dependency Hierarchy:

-> webdriverio-5.9.2.tgz (Root Library)

-> webdriver-5.9.1.tgz

-> request-2.87.0.tgz

-> ❌ form-data-2.3.3.tgz (Vulnerable Library)

Critical9.8Transitive form-data-2.3.3.tgzwebdriverio-5.9.2.tgz#47
CVE-893166-217151

Path to dependency file: /package.json

Path to vulnerable library: /package.json,/apm/package.json,/script/package.json

Dependency Hierarchy:

-> atom-package-manager-2.6.5.tgz (Root Library)

-> request-2.88.2.tgz

-> ❌ form-data-2.3.3.tgz (Vulnerable Library)

Critical9.8Transitive form-data-2.3.3.tgzatom-package-manager-2.6.5.tgz#3
CVE-796484-931798

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> markdown-preview-https://www.atom.io/api/packages/markdown-preview/versions/0.160.2/tarball.tgz (Root Library)

-> cheerio-1.0.0-rc.3.tgz

-> ❌ lodash-4.17.15.tgz (Vulnerable Library)

Critical9.8Transitive lodash-4.17.15.tgzmarkdown-preview-https://www.atom.io/api/packages/markdown-preview/versions/0.160.2/tarball.tgz#13
CVE-796484-931798

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> github-https://www.atom.io/api/packages/github/versions/0.34.2/tarball.tgz (Root Library)

-> babel7-transpiler-1.0.0-1.tgz

-> core-7.8.7.tgz

-> ❌ lodash-4.17.15.tgz (Vulnerable Library)

Critical9.8Transitive lodash-4.17.15.tgzgithub-https://www.atom.io/api/packages/github/versions/0.34.2/tarball.tgz#20
CVE-796484-931798

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> mocha-multi-reporters-1.1.7.tgz (Root Library)

-> ❌ lodash-4.17.15.tgz (Vulnerable Library)

Critical9.8Transitive lodash-4.17.15.tgzmocha-multi-reporters-1.1.7.tgz#21

✔️ Remediated vulnerabilities:

VulnerabilityVulnerable Library
GHSA-xf5p-87ch-gxw2marked-0.5.2.tgz
GHSA-8x6c-cv3v-vp6gcacheable-request-6.1.0.tgz
GHSA-2pr6-76vf-7546js-yaml-3.6.1.tgz
GHSA-6chw-6frg-f759acorn-5.7.3.tgz
GHSA-7fhm-mqm4-2wp7minimist-1.1.3.tgz
GHSA-7fhm-mqm4-2wp7minimist-0.0.8.tgz
GHSA-f7xj-rg7h-mc87stylelint-9.3.0.tgz
GHSA-35jh-r3h4-6jhmlodash-4.17.11.tgz
GHSA-8x6c-cv3v-vp6gcacheable-request-2.1.4.tgz
GHSA-ch52-vgq2-943fmarked-0.5.2.tgz
GHSA-7m7q-q53v-j47vmarked-0.5.2.tgz
GHSA-8x6c-cv3v-vp6gcacheable-request-7.0.2.tgz
GHSA-8j8c-7jfh-h6hxjs-yaml-3.6.1.tgz
GHSA-mjjq-c88q-qhr6dompurify-1.0.11.tgz
GHSA-7fhm-mqm4-2wp7acorn-5.7.3.tgz
GHSA-7fhm-mqm4-2wp7minimist-1.2.0.tgz
GHSA-g95f-p29q-9xw4braces-1.8.5.tgz
GHSA-7fhm-mqm4-2wp7minimist-0.0.10.tgz
GHSA-7wwv-vh3v-89cqhighlight.js-9.16.2.tgz
GHSA-xf5p-87ch-gxw2marked-0.3.19.tgz
GHSA-ch52-vgq2-943fmarked-0.6.3.tgz

Base branch total remaining vulnerabilities: 199
Base branch commit: 516d2ba6154c1452a1ee42314809c66edc833096


Total libraries scanned: 2251

Scan token: e95abeb351ca4598a86064ab814acad1