{"version": "2.1.0", "$schema": "https://json.schemastore.org/sarif-2.1.0.json", "runs": [{"tool": {"driver": {"name": "Repobility", "informationUri": "https://repobility.com", "rules": [{"id": "scanner-401215081ff3098f", "name": "Debug `console.log` remains in browser-facing code \u2014 artifacts/pregasquad-manager/src/main.tsx:20", "shortDescription": {"text": "Debug `console.log` remains in browser-facing code \u2014 artifacts/pregasquad-manager/src/main.tsx:20"}, "fullDescription": {"text": "Remove debug output or route intentional diagnostics through the project's structured logger. Browser console output can expose state and create noise; server and CLI output are outside this rule's scope.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 0.85}}, {"id": "scanner-8a918d1607d8ed0f", "name": "Truncated text has no discoverable full-value affordance \u2014 artifacts/pregasquad-manager/src/components/GlobalSearch.tsx:", "shortDescription": {"text": "Truncated text has no discoverable full-value affordance \u2014 artifacts/pregasquad-manager/src/components/GlobalSearch.tsx:127"}, "fullDescription": {"text": "A visibly truncated value should expose its full text through an accessible tooltip, description, or equivalent interaction. Native `title=` is one option, but it is not the only valid implementation.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.65}}, {"id": "scanner-44c3fe3ca2def34c", "name": "Truncated text has no discoverable full-value affordance \u2014 artifacts/pregasquad-manager/src/components/ServiceRecommenda", "shortDescription": {"text": "Truncated text has no discoverable full-value affordance \u2014 artifacts/pregasquad-manager/src/components/ServiceRecommendations.tsx:112"}, "fullDescription": {"text": "A visibly truncated value should expose its full text through an accessible tooltip, description, or equivalent interaction. Native `title=` is one option, but it is not the only valid implementation.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.65}}, {"id": "scanner-83496ea7438f8772", "name": "Debug `console.log` remains in browser-facing code \u2014 artifacts/pregasquad-manager/src/components/PushNotifications.tsx:4", "shortDescription": {"text": "Debug `console.log` remains in browser-facing code \u2014 artifacts/pregasquad-manager/src/components/PushNotifications.tsx:48"}, "fullDescription": {"text": "Remove debug output or route intentional diagnostics through the project's structured logger. Browser console output can expose state and create noise; server and CLI output are outside this rule's scope.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 0.85}}, {"id": "scanner-854eec80b29c2779", "name": "Truncated text has no discoverable full-value affordance \u2014 artifacts/pregasquad-manager/src/components/layout/BottomNav.", "shortDescription": {"text": "Truncated text has no discoverable full-value affordance \u2014 artifacts/pregasquad-manager/src/components/layout/BottomNav.tsx:331"}, "fullDescription": {"text": "A visibly truncated value should expose its full text through an accessible tooltip, description, or equivalent interaction. Native `title=` is one option, but it is not the only valid implementation.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.65}}, {"id": "scanner-452f1d42c3a0c04c", "name": "Truncated text has no discoverable full-value affordance \u2014 artifacts/pregasquad-manager/src/components/layout/Sidebar.ts", "shortDescription": {"text": "Truncated text has no discoverable full-value affordance \u2014 artifacts/pregasquad-manager/src/components/layout/Sidebar.tsx:413"}, "fullDescription": {"text": "A visibly truncated value should expose its full text through an accessible tooltip, description, or equivalent interaction. Native `title=` is one option, but it is not the only valid implementation.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.65}}, {"id": "scanner-9b50c99d3d6a0d9e", "name": "Debug `console.log` remains in browser-facing code \u2014 artifacts/pregasquad-manager/src/components/layout/Sidebar.tsx:185", "shortDescription": {"text": "Debug `console.log` remains in browser-facing code \u2014 artifacts/pregasquad-manager/src/components/layout/Sidebar.tsx:185"}, "fullDescription": {"text": "Remove debug output or route intentional diagnostics through the project's structured logger. Browser console output can expose state and create noise; server and CLI output are outside this rule's scope.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 0.85}}, {"id": "scanner-7a4b9fa3039828b6", "name": "`dangerouslySetInnerHTML` used in a React component \u2014 artifacts/pregasquad-manager/src/components/ui/chart.tsx:81", "shortDescription": {"text": "`dangerouslySetInnerHTML` used in a React component \u2014 artifacts/pregasquad-manager/src/components/ui/chart.tsx:81"}, "fullDescription": {"text": "Open XSS surface unless the input is provably trusted. Replace with explicit JSX or sanitize via a vetted library.\n\nWhy: OWASP basics. Already partially flagged by the security analyzer.\nRule id: fq.dangerous-html"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "medium", "confidence": 0.8}}, {"id": "scanner-1c22a9c89fb05def", "name": "Debug `console.log` remains in browser-facing code \u2014 artifacts/pregasquad-manager/src/lib/qzPrint.ts:13", "shortDescription": {"text": "Debug `console.log` remains in browser-facing code \u2014 artifacts/pregasquad-manager/src/lib/qzPrint.ts:13"}, "fullDescription": {"text": "Remove debug output or route intentional diagnostics through the project's structured logger. Browser console output can expose state and create noise; server and CLI output are outside this rule's scope.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 0.85}}, {"id": "scanner-a66df0e2bf117c3b", "name": "Debug `console.log` remains in browser-facing code \u2014 artifacts/pregasquad-manager/src/lib/queryClient.ts:144", "shortDescription": {"text": "Debug `console.log` remains in browser-facing code \u2014 artifacts/pregasquad-manager/src/lib/queryClient.ts:144"}, "fullDescription": {"text": "Remove debug output or route intentional diagnostics through the project's structured logger. Browser console output can expose state and create noise; server and CLI output are outside this rule's scope.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 0.85}}, {"id": "scanner-5552cefcf8a546c7", "name": "Debug `console.log` remains in browser-facing code \u2014 artifacts/pregasquad-manager/src/lib/syncService.ts:149", "shortDescription": {"text": "Debug `console.log` remains in browser-facing code \u2014 artifacts/pregasquad-manager/src/lib/syncService.ts:149"}, "fullDescription": {"text": "Remove debug output or route intentional diagnostics through the project's structured logger. Browser console output can expose state and create noise; server and CLI output are outside this rule's scope.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 0.85}}, {"id": "scanner-b16f35fd04438a69", "name": "Truncated text has no discoverable full-value affordance \u2014 artifacts/pregasquad-manager/src/pages/Services.tsx:324", "shortDescription": {"text": "Truncated text has no discoverable full-value affordance \u2014 artifacts/pregasquad-manager/src/pages/Services.tsx:324"}, "fullDescription": {"text": "A visibly truncated value should expose its full text through an accessible tooltip, description, or equivalent interaction. Native `title=` is one option, but it is not the only valid implementation.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.65}}, {"id": "scanner-790fc5d52de89fcb", "name": "Truncated text has no discoverable full-value affordance \u2014 artifacts/pregasquad-manager/src/pages/StaffPerformance.tsx:4", "shortDescription": {"text": "Truncated text has no discoverable full-value affordance \u2014 artifacts/pregasquad-manager/src/pages/StaffPerformance.tsx:490"}, "fullDescription": {"text": "A visibly truncated value should expose its full text through an accessible tooltip, description, or equivalent interaction. Native `title=` is one option, but it is not the only valid implementation.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.65}}, {"id": "scanner-bf827ac710a93a28", "name": "Truncated text has no discoverable full-value affordance \u2014 artifacts/pregasquad-manager/src/pages/AdminSettings.tsx:150", "shortDescription": {"text": "Truncated text has no discoverable full-value affordance \u2014 artifacts/pregasquad-manager/src/pages/AdminSettings.tsx:150"}, "fullDescription": {"text": "A visibly truncated value should expose its full text through an accessible tooltip, description, or equivalent interaction. Native `title=` is one option, but it is not the only valid implementation.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.65}}, {"id": "scanner-85a978b358941902", "name": "Truncated text has no discoverable full-value affordance \u2014 artifacts/pregasquad-manager/src/pages/Salaries.tsx:1059", "shortDescription": {"text": "Truncated text has no discoverable full-value affordance \u2014 artifacts/pregasquad-manager/src/pages/Salaries.tsx:1059"}, "fullDescription": {"text": "A visibly truncated value should expose its full text through an accessible tooltip, description, or equivalent interaction. Native `title=` is one option, but it is not the only valid implementation.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.65}}, {"id": "scanner-862031268a039f5c", "name": "Truncated text has no discoverable full-value affordance \u2014 artifacts/pregasquad-manager/src/pages/WhatsApp.tsx:1144", "shortDescription": {"text": "Truncated text has no discoverable full-value affordance \u2014 artifacts/pregasquad-manager/src/pages/WhatsApp.tsx:1144"}, "fullDescription": {"text": "A visibly truncated value should expose its full text through an accessible tooltip, description, or equivalent interaction. Native `title=` is one option, but it is not the only valid implementation.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.65}}, {"id": "scanner-941a30c5b41d1dc8", "name": "Truncated text has no discoverable full-value affordance \u2014 artifacts/pregasquad-manager/src/pages/BookingHistory.tsx:497", "shortDescription": {"text": "Truncated text has no discoverable full-value affordance \u2014 artifacts/pregasquad-manager/src/pages/BookingHistory.tsx:497"}, "fullDescription": {"text": "A visibly truncated value should expose its full text through an accessible tooltip, description, or equivalent interaction. Native `title=` is one option, but it is not the only valid implementation.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.65}}, {"id": "scanner-a4560e52955bb091", "name": "Truncated text has no discoverable full-value affordance \u2014 artifacts/pregasquad-manager/src/pages/Clients.tsx:709", "shortDescription": {"text": "Truncated text has no discoverable full-value affordance \u2014 artifacts/pregasquad-manager/src/pages/Clients.tsx:709"}, "fullDescription": {"text": "A visibly truncated value should expose its full text through an accessible tooltip, description, or equivalent interaction. Native `title=` is one option, but it is not the only valid implementation.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.65}}, {"id": "scanner-b06db29af3df354d", "name": "Truncated text has no discoverable full-value affordance \u2014 artifacts/pregasquad-manager/src/pages/Charges.tsx:777", "shortDescription": {"text": "Truncated text has no discoverable full-value affordance \u2014 artifacts/pregasquad-manager/src/pages/Charges.tsx:777"}, "fullDescription": {"text": "A visibly truncated value should expose its full text through an accessible tooltip, description, or equivalent interaction. Native `title=` is one option, but it is not the only valid implementation.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.65}}, {"id": "scanner-2c000fde0e374262", "name": "Truncated text has no discoverable full-value affordance \u2014 artifacts/pregasquad-manager/src/pages/Planning.tsx:230", "shortDescription": {"text": "Truncated text has no discoverable full-value affordance \u2014 artifacts/pregasquad-manager/src/pages/Planning.tsx:230"}, "fullDescription": {"text": "A visibly truncated value should expose its full text through an accessible tooltip, description, or equivalent interaction. Native `title=` is one option, but it is not the only valid implementation.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.65}}, {"id": "scanner-8389b3861444e72a", "name": "Truncated text has no discoverable full-value affordance \u2014 artifacts/pregasquad-manager/src/pages/StaffPortal.tsx:215", "shortDescription": {"text": "Truncated text has no discoverable full-value affordance \u2014 artifacts/pregasquad-manager/src/pages/StaffPortal.tsx:215"}, "fullDescription": {"text": "A visibly truncated value should expose its full text through an accessible tooltip, description, or equivalent interaction. Native `title=` is one option, but it is not the only valid implementation.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.65}}, {"id": "scanner-c0a4dca8d8cb1c96", "name": "Truncated text has no discoverable full-value affordance \u2014 artifacts/pregasquad-manager/src/pages/Staff.tsx:677", "shortDescription": {"text": "Truncated text has no discoverable full-value affordance \u2014 artifacts/pregasquad-manager/src/pages/Staff.tsx:677"}, "fullDescription": {"text": "A visibly truncated value should expose its full text through an accessible tooltip, description, or equivalent interaction. Native `title=` is one option, but it is not the only valid implementation.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.65}}, {"id": "scanner-bf2120a0dc582006", "name": "Truncated text has no discoverable full-value affordance \u2014 artifacts/pregasquad-manager/src/pages/POS.tsx:367", "shortDescription": {"text": "Truncated text has no discoverable full-value affordance \u2014 artifacts/pregasquad-manager/src/pages/POS.tsx:367"}, "fullDescription": {"text": "A visibly truncated value should expose its full text through an accessible tooltip, description, or equivalent interaction. Native `title=` is one option, but it is not the only valid implementation.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.65}}, {"id": "scanner-e97daf58d73ca27b", "name": "Truncated text has no discoverable full-value affordance \u2014 artifacts/pregasquad-manager/src/pages/Home.tsx:190", "shortDescription": {"text": "Truncated text has no discoverable full-value affordance \u2014 artifacts/pregasquad-manager/src/pages/Home.tsx:190"}, "fullDescription": {"text": "A visibly truncated value should expose its full text through an accessible tooltip, description, or equivalent interaction. Native `title=` is one option, but it is not the only valid implementation.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.65}}, {"id": "scanner-92559aaae451c545", "name": "Truncated text has no discoverable full-value affordance \u2014 artifacts/pregasquad-manager/src/pages/MyBookings.tsx:429", "shortDescription": {"text": "Truncated text has no discoverable full-value affordance \u2014 artifacts/pregasquad-manager/src/pages/MyBookings.tsx:429"}, "fullDescription": {"text": "A visibly truncated value should expose its full text through an accessible tooltip, description, or equivalent interaction. Native `title=` is one option, but it is not the only valid implementation.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.65}}, {"id": "scanner-ba2b5c25bd90752b", "name": "Truncated text has no discoverable full-value affordance \u2014 artifacts/pregasquad-manager/src/pages/Reports.tsx:792", "shortDescription": {"text": "Truncated text has no discoverable full-value affordance \u2014 artifacts/pregasquad-manager/src/pages/Reports.tsx:792"}, "fullDescription": {"text": "A visibly truncated value should expose its full text through an accessible tooltip, description, or equivalent interaction. Native `title=` is one option, but it is not the only valid implementation.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.65}}, {"id": "scanner-99859ea00b66de04", "name": "Debug `console.log` remains in browser-facing code \u2014 artifacts/pregasquad-manager/src/hooks/use-salon-data.ts:51", "shortDescription": {"text": "Debug `console.log` remains in browser-facing code \u2014 artifacts/pregasquad-manager/src/hooks/use-salon-data.ts:51"}, "fullDescription": {"text": "Remove debug output or route intentional diagnostics through the project's structured logger. Browser console output can expose state and create noise; server and CLI output are outside this rule's scope.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 0.85}}, {"id": "scanner-0416a48934a0f560", "name": "`dangerouslySetInnerHTML` used in a React component \u2014 artifacts/mockup-sandbox/src/components/ui/chart.tsx:79", "shortDescription": {"text": "`dangerouslySetInnerHTML` used in a React component \u2014 artifacts/mockup-sandbox/src/components/ui/chart.tsx:79"}, "fullDescription": {"text": "Open XSS surface unless the input is provably trusted. Replace with explicit JSX or sanitize via a vetted library.\n\nWhy: OWASP basics. Already partially flagged by the security analyzer.\nRule id: fq.dangerous-html"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "medium", "confidence": 0.8}}, {"id": "scanner-02482d7c6ffd044e", "name": "Truncated text has no discoverable full-value affordance \u2014 artifacts/mockup-sandbox/src/components/mockups/appointment-d", "shortDescription": {"text": "Truncated text has no discoverable full-value affordance \u2014 artifacts/mockup-sandbox/src/components/mockups/appointment-dialog/SoftRoseLuxury.tsx:105"}, "fullDescription": {"text": "A visibly truncated value should expose its full text through an accessible tooltip, description, or equivalent interaction. Native `title=` is one option, but it is not the only valid implementation.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.65}}, {"id": "scanner-2927d1589dd71f0d", "name": "Truncated text has no discoverable full-value affordance \u2014 artifacts/mockup-sandbox/src/components/mockups/charges/Glass", "shortDescription": {"text": "Truncated text has no discoverable full-value affordance \u2014 artifacts/mockup-sandbox/src/components/mockups/charges/GlassWater.tsx:362"}, "fullDescription": {"text": "A visibly truncated value should expose its full text through an accessible tooltip, description, or equivalent interaction. Native `title=` is one option, but it is not the only valid implementation.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.65}}, {"id": "scanner-4f765ae778431dec", "name": "react insecure request \u2014 .migration-backup/server/replit_integrations/object_storage/objectStorage.ts:280", "shortDescription": {"text": "react insecure request \u2014 .migration-backup/server/replit_integrations/object_storage/objectStorage.ts:280"}, "fullDescription": {"text": "Unencrypted request over HTTP detected.\n\nRule: typescript.react.security.react-insecure-request.react-insecure-request\nSeverity: ERROR\nOWASP: A03:2017 - Sensitive Data Exposure, A02:2021 - Cryptographic Failures, A04:2025 - Cryptographic Failures\nCWE: CWE-319: Cleartext Transmission of Sensitive Information\nCategory: security\nContext: production"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-b4fe1f6cd3164883", "name": "react insecure request \u2014 artifacts/api-server/src/replit_integrations/object_storage/objectStorage.ts:280", "shortDescription": {"text": "react insecure request \u2014 artifacts/api-server/src/replit_integrations/object_storage/objectStorage.ts:280"}, "fullDescription": {"text": "Unencrypted request over HTTP detected.\n\nRule: typescript.react.security.react-insecure-request.react-insecure-request\nSeverity: ERROR\nOWASP: A03:2017 - Sensitive Data Exposure, A02:2021 - Cryptographic Failures, A04:2025 - Cryptographic Failures\nCWE: CWE-319: Cleartext Transmission of Sensitive Information\nCategory: security\nContext: production"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-c6c38f15b5b6e7b5", "name": "CVE-2026-49356: @babel/core 7.28.5 \u2014 .migration-backup/package-lock.json", "shortDescription": {"text": "CVE-2026-49356: @babel/core 7.28.5 \u2014 .migration-backup/package-lock.json"}, "fullDescription": {"text": "@babel/core: @babel/core: Arbitrary file read via sourceMappingURL comment\n\nBabel is a compiler for writing next generation JavaScript. Prior to 8.0.0-rc.6 and 7.29.6, @babel/core affected by an arbitrary file read via a sourceMappingURL comment. Using @babel/core to compile maliciously crafted code can allow an attacker to read any source map from the system that is running Babel, if the attacker controls the input source code, can read the output source code, and knows the path of the source map file that they want to read. This vulnerability is fixed in 8.0.0-rc.6 an\n\nPackage: @babel/core\nInstalled: 7.28.5\nFixed in: 8.0.0-rc.6, 7.29.6\nSeverity: LOW\nFix: Upgrade @babel/core to 8.0.0-rc.6, 7.29.6"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-243b608fd15dc34f", "name": "CVE-2026-44728: @babel/plugin-transform-modules-systemjs 7.28.5 \u2014 .migration-backup/package-lock.json", "shortDescription": {"text": "CVE-2026-44728: @babel/plugin-transform-modules-systemjs 7.28.5 \u2014 .migration-backup/package-lock.json"}, "fullDescription": {"text": "Babel is a compiler for writing next generation JavaScript. From 7.12. ...\n\nBabel is a compiler for writing next generation JavaScript. From 7.12.0 to before 7.29.4 and 8.0.0-alpha.13, using Babel to compile code that was specifically crafted by an attacker can cause Babel to generate output code that executes arbitrary code. This vulnerability is fixed in 7.29.4 and 8.0.0-alpha.13.\n\nPackage: @babel/plugin-transform-modules-systemjs\nInstalled: 7.28.5\nFixed in: 7.29.4, 8.0.0-alpha.13\nSeverity: HIGH\nFix: Upgrade @babel/plugin-transform-modules-systemjs to 7.29.4, 8.0.0-alpha.13"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-b3dd3ee231a565ba", "name": "CVE-2026-25547: @isaacs/brace-expansion 5.0.0 \u2014 .migration-backup/package-lock.json", "shortDescription": {"text": "CVE-2026-25547: @isaacs/brace-expansion 5.0.0 \u2014 .migration-backup/package-lock.json"}, "fullDescription": {"text": "brace-expansion: brace-expansion: Denial of Service via unbounded brace range expansion\n\n@isaacs/brace-expansion is a hybrid CJS/ESM TypeScript fork of brace-expansion. Prior to version 5.0.1, @isaacs/brace-expansion is vulnerable to a denial of service (DoS) issue caused by unbounded brace range expansion. When an attacker provides a pattern containing repeated numeric brace ranges, the library attempts to eagerly generate every possible combination synchronously. Because the expansion grows exponentially, even a small input can consume excessive CPU and memory and may crash the No\n\nPackage: @isaacs/brace-expansion\nInstalled: 5.0.0\nFixed in: 5.0.1\nSeverity: HIGH\nFix: Upgrade @isaacs/brace-expansion to 5.0.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-3ebddbcdf2d43bf3", "name": "CVE-2026-3449: @tootallnate/once 2.0.0 \u2014 .migration-backup/package-lock.json", "shortDescription": {"text": "CVE-2026-3449: @tootallnate/once 2.0.0 \u2014 .migration-backup/package-lock.json"}, "fullDescription": {"text": "@tootallnate/once: @tootallnate/once: Denial of Service due to incorrect control flow scoping with AbortSignal\n\nVersions of the package @tootallnate/once before 3.0.1 are vulnerable to Incorrect Control Flow Scoping in promise resolving when AbortSignal option is used. The Promise remains in a permanently pending state after the signal is aborted, causing any await or .then() usage to hang indefinitely. This can cause a control-flow leak that can lead to stalled requests, blocked workers, or degraded application availability.\n\nPackage: @tootallnate/once\nInstalled: 2.0.0\nFixed in: 3.0.1, 2.0.1\nSeverity: LOW\nFix: Upgrade @tootallnate/once to 3.0.1, 2.0.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-45f864647e7bdd6b", "name": "CVE-2026-48063: @whiskeysockets/baileys 7.0.0-rc.9 \u2014 .migration-backup/package-lock.json", "shortDescription": {"text": "CVE-2026-48063: @whiskeysockets/baileys 7.0.0-rc.9 \u2014 .migration-backup/package-lock.json"}, "fullDescription": {"text": "Baileys has message upsert / hist sync spoofing and app state corruption when using maliciously crafted protocolMessage payload\n\nBaileys is a cocket-based TS/JavaScript API for WhatsApp Web. In versions prior to both 6.7.22 and 7.0.0-rc12, any Baileys session  can be sent a malicious payload via the placeholderResendMessage and trigger a fake messages.upsert event with a fake message key and payload. This allows anyone to spoof messages. The same exploit also allows an attacker to corrupt the app state sync system by sending fake key shares, and also allows for history sync spoofing which also serves the same problem, inj\n\nPackage: @whiskeysockets/baileys\nInstalled: 7.0.0-rc.9\nFixed in: 6.7.22, 7.0.0-rc12\nSeverity: CRITICAL\nFix: Upgrade @whiskeysockets/baileys to 6.7.22, 7.0.0-rc12"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "critical", "confidence": 1.0}}, {"id": "scanner-09f0c1b4ec446233", "name": "CVE-2026-34601: @xmldom/xmldom 0.8.11 \u2014 .migration-backup/package-lock.json", "shortDescription": {"text": "CVE-2026-34601: @xmldom/xmldom 0.8.11 \u2014 .migration-backup/package-lock.json"}, "fullDescription": {"text": "xmldom: xmldom: XML structure injection via CDATA terminator\n\nxmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) `DOMParser` and `XMLSerializer` module. In xmldom versions 0.6.0 and prior and @xmldom/xmldom prior to versions 0.8.12 and 0.9.9, xmldom/xmldom allows attacker-controlled strings containing the CDATA terminator ]]> to be inserted into a CDATASection node. During serialization, XMLSerializer emitted the CDATA content verbatim without rejecting or safely splitting the terminator. As a result, data intended to remain text-only be\n\nPackage: @xmldom/xmldom\nInstalled: 0.8.11\nFixed in: 0.8.12, 0.9.9\nSeverity: HIGH\nFix: Upgrade @xmldom/xmldom to 0.8.12, 0.9.9"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-85c657f0396a33a3", "name": "CVE-2026-41672: @xmldom/xmldom 0.8.11 \u2014 .migration-backup/package-lock.json", "shortDescription": {"text": "CVE-2026-41672: @xmldom/xmldom 0.8.11 \u2014 .migration-backup/package-lock.json"}, "fullDescription": {"text": "xmldom: @xmldom/xmldom: xmldom: Arbitrary XML Node Injection\n\nxmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) `DOMParser` and `XMLSerializer` module. In @xmldom/xmldom prior to versions 0.9.10 and 0.8.13 and xmldom version 0.6.0 and prior, the package allows attacker-controlled comment content to be serialized into XML without validating or neutralizing comment-breaking sequences. As a result, an attacker can terminate the comment early and inject arbitrary XML nodes into the serialized output. This issue has been patched in versions \n\nPackage: @xmldom/xmldom\nInstalled: 0.8.11\nFixed in: 0.8.13, 0.9.10\nSeverity: HIGH\nFix: Upgrade @xmldom/xmldom to 0.8.13, 0.9.10"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-0426ac768c965ab7", "name": "CVE-2026-41673: @xmldom/xmldom 0.8.11 \u2014 .migration-backup/package-lock.json", "shortDescription": {"text": "CVE-2026-41673: @xmldom/xmldom 0.8.11 \u2014 .migration-backup/package-lock.json"}, "fullDescription": {"text": "@xmldom/xmldom: xmldom: xmldom: Denial of Service via deeply nested XML documents\n\nxmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) `DOMParser` and `XMLSerializer` module. In @xmldom/xmldom prior to versions 0.9.10 and 0.8.13 and xmldom version 0.6.0 and prior, seven recursive traversals in lib/dom.js operate without a depth limit. A sufficiently deeply nested DOM tree causes a RangeError: Maximum call stack size exceeded, crashing the application. This issue has been patched in versions @xmldom/xmldom versions 0.9.10 and 0.8.13.\n\nPackage: @xmldom/xmldom\nInstalled: 0.8.11\nFixed in: 0.8.13, 0.9.10\nSeverity: HIGH\nFix: Upgrade @xmldom/xmldom to 0.8.13, 0.9.10"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-f17131c5c6eb8788", "name": "CVE-2026-41674: @xmldom/xmldom 0.8.11 \u2014 .migration-backup/package-lock.json", "shortDescription": {"text": "CVE-2026-41674: @xmldom/xmldom 0.8.11 \u2014 .migration-backup/package-lock.json"}, "fullDescription": {"text": "xmldom: xmldom: Arbitrary XML markup injection\n\nxmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) `DOMParser` and `XMLSerializer` module. In @xmldom/xmldom prior to versions 0.9.10 and 0.8.13 and xmldom version 0.6.0 and prior, the package serializes DocumentType node fields (internalSubset, publicId, systemId) verbatim without any escaping or validation. When these fields are set programmatically to attacker-controlled strings, XMLSerializer.serializeToString can produce output where the DOCTYPE declaration is terminated \n\nPackage: @xmldom/xmldom\nInstalled: 0.8.11\nFixed in: 0.8.13, 0.9.10\nSeverity: HIGH\nFix: Upgrade @xmldom/xmldom to 0.8.13, 0.9.10"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-d7a1daec34fe551d", "name": "CVE-2026-41675: @xmldom/xmldom 0.8.11 \u2014 .migration-backup/package-lock.json", "shortDescription": {"text": "CVE-2026-41675: @xmldom/xmldom 0.8.11 \u2014 .migration-backup/package-lock.json"}, "fullDescription": {"text": "xmldom: xmldom: Arbitrary XML node injection via crafted processing instructions\n\nxmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) `DOMParser` and `XMLSerializer` module. In @xmldom/xmldom prior to versions 0.9.10 and 0.8.13 and xmldom version 0.6.0 and prior, the package allows attacker-controlled processing instruction data to be serialized into XML without validating or neutralizing the PI-closing sequence ?>. As a result, an attacker can terminate the processing instruction early and inject arbitrary XML nodes into the serialized output. This issue ha\n\nPackage: @xmldom/xmldom\nInstalled: 0.8.11\nFixed in: 0.8.13, 0.9.10\nSeverity: HIGH\nFix: Upgrade @xmldom/xmldom to 0.8.13, 0.9.10"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-8165fb42f4e4865e", "name": "CVE-2025-69873: ajv 8.17.1 \u2014 .migration-backup/package-lock.json", "shortDescription": {"text": "CVE-2025-69873: ajv 8.17.1 \u2014 .migration-backup/package-lock.json"}, "fullDescription": {"text": "ajv: ReDoS via $data reference\n\najv (Another JSON Schema Validator) before 8.18.0 is vulnerable to Regular Expression Denial of Service (ReDoS) when the $data option is enabled. The pattern keyword accepts runtime data via JSON Pointer syntax ($data reference), which is passed directly to the JavaScript RegExp() constructor without validation. An attacker can inject a malicious regex pattern (e.g., \"^(a|a)*$\") combined with crafted input to cause catastrophic backtracking. A 31-character payload causes approximately 44 seconds\n\nPackage: ajv\nInstalled: 8.17.1\nFixed in: 8.18.0, 6.14.0\nSeverity: MEDIUM\nFix: Upgrade ajv to 8.18.0, 6.14.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-a618b02681693506", "name": "CVE-2026-25639: axios 1.13.2 \u2014 .migration-backup/package-lock.json", "shortDescription": {"text": "CVE-2026-25639: axios 1.13.2 \u2014 .migration-backup/package-lock.json"}, "fullDescription": {"text": "axios: Axios affected by Denial of Service via __proto__ Key in mergeConfig\n\nAxios is a promise based HTTP client for the browser and Node.js. Prior to versions 0.30.3 and 1.13.5, the mergeConfig function in axios crashes with a TypeError when processing configuration objects containing __proto__ as an own property. An attacker can trigger this by providing a malicious configuration object created via JSON.parse(), causing complete denial of service. This vulnerability is fixed in versions 0.30.3 and 1.13.5.\n\nPackage: axios\nInstalled: 1.13.2\nFixed in: 1.13.5, 0.30.3\nSeverity: HIGH\nFix: Upgrade axios to 1.13.5, 0.30.3"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-ab9c5d9bd2e0af69", "name": "CVE-2026-42033: axios 1.13.2 \u2014 .migration-backup/package-lock.json", "shortDescription": {"text": "CVE-2026-42033: axios 1.13.2 \u2014 .migration-backup/package-lock.json"}, "fullDescription": {"text": "axios: Axios: HTTP Transport Hijacking via Prototype Pollution\n\nAxios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, when Object.prototype has been polluted by any co-dependency with keys that axios reads without a hasOwnProperty guard, an attacker can (a) silently intercept and modify every JSON response before the application sees it, or (b) fully hijack the underlying HTTP transport, gaining access to request credentials, headers, and body. The precondition is prototype pollution from a separate source in the same \n\nPackage: axios\nInstalled: 1.13.2\nFixed in: 1.15.1, 0.31.1\nSeverity: HIGH\nFix: Upgrade axios to 1.15.1, 0.31.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-4f3c06f7a72b2b2d", "name": "CVE-2026-42035: axios 1.13.2 \u2014 .migration-backup/package-lock.json", "shortDescription": {"text": "CVE-2026-42035: axios 1.13.2 \u2014 .migration-backup/package-lock.json"}, "fullDescription": {"text": "axios: Axios: Arbitrary HTTP header injection via prototype pollution\n\nAxios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, a prototype pollution gadget exists in the Axios HTTP adapter (lib/adapters/http.js) that allows an attacker to inject arbitrary HTTP headers into outgoing requests. The vulnerability exploits duck-type checking of the data payload, where if Object.prototype is polluted with getHeaders, append, pipe, on, once, and Symbol.toStringTag, Axios misidentifies any plain object payload as a FormData instance an\n\nPackage: axios\nInstalled: 1.13.2\nFixed in: 1.15.1, 0.31.1\nSeverity: HIGH\nFix: Upgrade axios to 1.15.1, 0.31.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-513f5fff3af09297", "name": "CVE-2026-42043: axios 1.13.2 \u2014 .migration-backup/package-lock.json", "shortDescription": {"text": "CVE-2026-42043: axios 1.13.2 \u2014 .migration-backup/package-lock.json"}, "fullDescription": {"text": "axios: Axios: NO_PROXY bypass via crafted URL\n\nAxios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, an attacker who can influence the target URL of an Axios request can use any address in the 127.0.0.0/8 range (other than 127.0.0.1) to completely bypass the NO_PROXY protection. This vulnerability is due to an incomplete for CVE-2025-62718, This vulnerability is fixed in 1.15.1 and 0.31.1.\n\nPackage: axios\nInstalled: 1.13.2\nFixed in: 1.15.1, 0.31.1\nSeverity: HIGH\nFix: Upgrade axios to 1.15.1, 0.31.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-2e247d7abfd33a26", "name": "CVE-2026-42264: axios 1.13.2 \u2014 .migration-backup/package-lock.json", "shortDescription": {"text": "CVE-2026-42264: axios 1.13.2 \u2014 .migration-backup/package-lock.json"}, "fullDescription": {"text": "axios: Axios: Prototype pollution allows information disclosure and request manipulation\n\nAxios is a promise based HTTP client for the browser and Node.js. From version 1.0.0 to before version 1.15.2, fFive config properties (auth, baseURL, socketPath, beforeRedirect, and insecureHTTPParser) in the HTTP adapter are read via direct property access without hasOwnProperty guards, making them exploitable as prototype pollution gadgets. When Object.prototype is polluted by another dependency in the same process, axios silently picks up these polluted values on every outbound HTTP request.\n\nPackage: axios\nInstalled: 1.13.2\nFixed in: 1.15.2\nSeverity: HIGH\nFix: Upgrade axios to 1.15.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-19e173bfdef24743", "name": "CVE-2026-44486: axios 1.13.2 \u2014 .migration-backup/package-lock.json", "shortDescription": {"text": "CVE-2026-44486: axios 1.13.2 \u2014 .migration-backup/package-lock.json"}, "fullDescription": {"text": "axios: Axios: Information disclosure of proxy credentials via HTTP redirects\n\nAxios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, Axios\u2019 Node.js HTTP adapter can leak proxy credentials to a redirect target in affected versions. When a request is sent through an authenticated proxy, Axios may add a Proxy-Authorization header. If Axios then follows a redirect and the redirected request is no longer sent through that proxy, the stale Proxy-Authorization header can remain on the redirected request and be sent to the redirect target. T\n\nPackage: axios\nInstalled: 1.13.2\nFixed in: 1.16.0, 0.32.0\nSeverity: HIGH\nFix: Upgrade axios to 1.16.0, 0.32.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-756f54d231cb9b76", "name": "CVE-2026-44487: axios 1.13.2 \u2014 .migration-backup/package-lock.json", "shortDescription": {"text": "CVE-2026-44487: axios 1.13.2 \u2014 .migration-backup/package-lock.json"}, "fullDescription": {"text": "axios: Axios: Information disclosure of proxy credentials via redirect flows\n\nAxios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, Axios\u2019s Node.js HTTP adapter may forward a Proxy-Authorization header to a redirected origin during specific proxy-to-direct redirect flows. This affects Node.js usage, where an initial HTTP request is sent through an authenticated HTTP proxy, redirects are followed, and the redirected URL is no longer proxied. Under affected redirect shapes, the final origin can receive the proxy credential that was in\n\nPackage: axios\nInstalled: 1.13.2\nFixed in: 1.16.0, 0.32.0\nSeverity: HIGH\nFix: Upgrade axios to 1.16.0, 0.32.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-c7fe83d58fe64294", "name": "CVE-2026-44488: axios 1.13.2 \u2014 .migration-backup/package-lock.json", "shortDescription": {"text": "CVE-2026-44488: axios 1.13.2 \u2014 .migration-backup/package-lock.json"}, "fullDescription": {"text": "axios: Axios: Denial of Service due to unenforced request and response size limits\n\nAxios is a promise based HTTP client for the browser and Node.js. Axios versions 1.7.0 through 1.15.x did not enforce configured request and response size limits when requests were sent with the fetch adapter. Applications that selected adapter: 'fetch', or ran in environments where axios resolved to the fetch adapter, could receive or send bodies larger than maxContentLength or maxBodyLength despite those limits being explicitly configured. This can cause resource exhaustion in server-side usag\n\nPackage: axios\nInstalled: 1.13.2\nFixed in: 1.16.0\nSeverity: HIGH\nFix: Upgrade axios to 1.16.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-627a9eec7dc4855f", "name": "CVE-2026-44494: axios 1.13.2 \u2014 .migration-backup/package-lock.json", "shortDescription": {"text": "CVE-2026-44494: axios 1.13.2 \u2014 .migration-backup/package-lock.json"}, "fullDescription": {"text": "axios: Axios: Man-in-the-Middle (MITM) attack via Prototype Pollution\n\nAxios is a promise based HTTP client for the browser and Node.js. From 1.0.0 to before 1.16.0, the Axios library is vulnerable to a Prototype Pollution \"Gadget\" attack that allows any Object.prototype pollution in the application's dependency tree to be escalated into a full Man-in-the-Middle (MITM) attack \u2014 intercepting, reading, and modifying all HTTP traffic including authentication credentials. The HTTP adapter at lib/adapters/http.js:670 reads config.proxy via standard property access, whic\n\nPackage: axios\nInstalled: 1.13.2\nFixed in: 1.16.0\nSeverity: HIGH\nFix: Upgrade axios to 1.16.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-d4e02ed22235f31b", "name": "CVE-2026-44495: axios 1.13.2 \u2014 .migration-backup/package-lock.json", "shortDescription": {"text": "CVE-2026-44495: axios 1.13.2 \u2014 .migration-backup/package-lock.json"}, "fullDescription": {"text": "axios: Axios: Information disclosure due to prototype pollution vulnerability\n\nAxios is a promise based HTTP client for the browser and Node.js. From 0.19.0 to before 0.31.1 and 1.15.2, Axios contains prototype-pollution gadgets in request config processing. If another vulnerability in the same JavaScript process has already polluted Object.prototype.transformResponse, affected Axios versions may treat that inherited value as request configuration or as an option validator. Axios does not itself create the prototype pollution. Exploitability requires a separate prototype-p\n\nPackage: axios\nInstalled: 1.13.2\nFixed in: 1.15.2, 0.31.1\nSeverity: HIGH\nFix: Upgrade axios to 1.15.2, 0.31.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-497b05574f32e2f1", "name": "CVE-2026-44496: axios 1.13.2 \u2014 .migration-backup/package-lock.json", "shortDescription": {"text": "CVE-2026-44496: axios 1.13.2 \u2014 .migration-backup/package-lock.json"}, "fullDescription": {"text": "axios: Axios: Client-side Denial of Service via unescaped regex metacharacters in XSRF cookie name\n\nAxios is a promise based HTTP client for the browser and Node.js. Axios versions before 0.32.0 on the 0.x line and before 1.16.0 on the 1.x line build a regular expression from the configured XSRF cookie name without escaping regex metacharacters. In standard browser environments, an attacker who can influence the cookie name passed to axios can cause expensive regex backtracking while axios reads document.cookie. The practical impact is client-side availability degradation, such as freezing the\n\nPackage: axios\nInstalled: 1.13.2\nFixed in: 1.16.0, 0.32.0\nSeverity: HIGH\nFix: Upgrade axios to 1.16.0, 0.32.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-a0edcfccff66eedf", "name": "CVE-2025-62718: axios 1.13.2 \u2014 .migration-backup/package-lock.json", "shortDescription": {"text": "CVE-2025-62718: axios 1.13.2 \u2014 .migration-backup/package-lock.json"}, "fullDescription": {"text": "axios: Axios: Server-Side Request Forgery and proxy bypass due to improper hostname normalization\n\nAxios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.0 and 0.31.0, Axios does not correctly handle hostname normalization when checking NO_PROXY rules. Requests to loopback addresses like localhost. (with a trailing dot) or [::1] (IPv6 literal) skip NO_PROXY matching and go through the configured proxy. This goes against what developers expect and lets attackers force requests through a proxy, even if NO_PROXY is set up to protect loopback or internal services. This is\n\nPackage: axios\nInstalled: 1.13.2\nFixed in: 1.15.0, 0.31.0\nSeverity: MEDIUM\nFix: Upgrade axios to 1.15.0, 0.31.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-122a3ac56316b0f6", "name": "CVE-2026-40175: axios 1.13.2 \u2014 .migration-backup/package-lock.json", "shortDescription": {"text": "CVE-2026-40175: axios 1.13.2 \u2014 .migration-backup/package-lock.json"}, "fullDescription": {"text": "axios: Axios: Remote Code Execution via Prototype Pollution escalation\n\nAxios is a promise based HTTP client for the browser and Node.js. Versions prior to 1.15.0 and 0.3.1 are vulnerable to a specific gadget-style attack chain in which prototype pollution in a third-party dependency may be leveraged to inject unsanitized header values into outbound requests. This vulnerability is fixed in 1.15.0 and 0.3.1.\n\nPackage: axios\nInstalled: 1.13.2\nFixed in: 1.15.0, 0.31.0\nSeverity: MEDIUM\nFix: Upgrade axios to 1.15.0, 0.31.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-e53212f9f7a81b44", "name": "CVE-2026-42034: axios 1.13.2 \u2014 .migration-backup/package-lock.json", "shortDescription": {"text": "CVE-2026-42034: axios 1.13.2 \u2014 .migration-backup/package-lock.json"}, "fullDescription": {"text": "axios: Axios: Denial of Service via oversized streamed uploads bypassing body limits\n\nAxios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, for stream request bodies, maxBodyLength is bypassed when maxRedirects is set to 0 (native http/https transport path). Oversized streamed uploads are sent fully even when the caller sets strict body limits. This vulnerability is fixed in 1.15.1 and 0.31.1.\n\nPackage: axios\nInstalled: 1.13.2\nFixed in: 1.15.1, 0.31.1\nSeverity: MEDIUM\nFix: Upgrade axios to 1.15.1, 0.31.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-a7b8751ef3ac9afe", "name": "CVE-2026-42036: axios 1.13.2 \u2014 .migration-backup/package-lock.json", "shortDescription": {"text": "CVE-2026-42036: axios 1.13.2 \u2014 .migration-backup/package-lock.json"}, "fullDescription": {"text": "axios: Axios: Denial of Service via unbounded stream consumption when 'responseType: 'stream'' is used\n\nAxios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, when responseType: 'stream' is used, Axios returns the response stream without enforcing maxContentLength. This bypasses configured response-size limits and allows unbounded downstream consumption. This vulnerability is fixed in 1.15.1 and 0.31.1.\n\nPackage: axios\nInstalled: 1.13.2\nFixed in: 1.15.1, 0.31.1\nSeverity: MEDIUM\nFix: Upgrade axios to 1.15.1, 0.31.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b44965bb351b6428", "name": "CVE-2026-42037: axios 1.13.2 \u2014 .migration-backup/package-lock.json", "shortDescription": {"text": "CVE-2026-42037: axios 1.13.2 \u2014 .migration-backup/package-lock.json"}, "fullDescription": {"text": "axios: Node.js: Axios: Information disclosure via CRLF injection in multipart Content-Type header\n\nAxios is a promise based HTTP client for the browser and Node.js. From 1.0.0 to before 1.15.1, the FormDataPart constructor in lib/helpers/formDataToStream.js interpolates value.type directly into the Content-Type header of each multipart part without sanitizing CRLF (\\r\\n) sequences. An attacker who controls the .type property of a Blob/File-like object (e.g., via a user-uploaded file in a Node.js proxy service) can inject arbitrary MIME part headers into the multipart form-data body. This bypa\n\nPackage: axios\nInstalled: 1.13.2\nFixed in: 1.15.1\nSeverity: MEDIUM\nFix: Upgrade axios to 1.15.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-0f9337daebe843cd", "name": "CVE-2026-42038: axios 1.13.2 \u2014 .migration-backup/package-lock.json", "shortDescription": {"text": "CVE-2026-42038: axios 1.13.2 \u2014 .migration-backup/package-lock.json"}, "fullDescription": {"text": "axios: Axios: Information disclosure due to `no_proxy` bypass\n\nAxios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, he fix for no_proxy hostname normalization bypass is incomplete. When no_proxy=localhost is set, requests to 127.0.0.1 and [::1] still route through the proxy instead of bypassing it. The shouldBypassProxy() function does pure string matching \u2014 it does not resolve IP aliases or loopback equivalents. This vulnerability is fixed in 1.15.1 and 0.31.1.\n\nPackage: axios\nInstalled: 1.13.2\nFixed in: 1.15.1, 0.31.1\nSeverity: MEDIUM\nFix: Upgrade axios to 1.15.1, 0.31.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-4ab4953dfdf824c3", "name": "CVE-2026-42039: axios 1.13.2 \u2014 .migration-backup/package-lock.json", "shortDescription": {"text": "CVE-2026-42039: axios 1.13.2 \u2014 .migration-backup/package-lock.json"}, "fullDescription": {"text": "axios: Node.js: Axios: Denial of Service via unbounded recursion in toFormData with deeply nested request data\n\nAxios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, toFormData recursively walks nested objects with no depth limit, so a deeply nested value passed as request data crashes the Node.js process with a RangeError. This vulnerability is fixed in 1.15.1 and 0.31.1.\n\nPackage: axios\nInstalled: 1.13.2\nFixed in: 1.15.1, 0.31.1\nSeverity: MEDIUM\nFix: Upgrade axios to 1.15.1, 0.31.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ddeccb35106b6107", "name": "CVE-2026-42041: axios 1.13.2 \u2014 .migration-backup/package-lock.json", "shortDescription": {"text": "CVE-2026-42041: axios 1.13.2 \u2014 .migration-backup/package-lock.json"}, "fullDescription": {"text": "axios: Axios: Authentication bypass due to prototype pollution of HTTP error handling\n\nAxios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, the Axios library is vulnerable to a Prototype Pollution \"Gadget\" attack that allows any Object.prototype pollution to silently suppress all HTTP error responses (401, 403, 500, etc.), causing them to be treated as successful responses. This completely bypasses application-level authentication and error handling. The root cause is that validateStatus is the only config property using the mergeDirectKeys\n\nPackage: axios\nInstalled: 1.13.2\nFixed in: 1.15.1, 0.31.1\nSeverity: MEDIUM\nFix: Upgrade axios to 1.15.1, 0.31.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-de36057e8b24c101", "name": "CVE-2026-42042: axios 1.13.2 \u2014 .migration-backup/package-lock.json", "shortDescription": {"text": "CVE-2026-42042: axios 1.13.2 \u2014 .migration-backup/package-lock.json"}, "fullDescription": {"text": "axios: Axios: XSRF token bypass leading to information disclosure\n\nAxios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, the Axios library's XSRF token protection logic uses JavaScript truthy/falsy semantics instead of strict boolean comparison for the withXSRFToken config property. When this property is set to any truthy non-boolean value (via prototype pollution or misconfiguration), the same-origin check (isURLSameOrigin) is short-circuited, causing XSRF tokens to be sent to all request targets including cross-origin s\n\nPackage: axios\nInstalled: 1.13.2\nFixed in: 1.15.1, 0.31.1\nSeverity: MEDIUM\nFix: Upgrade axios to 1.15.1, 0.31.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-2f1031dd461089db", "name": "CVE-2026-42044: axios 1.13.2 \u2014 .migration-backup/package-lock.json", "shortDescription": {"text": "CVE-2026-42044: axios 1.13.2 \u2014 .migration-backup/package-lock.json"}, "fullDescription": {"text": "axios: Axios: Invisible JSON Response Tampering via Prototype Pollution Gadget\n\nAxios is a promise based HTTP client for the browser and Node.js. From 1.0.0 to before 1.15.2, he Axios library is vulnerable to a Prototype Pollution \"Gadget\" attack that allows any Object.prototype pollution in the application's dependency tree to be escalated into surgical, invisible modification of all JSON API responses \u2014 including privilege escalation, balance manipulation, and authorization bypass. The default transformResponse function at lib/defaults/index.js:124 calls JSON.parse(data, \n\nPackage: axios\nInstalled: 1.13.2\nFixed in: 1.15.2\nSeverity: MEDIUM\nFix: Upgrade axios to 1.15.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-5c0ad999116faa59", "name": "CVE-2026-44490: axios 1.13.2 \u2014 .migration-backup/package-lock.json", "shortDescription": {"text": "CVE-2026-44490: axios 1.13.2 \u2014 .migration-backup/package-lock.json"}, "fullDescription": {"text": "axios: Axios: Information disclosure and denial of service due to prototype pollution\n\nAxios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, axios exposes two read-side prototype-pollution gadgets. When Object.prototype is polluted by an upstream dependency in the same process (e.g. lodash _.merge / CVE-2018-16487), axios silently picks up the polluted values. (1) lib/utils.js line 406 builds merge()'s accumulator as result = {}, so result[targetKey] (line 414) walks Object.prototype and the polluted bucket's own keys are copied into the mer\n\nPackage: axios\nInstalled: 1.13.2\nFixed in: 1.16.0, 0.32.0\nSeverity: MEDIUM\nFix: Upgrade axios to 1.16.0, 0.32.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-db815f5d5fa0cd03", "name": "CVE-2026-67312: axios 1.13.2 \u2014 .migration-backup/package-lock.json", "shortDescription": {"text": "CVE-2026-67312: axios 1.13.2 \u2014 .migration-backup/package-lock.json"}, "fullDescription": {"text": "axios: axios: Denial of Service via uncontrolled recursion in form data processing\n\naxios versions from 0.28.0 before 0.33.0 and from 1.0.0 before 1.18.0 contain uncontrolled recursion in formDataToJSON (exposed as axios.formToJSON() and used internally when serializing FormData with Content-Type: application/json). When an application passes attacker-controlled FormData field names, a field name with thousands of nested bracket-delimited segments causes unbounded recursion in buildPath(), exhausting the JavaScript call stack (RangeError: Maximum call stack size exceeded) and c\n\nPackage: axios\nInstalled: 1.13.2\nFixed in: 0.33.0, 1.18.0\nSeverity: MEDIUM\nFix: Upgrade axios to 0.33.0, 1.18.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-1efb0227c205b2fe", "name": "CVE-2026-67316: axios 1.13.2 \u2014 .migration-backup/package-lock.json", "shortDescription": {"text": "CVE-2026-67316: axios 1.13.2 \u2014 .migration-backup/package-lock.json"}, "fullDescription": {"text": "axios: axios: Prototype Pollution allows unauthorized data transmission and network redirection\n\naxios is vulnerable to read-side prototype-pollution gadgets that can alter request construction when Object.prototype has already been polluted by a separate vulnerability or dependency. In the bodyless method aliases (axios.get(), axios.delete(), axios.head(), axios.options()), inherited data is read via (config || {}).data before config normalization, causing an attacker-controlled body to be sent on requests that did not set one. Additional low-level paths, only reachable when calling export\n\nPackage: axios\nInstalled: 1.13.2\nFixed in: 1.18.0, 0.33.0\nSeverity: MEDIUM\nFix: Upgrade axios to 1.18.0, 0.33.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-becd814d7b613c04", "name": "GHSA-42h9-826w-cgv3: axios 1.13.2 \u2014 .migration-backup/package-lock.json", "shortDescription": {"text": "GHSA-42h9-826w-cgv3: axios 1.13.2 \u2014 .migration-backup/package-lock.json"}, "fullDescription": {"text": "Axios: Excessive recursion in formDataToJSON can cause denial of service\n\n## Summary\nAxios versions `0.28.0` and later contain uncontrolled recursion in `formDataToJSON`, the helper behind the public `axios.formToJSON()` / named `formToJSON` API and the default request transform used when FormData is sent with an `application/json` content type.\n\nApplications are affected when they pass attacker-controlled `FormData` field names into this functionality. A field name with thousands of nested bracket segments can exhaust the JavaScript call stack and throw `RangeError: \n\nPackage: axios\nInstalled: 1.13.2\nFixed in: 0.33.0, 1.18.0\nSeverity: MEDIUM\nFix: Upgrade axios to 0.33.0, 1.18.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-073e9ca5b0a3309f", "name": "GHSA-7q8q-rj6j-mhjq: axios 1.13.2 \u2014 .migration-backup/package-lock.json", "shortDescription": {"text": "GHSA-7q8q-rj6j-mhjq: axios 1.13.2 \u2014 .migration-backup/package-lock.json"}, "fullDescription": {"text": "Axios: Nested axios option objects can consume polluted prototype values\n\n## Summary\n\nAxios can consume inherited properties from nested request option objects when the JavaScript process already has a polluted `Object.prototype`.\n\nThe top-level merged config is protected with a null prototype, but nested plain objects such as `auth` and `paramsSerializer` are cloned into ordinary objects. If application code passes placeholders such as `auth: {}` or `paramsSerializer: {}`, inherited `username`, `password`, `encode`, or `serialize` properties can influence outbound re\n\nPackage: axios\nInstalled: 1.13.2\nFixed in: 0.33.0, 1.18.0\nSeverity: MEDIUM\nFix: Upgrade axios to 0.33.0, 1.18.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-483496a466bd40fb", "name": "GHSA-jqh4-m9w3-8hp9: axios 1.13.2 \u2014 .migration-backup/package-lock.json", "shortDescription": {"text": "GHSA-jqh4-m9w3-8hp9: axios 1.13.2 \u2014 .migration-backup/package-lock.json"}, "fullDescription": {"text": "Axios: Fetch adapter `ReadableStream` uploads bypass `maxBodyLength`\n\n## Summary\n\naxios\u2019 fetch adapter does not enforce `maxBodyLength` for live WHATWG `ReadableStream` request bodies whose size cannot be determined before dispatch. Applications that use `adapter: \"fetch\"` and rely on `maxBodyLength` to cap untrusted upload/proxy streams can send the full stream even when it exceeds the configured limit.\n\nThis affects fetch-adapter usage in edge runtimes where fetch is selected, and in Node.js or browser environments where the fetch adapter is explicitly selected.\n\nPackage: axios\nInstalled: 1.13.2\nFixed in: 1.18.0\nSeverity: MEDIUM\nFix: Upgrade axios to 1.18.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-f57372826c3d9ea7", "name": "GHSA-mwf2-3pr3-8698: axios 1.13.2 \u2014 .migration-backup/package-lock.json", "shortDescription": {"text": "GHSA-mwf2-3pr3-8698: axios 1.13.2 \u2014 .migration-backup/package-lock.json"}, "fullDescription": {"text": "Axios: HTTP/2 streamed uploads bypass `maxBodyLength`\n\n## Summary\n\nAxios versions with Node.js HTTP/2 support allow streamed request bodies to bypass `maxBodyLength` enforcement when requests are sent with `httpVersion: 2`.\n\nThis affects applications that rely on `maxBodyLength` as a hard cap while forwarding attacker-controlled streams, such as upload endpoints proxying user data to an upstream HTTP/2 service. Buffered request bodies are still checked before the request is sent.\n\n## Impact\n\nAn attacker who can control a stream passed to axios can c\n\nPackage: axios\nInstalled: 1.13.2\nFixed in: 1.18.0\nSeverity: MEDIUM\nFix: Upgrade axios to 1.18.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-f3b4273fb283a749", "name": "CVE-2026-42040: axios 1.13.2 \u2014 .migration-backup/package-lock.json", "shortDescription": {"text": "CVE-2026-42040: axios 1.13.2 \u2014 .migration-backup/package-lock.json"}, "fullDescription": {"text": "axios: Axios: Incorrect null byte handling can lead to data integrity issues\n\nAxios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, the encode() function in lib/helpers/AxiosURLSearchParams.js contains a character mapping (charMap) at line 21 that reverses the safe percent-encoding of null bytes. After encodeURIComponent('\\x00') correctly produces the safe sequence %00, the charMap entry '%00': '\\x00' converts it back to a raw null byte. Primary impact is limited because the standard axios request flow is not affected. This vulnerab\n\nPackage: axios\nInstalled: 1.13.2\nFixed in: 1.15.1, 0.31.1\nSeverity: LOW\nFix: Upgrade axios to 1.15.1, 0.31.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2f2b98bf2f78ae98", "name": "CVE-2026-2739: bn.js 4.12.2 \u2014 .migration-backup/package-lock.json", "shortDescription": {"text": "CVE-2026-2739: bn.js 4.12.2 \u2014 .migration-backup/package-lock.json"}, "fullDescription": {"text": "bn.js: bn.js: Denial of Service via calling maskn(0)\n\nThis affects versions of the package bn.js before 5.2.3. Calling maskn(0) on any BN instance corrupts the internal state, causing toString(), divmod(), and other methods to enter an infinite loop, hanging the process indefinitely.\n\nPackage: bn.js\nInstalled: 4.12.2\nFixed in: 4.12.3, 5.2.3\nSeverity: MEDIUM\nFix: Upgrade bn.js to 4.12.3, 5.2.3"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-74044c26d670987b", "name": "CVE-2026-12590: body-parser 1.20.4 \u2014 .migration-backup/package-lock.json", "shortDescription": {"text": "CVE-2026-12590: body-parser 1.20.4 \u2014 .migration-backup/package-lock.json"}, "fullDescription": {"text": "body-parser: body-parser: Denial of Service via invalid limit option\n\nImpact: In body-parser versions prior to 1.20.6 (1.x line) and 2.3.0 (2.x line), when the parser is configured with an invalid limit option value such as an unparseable string or NaN, bytes.parse returns null and the request body size check is silently skipped. Applications that rely on limit as their primary safeguard against oversized request bodies will accept arbitrarily large payloads, leading to excessive memory and CPU usage and denial of service. Patches: This issue is fixed in body-pars\n\nPackage: body-parser\nInstalled: 1.20.4\nFixed in: 1.20.6, 2.3.0\nSeverity: LOW\nFix: Upgrade body-parser to 1.20.6, 2.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-43550612bada21fa", "name": "CVE-2026-13149: brace-expansion 2.0.2 \u2014 .migration-backup/package-lock.json", "shortDescription": {"text": "CVE-2026-13149: brace-expansion 2.0.2 \u2014 .migration-backup/package-lock.json"}, "fullDescription": {"text": "brace-expansion: Brace-expansion: Denial of Service due to exponential-time complexity\n\nbrace-expansion through 5.0.6 is vulnerable to denial of service. The expand() function exhibits exponential-time complexity in the number of consecutive non-expanding '{}' brace groups. An attacker who passes a crafted string to expand(), directly or transitively, can cause significant CPU consumption and event-loop blocking. The max option does not mitigate this, as it bounds the output size rather than the recursion work.\n\nPackage: brace-expansion\nInstalled: 2.0.2\nFixed in: 5.0.7, 1.1.16, 2.1.2\nSeverity: HIGH\nFix: Upgrade brace-expansion to 5.0.7, 1.1.16, 2.1.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-52df6a19078a083b", "name": "CVE-2026-14257: brace-expansion 2.0.2 \u2014 .migration-backup/package-lock.json", "shortDescription": {"text": "CVE-2026-14257: brace-expansion 2.0.2 \u2014 .migration-backup/package-lock.json"}, "fullDescription": {"text": "brace-expansion: Brace-expansion: Denial of Service via memory exhaustion in expand() function\n\nbrace-expansion through 5.0.7 is vulnerable to denial of service via memory exhaustion. The expand() function limits the number of results with a max option (default 100,000) but does not bound the length of each result string. By chaining multiple brace groups, an attacker keeps the result count under the limit while making each result progressively longer, so total memory scales with both count and string length until the process hits a fatal, uncatchable out-of-memory error. About 7.5 KB of i\n\nPackage: brace-expansion\nInstalled: 2.0.2\nFixed in: 5.0.8, 3.0.3, 2.1.3, 1.1.17\nSeverity: HIGH\nFix: Upgrade brace-expansion to 5.0.8, 3.0.3, 2.1.3, 1.1.17"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-7d3d39ff0adba768", "name": "CVE-2026-69152: brace-expansion 2.0.2 \u2014 .migration-backup/package-lock.json", "shortDescription": {"text": "CVE-2026-69152: brace-expansion 2.0.2 \u2014 .migration-backup/package-lock.json"}, "fullDescription": {"text": "brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation\n\nThe brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.18, 2.1.4, 3.0.6, and 5.0.9, expand() does not apply maxLength while constructing comma-alternative intermediate arrays or padded sequences, allowing attacker-controlled input to exhaust memory or block the event loop. The fix for CVE-2026-14257 is bypassed by the vulnerability. This issue is fixed in versions 1.1.18, 2.1.4, 3.0.6, and 5.0.9.\n\nPackage: brace-expansion\nInstalled: 2.0.2\nFixed in: 1.1.18, 2.1.4, 3.0.6, 5.0.9\nSeverity: HIGH\nFix: Upgrade brace-expansion to 1.1.18, 2.1.4, 3.0.6, 5.0.9"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-2f2b5f4facd665c9", "name": "CVE-2026-33750: brace-expansion 2.0.2 \u2014 .migration-backup/package-lock.json", "shortDescription": {"text": "CVE-2026-33750: brace-expansion 2.0.2 \u2014 .migration-backup/package-lock.json"}, "fullDescription": {"text": "brace-expansion: brace-expansion: Denial of Service via zero step value in brace pattern\n\nThe brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to versions 5.0.5, 3.0.2, 2.0.3, and 1.1.13, a brace pattern with a zero step value (e.g., `{1..2..0}`) causes the sequence generation loop to run indefinitely, making the process hang for seconds and allocate heaps of memory. Versions 5.0.5, 3.0.2, 2.0.3, and 1.1.13 fix the issue. As a workaround, sanitize strings passed to `expand()` to ensure a step value of `0` is not used.\n\nPackage: brace-expansion\nInstalled: 2.0.2\nFixed in: 5.0.5, 3.0.2, 2.0.3, 1.1.13\nSeverity: MEDIUM\nFix: Upgrade brace-expansion to 5.0.5, 3.0.2, 2.0.3, 1.1.13"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-a4d831c90fffeb9c", "name": "CVE-2026-39356: drizzle-orm 0.39.3 \u2014 .migration-backup/package-lock.json", "shortDescription": {"text": "CVE-2026-39356: drizzle-orm 0.39.3 \u2014 .migration-backup/package-lock.json"}, "fullDescription": {"text": "Drizzle ORM has SQL injection via improperly escaped SQL identifiers\n\nDrizzle is a modern TypeScript ORM. Prior to 0.45.2 and 1.0.0-beta.20, Drizzle ORM improperly escaped quoted SQL identifiers in its dialect-specific escapeName() implementations. In affected versions, embedded identifier delimiters were not escaped before the identifier was wrapped in quotes or backticks. As a result, applications that pass attacker-controlled input to APIs that construct SQL identifiers or aliases, such as sql.identifier(), .as(), may allow an attacker to terminate the quoted i\n\nPackage: drizzle-orm\nInstalled: 0.39.3\nFixed in: 0.45.2, 1.0.0-beta.20\nSeverity: HIGH\nFix: Upgrade drizzle-orm to 0.45.2, 1.0.0-beta.20"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-0b27f2e566913181", "name": "CVE-2026-59724: engine.io 6.6.5 \u2014 .migration-backup/package-lock.json", "shortDescription": {"text": "CVE-2026-59724: engine.io 6.6.5 \u2014 .migration-backup/package-lock.json"}, "fullDescription": {"text": "engine.io: Engine.IO: Denial of Service via crafted WebTransport session ID\n\nSocket.IO enables bidirectional and low-latency communication for every platform. From 6.5.0 before 6.6.7, Engine.IO servers with WebTransport enabled can resolve a crafted session ID such as __proto__ through an inherited property of the clients object during WebTransport upgrade handling, causing a TypeError and denial of service. This issue is fixed in version 6.6.7.\n\nPackage: engine.io\nInstalled: 6.6.5\nFixed in: 6.6.7\nSeverity: HIGH\nFix: Upgrade engine.io to 6.6.7"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-12ae96f103d48a0d", "name": "CVE-2026-59725: engine.io 6.6.5 \u2014 .migration-backup/package-lock.json", "shortDescription": {"text": "CVE-2026-59725: engine.io 6.6.5 \u2014 .migration-backup/package-lock.json"}, "fullDescription": {"text": "socket.io: engine.io: Socket.IO: Denial of Service via invalid binary POST requests\n\nSocket.IO enables bidirectional and low-latency communication for every platform. From 4.1.0 before 6.6.7, Engine.IO protocol v4 polling transport does not properly close the HTTP response for invalid binary POST requests with Content-Type: application/octet-stream, allowing an unauthenticated attacker to exhaust server-side connections and sockets. This issue is fixed in version 6.6.7.\n\nPackage: engine.io\nInstalled: 6.6.5\nFixed in: 6.6.7\nSeverity: HIGH\nFix: Upgrade engine.io to 6.6.7"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-eb6f9fcf16589539", "name": "CVE-2026-13676: fast-uri 3.1.0 \u2014 .migration-backup/package-lock.json", "shortDescription": {"text": "CVE-2026-13676: fast-uri 3.1.0 \u2014 .migration-backup/package-lock.json"}, "fullDescription": {"text": "fast-uri: fast-uri: Security policy bypass due to improper Unicode hostname canonicalization\n\nfast-uri versions 2.3.1 through 3.1.2 and 4.0.0 fail to canonicalize Unicode (IDN) hostnames for HTTP-family URLs. The IDN conversion path calls a helper that does not exist on the global URL constructor, silently leaving the host in its original Unicode form while normalize() and equal() still return values that differ from a WHATWG-compatible URL parser. Applications that use fast-uri to enforce host-based policy (denylists, loopback filtering, redirect validation, outbound proxy routing) befo\n\nPackage: fast-uri\nInstalled: 3.1.0\nFixed in: 4.0.1, 3.1.3, 2.4.2\nSeverity: HIGH\nFix: Upgrade fast-uri to 4.0.1, 3.1.3, 2.4.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-87ff36bc4d55b755", "name": "CVE-2026-16221: fast-uri 3.1.0 \u2014 .migration-backup/package-lock.json", "shortDescription": {"text": "CVE-2026-16221: fast-uri 3.1.0 \u2014 .migration-backup/package-lock.json"}, "fullDescription": {"text": "fast-uri: Fast-uri: Security policy bypass due to URL parsing inconsistency\n\nImpact: fast-uri versions from 2.3.1 through 4.1.0 (including the 3.x line up to 3.1.3 and the 2.x line up to 2.4.2) do not treat a literal backslash character (U+005C) as an authority delimiter. Node's native WHATWG URL parser, used by fetch, undici, and Node's http and https clients, normalizes the backslash to a forward slash for special schemes such as http, https, ws, wss, ftp, and file. As a result, the two parsers extract different hosts from the same input string. Applications that use f\n\nPackage: fast-uri\nInstalled: 3.1.0\nFixed in: 2.4.3, 3.1.4, 4.1.1\nSeverity: HIGH\nFix: Upgrade fast-uri to 2.4.3, 3.1.4, 4.1.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-57bbc7c08a7c9ebc", "name": "CVE-2026-18446: fast-uri 3.1.0 \u2014 .migration-backup/package-lock.json", "shortDescription": {"text": "CVE-2026-18446: fast-uri 3.1.0 \u2014 .migration-backup/package-lock.json"}, "fullDescription": {"text": "fast-uri: fast-uri: Host confusion vulnerability via backslash in URI authority\n\nfast-uri before 4.1.2, 3.1.5, and 2.4.4 requires a literal double forward slash to recognize a URI authority, so a reference that uses a backslash based introducer in place of it (backslash backslash, forward slash backslash, or backslash forward slash) is parsed with no authority and folds into the path. Node's native WHATWG URL parser instead treats a backslash as interchangeable with a forward slash for special schemes, so the two parsers extract different hosts from the same input. Applicati\n\nPackage: fast-uri\nInstalled: 3.1.0\nFixed in: 2.4.4, 3.1.5, 4.1.2\nSeverity: HIGH\nFix: Upgrade fast-uri to 2.4.4, 3.1.5, 4.1.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-c1b42fe08d5bbb53", "name": "CVE-2026-6321: fast-uri 3.1.0 \u2014 .migration-backup/package-lock.json", "shortDescription": {"text": "CVE-2026-6321: fast-uri 3.1.0 \u2014 .migration-backup/package-lock.json"}, "fullDescription": {"text": "fast-uri: fast-uri: Path traversal vulnerability allows bypass of security policies\n\nfast-uri decoded percent-encoded path separators and dot segments before applying dot-segment removal in its normalize() and equal() functions. Encoded path data was treated like real slashes and parent-directory references, so distinct URIs could collapse onto the same normalized path. Applications that normalize or compare attacker-controlled URLs to enforce path-based policy can be bypassed, with a path that appears confined under an allowed prefix normalizing to a different location. Version\n\nPackage: fast-uri\nInstalled: 3.1.0\nFixed in: 3.1.1, 2.4.1\nSeverity: HIGH\nFix: Upgrade fast-uri to 3.1.1, 2.4.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-d02be77c25b740b5", "name": "CVE-2026-6322: fast-uri 3.1.0 \u2014 .migration-backup/package-lock.json", "shortDescription": {"text": "CVE-2026-6322: fast-uri 3.1.0 \u2014 .migration-backup/package-lock.json"}, "fullDescription": {"text": "fast-uri: fast-uri: URI authority bypass due to improper delimiter handling\n\nfast-uri normalize() decoded percent-encoded authority delimiters inside the host component and then re-emitted them as raw delimiters during serialization. A host that combined an allowed domain, an encoded at-sign, and a different domain was re-emitted with the at-sign as a raw userinfo separator, changing the URI's authority to the second domain. Applications that normalize untrusted URLs before host allowlist checks, redirect validation, or outbound request routing can be steered to a differ\n\nPackage: fast-uri\nInstalled: 3.1.0\nFixed in: 3.1.2, 2.4.1\nSeverity: HIGH\nFix: Upgrade fast-uri to 3.1.2, 2.4.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-f568e41d12dac34c", "name": "CVE-2026-26278: fast-xml-parser 5.3.5 \u2014 .migration-backup/package-lock.json", "shortDescription": {"text": "CVE-2026-26278: fast-xml-parser 5.3.5 \u2014 .migration-backup/package-lock.json"}, "fullDescription": {"text": "fast-xml-parser: fast-xml-parser: Denial of Service via unlimited XML entity expansion\n\nfast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS object without C/C++ based libraries and no callback. In versions 4.1.3 through 5.3.5, the XML parser can be forced to do an unlimited amount of entity expansion. With a very small XML input, it\u2019s possible to make the parser spend seconds or even minutes processing a single request, effectively freezing the application. Version 5.3.6 fixes the issue. As a workaround, avoid using DOCTYPE parsing by `process\n\nPackage: fast-xml-parser\nInstalled: 5.3.5\nFixed in: 4.5.4, 5.3.6\nSeverity: HIGH\nFix: Upgrade fast-xml-parser to 4.5.4, 5.3.6"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-5b278a5cd0e59dea", "name": "CVE-2026-33036: fast-xml-parser 5.3.5 \u2014 .migration-backup/package-lock.json", "shortDescription": {"text": "CVE-2026-33036: fast-xml-parser 5.3.5 \u2014 .migration-backup/package-lock.json"}, "fullDescription": {"text": "fast-xml-parser: fast-xml-parser: Denial of Service via XML entity expansion bypass\n\nfast-xml-parser allows users to process XML from JS object without C/C++ based libraries or callbacks. Versions 4.0.0-beta.3 through 5.5.5 contain a bypass vulnerability where numeric character references (&#NNN;, &#xHH;) and standard XML entities completely evade the entity expansion limits (e.g., maxTotalExpansions, maxExpandedLength) added to fix CVE-2026-26278, enabling XML entity expansion Denial of Service. The root cause is that replaceEntitiesValue() in OrderedObjParser.js only enforces \n\nPackage: fast-xml-parser\nInstalled: 5.3.5\nFixed in: 5.5.6, 4.5.5\nSeverity: HIGH\nFix: Upgrade fast-xml-parser to 5.5.6, 4.5.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-35eb9baad8ccd72b", "name": "CVE-2026-33349: fast-xml-parser 5.3.5 \u2014 .migration-backup/package-lock.json", "shortDescription": {"text": "CVE-2026-33349: fast-xml-parser 5.3.5 \u2014 .migration-backup/package-lock.json"}, "fullDescription": {"text": "fast-xml-parser: fast-xml-parser: Denial of Service via unbounded entity expansion due to incorrect configuration limit handling\n\nfast-xml-parser allows users to process XML from JS object without C/C++ based libraries or callbacks. From version 4.0.0-beta.3 to before version 5.5.7, the DocTypeReader in fast-xml-parser uses JavaScript truthy checks to evaluate maxEntityCount and maxEntitySize configuration limits. When a developer explicitly sets either limit to 0 \u2014 intending to disallow all entities or restrict entity size to zero bytes \u2014 the falsy nature of 0 in JavaScript causes the guard conditions to short-circuit, co\n\nPackage: fast-xml-parser\nInstalled: 5.3.5\nFixed in: 4.5.5, 5.5.7\nSeverity: MEDIUM\nFix: Upgrade fast-xml-parser to 4.5.5, 5.5.7"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-693422d7e76a261b", "name": "CVE-2026-41650: fast-xml-parser 5.3.5 \u2014 .migration-backup/package-lock.json", "shortDescription": {"text": "CVE-2026-41650: fast-xml-parser 5.3.5 \u2014 .migration-backup/package-lock.json"}, "fullDescription": {"text": "fast-xml-parser: fast-xml-parser: XML injection via improper escaping of comment and CDATA sequences\n\nfast-xml-parser allows users to process XML from JS object without C/C++ based libraries or callbacks. Prior to version 5.7.0, XMLBuilder does not escape the \"-->\" sequence in comment content or the \"]]>\" sequence in CDATA sections when building XML from JavaScript objects. This allows XML injection when user-controlled data flows into comments or CDATA elements, leading to XSS, SOAP injection, or data manipulation. This issue has been patched in version 5.7.0.\n\nPackage: fast-xml-parser\nInstalled: 5.3.5\nFixed in: 5.7.0\nSeverity: MEDIUM\nFix: Upgrade fast-xml-parser to 5.7.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-f7ad91af0f09b344", "name": "CVE-2026-27942: fast-xml-parser 5.3.5 \u2014 .migration-backup/package-lock.json", "shortDescription": {"text": "CVE-2026-27942: fast-xml-parser 5.3.5 \u2014 .migration-backup/package-lock.json"}, "fullDescription": {"text": "fast-xml-parser: fast-xml-parser: Stack overflow leads to Denial of Service\n\nfast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS object without C/C++ based libraries and no callback. Prior to version 5.3.8, the application crashes with stack overflow when user use XML builder with `preserveOrder:true`. Version 5.3.8 fixes the issue. As a workaround, use XML builder with `preserveOrder:false` or check the input data before passing to builder.\n\nPackage: fast-xml-parser\nInstalled: 5.3.5\nFixed in: 5.3.8, 4.5.4\nSeverity: LOW\nFix: Upgrade fast-xml-parser to 5.3.8, 4.5.4"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-037e54325f081875", "name": "GHSA-r4q5-vmmm-2653: follow-redirects 1.15.11 \u2014 .migration-backup/package-lock.json", "shortDescription": {"text": "GHSA-r4q5-vmmm-2653: follow-redirects 1.15.11 \u2014 .migration-backup/package-lock.json"}, "fullDescription": {"text": "follow-redirects leaks Custom Authentication Headers to Cross-Domain Redirect Targets\n\n## Summary\n\nWhen an HTTP request follows a cross-domain redirect (301/302/307/308), `follow-redirects` only strips `authorization`, `proxy-authorization`, and `cookie` headers (matched by regex at index.js:469-476). Any custom authentication header (e.g., `X-API-Key`, `X-Auth-Token`, `Api-Key`, `Token`) is forwarded verbatim to the redirect target.\n\nSince `follow-redirects` is the redirect-handling dependency for **axios** (105K+ stars), this vulnerability affects the entire axios ecosystem.\n\n##\n\nPackage: follow-redirects\nInstalled: 1.15.11\nFixed in: 1.16.0\nSeverity: MEDIUM\nFix: Upgrade follow-redirects to 1.16.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-e7c6a241869a7c30", "name": "CVE-2026-12143: form-data 2.5.5 \u2014 .migration-backup/package-lock.json", "shortDescription": {"text": "CVE-2026-12143: form-data 2.5.5 \u2014 .migration-backup/package-lock.json"}, "fullDescription": {"text": "form-data: form-data: Form field override via CRLF injection\n\nform-data is a library for creating readable multipart/form-data streams. In versions through 4.0.5, the `field` argument to `FormData#append` and the `filename` option are concatenated verbatim into the `Content-Disposition` header without escaping carriage return (CR), line feed (LF), or double-quote (\") characters. An application that passes attacker-controlled data as a field name or filename (for example, an API gateway that turns JSON object keys into multipart field names) allows the atta\n\nPackage: form-data\nInstalled: 2.5.5\nFixed in: 2.5.6, 3.0.5, 4.0.6\nSeverity: HIGH\nFix: Upgrade form-data to 2.5.6, 3.0.5, 4.0.6"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-0cf91d1eb6007d04", "name": "CVE-2026-12143: form-data 4.0.5 \u2014 .migration-backup/package-lock.json", "shortDescription": {"text": "CVE-2026-12143: form-data 4.0.5 \u2014 .migration-backup/package-lock.json"}, "fullDescription": {"text": "form-data: form-data: Form field override via CRLF injection\n\nform-data is a library for creating readable multipart/form-data streams. In versions through 4.0.5, the `field` argument to `FormData#append` and the `filename` option are concatenated verbatim into the `Content-Disposition` header without escaping carriage return (CR), line feed (LF), or double-quote (\") characters. An application that passes attacker-controlled data as a field name or filename (for example, an API gateway that turns JSON object keys into multipart field names) allows the atta\n\nPackage: form-data\nInstalled: 4.0.5\nFixed in: 2.5.6, 3.0.5, 4.0.6\nSeverity: HIGH\nFix: Upgrade form-data to 2.5.6, 3.0.5, 4.0.6"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-5e66669a33bed215", "name": "CVE-2026-4800: lodash 4.17.23 \u2014 .migration-backup/package-lock.json", "shortDescription": {"text": "CVE-2026-4800: lodash 4.17.23 \u2014 .migration-backup/package-lock.json"}, "fullDescription": {"text": "lodash: lodash: Arbitrary code execution via untrusted input in template imports\n\nImpact:\n\nThe fix for CVE-2021-23337 (https://github.com/advisories/GHSA-35jh-r3h4-6jhm) added validation for the variable option in _.template but did not apply the same validation to options.imports key names. Both paths flow into the same Function() constructor sink.\n\nWhen an application passes untrusted input as options.imports key names, an attacker can inject default-parameter expressions that execute arbitrary code at template compilation time.\n\nAdditionally, _.template uses assignInWith t\n\nPackage: lodash\nInstalled: 4.17.23\nFixed in: 4.18.0\nSeverity: HIGH\nFix: Upgrade lodash to 4.18.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-30ec4a6de706b35a", "name": "CVE-2026-2950: lodash 4.17.23 \u2014 .migration-backup/package-lock.json", "shortDescription": {"text": "CVE-2026-2950: lodash 4.17.23 \u2014 .migration-backup/package-lock.json"}, "fullDescription": {"text": "lodash: Lodash: Prototype pollution allows deletion of built-in prototype properties via array path bypass\n\nImpact:\n\nLodash versions 4.17.23 and earlier are vulnerable to prototype pollution in the _.unset and _.omit functions. The fix for (CVE-2025-13465: https://github.com/lodash/lodash/security/advisories/GHSA-xxjr-mmjv-4gpg) only guards against string key members, so an attacker can bypass the check by passing array-wrapped path segments. This allows deletion of properties from built-in prototypes such as Object.prototype, Number.prototype, and String.prototype.\n\nThe issue permits deletion of prot\n\nPackage: lodash\nInstalled: 4.17.23\nFixed in: 4.18.0\nSeverity: MEDIUM\nFix: Upgrade lodash to 4.18.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b139460868786224", "name": "CVE-2026-26996: minimatch 10.1.1 \u2014 .migration-backup/package-lock.json", "shortDescription": {"text": "CVE-2026-26996: minimatch 10.1.1 \u2014 .migration-backup/package-lock.json"}, "fullDescription": {"text": "minimatch: minimatch: Denial of Service via specially crafted glob patterns\n\nminimatch is a minimal matching utility for converting glob expressions into JavaScript RegExp objects. Versions 10.2.0 and below are vulnerable to Regular Expression Denial of Service (ReDoS) when a glob pattern contains many consecutive * wildcards followed by a literal character that doesn't appear in the test string. Each * compiles to a separate [^/]*? regex group, and when the match fails, V8's regex engine backtracks exponentially across all possible splits. The time complexity is O(4^N) \n\nPackage: minimatch\nInstalled: 10.1.1\nFixed in: 10.2.1, 9.0.6, 8.0.5, 7.4.7, 6.2.1, 5.1.7, 4.2.4, 3.1.3\nSeverity: HIGH\nFix: Upgrade minimatch to 10.2.1, 9.0.6, 8.0.5, 7.4.7, 6.2.1, 5.1.7, 4.2.4, 3.1.3"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-2e065c23622703e5", "name": "CVE-2026-27903: minimatch 10.1.1 \u2014 .migration-backup/package-lock.json", "shortDescription": {"text": "CVE-2026-27903: minimatch 10.1.1 \u2014 .migration-backup/package-lock.json"}, "fullDescription": {"text": "minimatch: minimatch: Denial of Service due to unbounded recursive backtracking via crafted glob patterns\n\nminimatch is a minimal matching utility for converting glob expressions into JavaScript RegExp objects. Prior to version 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, and 3.1.3, `matchOne()` performs unbounded recursive backtracking when a glob pattern contains multiple non-adjacent `**` (GLOBSTAR) segments and the input path does not match. The time complexity is O(C(n, k)) -- binomial -- where `n` is the number of path segments and `k` is the number of globstars. With k=11 and n=30, a call\n\nPackage: minimatch\nInstalled: 10.1.1\nFixed in: 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, 3.1.3\nSeverity: HIGH\nFix: Upgrade minimatch to 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, 3.1.3"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-0e78b535468db104", "name": "CVE-2026-27904: minimatch 10.1.1 \u2014 .migration-backup/package-lock.json", "shortDescription": {"text": "CVE-2026-27904: minimatch 10.1.1 \u2014 .migration-backup/package-lock.json"}, "fullDescription": {"text": "minimatch: Minimatch: Denial of Service via catastrophic backtracking in glob expressions\n\nminimatch is a minimal matching utility for converting glob expressions into JavaScript RegExp objects. Prior to version 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, and 3.1.4, nested `*()` extglobs produce regexps with nested unbounded quantifiers (e.g. `(?:(?:a|b)*)*`), which exhibit catastrophic backtracking in V8. With a 12-byte pattern `*(*(*(a|b)))` and an 18-byte non-matching input, `minimatch()` stalls for over 7 seconds. Adding a single nesting level or a few input characters pushe\n\nPackage: minimatch\nInstalled: 10.1.1\nFixed in: 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, 3.1.4\nSeverity: HIGH\nFix: Upgrade minimatch to 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, 3.1.4"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-c8ab983c94610f21", "name": "CVE-2026-26996: minimatch 5.1.6 \u2014 .migration-backup/package-lock.json", "shortDescription": {"text": "CVE-2026-26996: minimatch 5.1.6 \u2014 .migration-backup/package-lock.json"}, "fullDescription": {"text": "minimatch: minimatch: Denial of Service via specially crafted glob patterns\n\nminimatch is a minimal matching utility for converting glob expressions into JavaScript RegExp objects. Versions 10.2.0 and below are vulnerable to Regular Expression Denial of Service (ReDoS) when a glob pattern contains many consecutive * wildcards followed by a literal character that doesn't appear in the test string. Each * compiles to a separate [^/]*? regex group, and when the match fails, V8's regex engine backtracks exponentially across all possible splits. The time complexity is O(4^N) \n\nPackage: minimatch\nInstalled: 5.1.6\nFixed in: 10.2.1, 9.0.6, 8.0.5, 7.4.7, 6.2.1, 5.1.7, 4.2.4, 3.1.3\nSeverity: HIGH\nFix: Upgrade minimatch to 10.2.1, 9.0.6, 8.0.5, 7.4.7, 6.2.1, 5.1.7, 4.2.4, 3.1.3"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-d509576ab53e8e36", "name": "CVE-2026-27903: minimatch 5.1.6 \u2014 .migration-backup/package-lock.json", "shortDescription": {"text": "CVE-2026-27903: minimatch 5.1.6 \u2014 .migration-backup/package-lock.json"}, "fullDescription": {"text": "minimatch: minimatch: Denial of Service due to unbounded recursive backtracking via crafted glob patterns\n\nminimatch is a minimal matching utility for converting glob expressions into JavaScript RegExp objects. Prior to version 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, and 3.1.3, `matchOne()` performs unbounded recursive backtracking when a glob pattern contains multiple non-adjacent `**` (GLOBSTAR) segments and the input path does not match. The time complexity is O(C(n, k)) -- binomial -- where `n` is the number of path segments and `k` is the number of globstars. With k=11 and n=30, a call\n\nPackage: minimatch\nInstalled: 5.1.6\nFixed in: 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, 3.1.3\nSeverity: HIGH\nFix: Upgrade minimatch to 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, 3.1.3"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-656d4fde2313d517", "name": "CVE-2026-27904: minimatch 5.1.6 \u2014 .migration-backup/package-lock.json", "shortDescription": {"text": "CVE-2026-27904: minimatch 5.1.6 \u2014 .migration-backup/package-lock.json"}, "fullDescription": {"text": "minimatch: Minimatch: Denial of Service via catastrophic backtracking in glob expressions\n\nminimatch is a minimal matching utility for converting glob expressions into JavaScript RegExp objects. Prior to version 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, and 3.1.4, nested `*()` extglobs produce regexps with nested unbounded quantifiers (e.g. `(?:(?:a|b)*)*`), which exhibit catastrophic backtracking in V8. With a 12-byte pattern `*(*(*(a|b)))` and an 18-byte non-matching input, `minimatch()` stalls for over 7 seconds. Adding a single nesting level or a few input characters pushe\n\nPackage: minimatch\nInstalled: 5.1.6\nFixed in: 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, 3.1.4\nSeverity: HIGH\nFix: Upgrade minimatch to 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, 3.1.4"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-784bae0fb5049433", "name": "CVE-2026-26996: minimatch 9.0.5 \u2014 .migration-backup/package-lock.json", "shortDescription": {"text": "CVE-2026-26996: minimatch 9.0.5 \u2014 .migration-backup/package-lock.json"}, "fullDescription": {"text": "minimatch: minimatch: Denial of Service via specially crafted glob patterns\n\nminimatch is a minimal matching utility for converting glob expressions into JavaScript RegExp objects. Versions 10.2.0 and below are vulnerable to Regular Expression Denial of Service (ReDoS) when a glob pattern contains many consecutive * wildcards followed by a literal character that doesn't appear in the test string. Each * compiles to a separate [^/]*? regex group, and when the match fails, V8's regex engine backtracks exponentially across all possible splits. The time complexity is O(4^N) \n\nPackage: minimatch\nInstalled: 9.0.5\nFixed in: 10.2.1, 9.0.6, 8.0.5, 7.4.7, 6.2.1, 5.1.7, 4.2.4, 3.1.3\nSeverity: HIGH\nFix: Upgrade minimatch to 10.2.1, 9.0.6, 8.0.5, 7.4.7, 6.2.1, 5.1.7, 4.2.4, 3.1.3"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-b37a04641b97221e", "name": "CVE-2026-27903: minimatch 9.0.5 \u2014 .migration-backup/package-lock.json", "shortDescription": {"text": "CVE-2026-27903: minimatch 9.0.5 \u2014 .migration-backup/package-lock.json"}, "fullDescription": {"text": "minimatch: minimatch: Denial of Service due to unbounded recursive backtracking via crafted glob patterns\n\nminimatch is a minimal matching utility for converting glob expressions into JavaScript RegExp objects. Prior to version 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, and 3.1.3, `matchOne()` performs unbounded recursive backtracking when a glob pattern contains multiple non-adjacent `**` (GLOBSTAR) segments and the input path does not match. The time complexity is O(C(n, k)) -- binomial -- where `n` is the number of path segments and `k` is the number of globstars. With k=11 and n=30, a call\n\nPackage: minimatch\nInstalled: 9.0.5\nFixed in: 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, 3.1.3\nSeverity: HIGH\nFix: Upgrade minimatch to 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, 3.1.3"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-fd8d89a27e151543", "name": "CVE-2026-27904: minimatch 9.0.5 \u2014 .migration-backup/package-lock.json", "shortDescription": {"text": "CVE-2026-27904: minimatch 9.0.5 \u2014 .migration-backup/package-lock.json"}, "fullDescription": {"text": "minimatch: Minimatch: Denial of Service via catastrophic backtracking in glob expressions\n\nminimatch is a minimal matching utility for converting glob expressions into JavaScript RegExp objects. Prior to version 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, and 3.1.4, nested `*()` extglobs produce regexps with nested unbounded quantifiers (e.g. `(?:(?:a|b)*)*`), which exhibit catastrophic backtracking in V8. With a 12-byte pattern `*(*(*(a|b)))` and an 18-byte non-matching input, `minimatch()` stalls for over 7 seconds. Adding a single nesting level or a few input characters pushe\n\nPackage: minimatch\nInstalled: 9.0.5\nFixed in: 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, 3.1.4\nSeverity: HIGH\nFix: Upgrade minimatch to 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, 3.1.4"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-099b9273041be41f", "name": "CVE-2026-5079: multer 2.1.1 \u2014 .migration-backup/package-lock.json", "shortDescription": {"text": "CVE-2026-5079: multer 2.1.1 \u2014 .migration-backup/package-lock.json"}, "fullDescription": {"text": "multer: Multer: Denial of Service via deeply nested field names in multipart form data\n\nImpact: multer versions 1.0.0 through 2.1.1 and 3.0.0-alpha.1 are vulnerable to a Denial of Service via deeply nested field names in multipart form data. The append-field dependency parses bracket notation in field names with no limit on nesting depth, allowing an attacker to force allocation of deeply nested object structures that consume CPU and memory. A single HTTP request with a crafted multipart body is sufficient to exploit this.\n\nPatches: Users should upgrade to multer 2.2.0 (2.x line) o\n\nPackage: multer\nInstalled: 2.1.1\nFixed in: 2.2.0, 3.0.0-alpha.2\nSeverity: HIGH\nFix: Upgrade multer to 2.2.0, 3.0.0-alpha.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-c5b0f76a1d8af59a", "name": "CVE-2026-5038: multer 2.1.1 \u2014 .migration-backup/package-lock.json", "shortDescription": {"text": "CVE-2026-5038: multer 2.1.1 \u2014 .migration-backup/package-lock.json"}, "fullDescription": {"text": "multer: Multer: Denial of Service via aborted or malformed multipart uploads\n\nImpact: multer versions 2.0.0-alpha.1 through 2.1.1 and 3.0.0-alpha.1 are vulnerable to a Denial of Service when using diskStorage. Aborted or malformed multipart uploads leave orphaned partial files on disk because the Readable.pipe() call does not propagate the stream destroy signal to \nthe underlying fs.WriteStream. An attacker can exhaust disk space by triggering many aborted uploads, with no application bug required.\n\nPatches: Users should upgrade to multer 2.2.0 (2.x line) or 3.0.0-alpha.2\n\nPackage: multer\nInstalled: 2.1.1\nFixed in: 2.2.0, 3.0.0-alpha.2\nSeverity: MEDIUM\nFix: Upgrade multer to 2.2.0, 3.0.0-alpha.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-14a15098389f477e", "name": "GHSA-rgwj-5xj2-c3m3: mysql2 3.16.3 \u2014 .migration-backup/package-lock.json", "shortDescription": {"text": "GHSA-rgwj-5xj2-c3m3: mysql2 3.16.3 \u2014 .migration-backup/package-lock.json"}, "fullDescription": {"text": "MySQL2: Unbounded zlib inflate in compressed MySQL protocol handler allows decompression-bomb DoS\n\n## Vulnerability Details\n\n**File**: `lib/compressed_protocol.js`\n**Line**: 43 (`zlib.inflate(body, (err, data) => { ... })` inside `handleCompressedPacket`)\n\n### Root Cause\nWhen a connection is created with `compress: true` (and the server advertises `CLIENT_COMPRESS`), every incoming packet is unwrapped by `handleCompressedPacket()` in `lib/compressed_protocol.js`, which calls:\n\n```js\nzlib.inflate(body, (err, data) => { ... });\n```\n\nNo options object (in particular, no `maxOutputLength`) is pas\n\nPackage: mysql2\nInstalled: 3.16.3\nFixed in: 3.23.1\nSeverity: MEDIUM\nFix: Upgrade mysql2 to 3.23.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-12a263cc878c854c", "name": "CVE-2026-67213: nanoid 3.3.11 \u2014 .migration-backup/package-lock.json", "shortDescription": {"text": "CVE-2026-67213: nanoid 3.3.11 \u2014 .migration-backup/package-lock.json"}, "fullDescription": {"text": "nanoid: nanoid: Denial of Service via infinite loop in random ID generation\n\nnanoid (Nano ID) before 5.1.6 contains an infinite loop in the customAlphabet and customRandom functions. When these functions are configured with a size of 0, the internal generation loop never satisfies its exit condition and spins indefinitely, hanging the calling thread. An application that passes an unvalidated, attacker-controlled size of 0 to these functions is exposed to a denial-of-service condition.\n\nPackage: nanoid\nInstalled: 3.3.11\nFixed in: 3.3.18, 5.1.6\nSeverity: HIGH\nFix: Upgrade nanoid to 3.3.18, 5.1.6"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-a687079dd22cf128", "name": "CVE-2026-67214: nanoid 3.3.11 \u2014 .migration-backup/package-lock.json", "shortDescription": {"text": "CVE-2026-67214: nanoid 3.3.11 \u2014 .migration-backup/package-lock.json"}, "fullDescription": {"text": "nanoid: nanoid: Denial of Service via negative size input in non-secure module functions\n\nnanoid (Nano ID) before 3.3.16 and 5.1.16 contains an infinite loop in the customAlphabet and nanoid functions of its non-secure module (nanoid/non-secure). When these functions are given a negative size, the loop counter is decremented from a negative value and never reaches its termination condition, spinning indefinitely and hanging the calling thread. An application that passes an unvalidated, attacker-controlled negative size to these functions is exposed to a denial-of-service condition.\n\nPackage: nanoid\nInstalled: 3.3.11\nFixed in: 3.3.16, 5.1.16\nSeverity: HIGH\nFix: Upgrade nanoid to 3.3.16, 5.1.16"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-13e2f2635a20c5d4", "name": "CVE-2026-67214: nanoid 5.1.6 \u2014 .migration-backup/package-lock.json", "shortDescription": {"text": "CVE-2026-67214: nanoid 5.1.6 \u2014 .migration-backup/package-lock.json"}, "fullDescription": {"text": "nanoid: nanoid: Denial of Service via negative size input in non-secure module functions\n\nnanoid (Nano ID) before 3.3.16 and 5.1.16 contains an infinite loop in the customAlphabet and nanoid functions of its non-secure module (nanoid/non-secure). When these functions are given a negative size, the loop counter is decremented from a negative value and never reaches its termination condition, spinning indefinitely and hanging the calling thread. An application that passes an unvalidated, attacker-controlled negative size to these functions is exposed to a denial-of-service condition.\n\nPackage: nanoid\nInstalled: 5.1.6\nFixed in: 3.3.16, 5.1.16\nSeverity: HIGH\nFix: Upgrade nanoid to 3.3.16, 5.1.16"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-c26e7ef39b91c66b", "name": "CVE-2026-4867: path-to-regexp 0.1.12 \u2014 .migration-backup/package-lock.json", "shortDescription": {"text": "CVE-2026-4867: path-to-regexp 0.1.12 \u2014 .migration-backup/package-lock.json"}, "fullDescription": {"text": "path-to-regexp: path-to-regexp: Denial of Service via catastrophic backtracking from malformed URL parameters\n\nImpact:\n\nA bad regular expression is generated any time you have three or more parameters within a single segment, separated by something that is not a period (.). For example, /:a-:b-:c or /:a-:b-:c-:d. The backtrack protection added in path-to-regexp@0.1.12 only prevents ambiguity for two parameters. With three or more, the generated lookahead does not block single separator characters, so capture groups overlap and cause catastrophic backtracking.\n\nPatches:\n\nUpgrade to path-to-regexp@0.1.13\n\n\n\nPackage: path-to-regexp\nInstalled: 0.1.12\nFixed in: 0.1.13\nSeverity: HIGH\nFix: Upgrade path-to-regexp to 0.1.13"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-76ebe13d5084bb02", "name": "CVE-2026-33671: picomatch 2.3.1 \u2014 .migration-backup/package-lock.json", "shortDescription": {"text": "CVE-2026-33671: picomatch 2.3.1 \u2014 .migration-backup/package-lock.json"}, "fullDescription": {"text": "picomatch: Picomatch: Regular Expression Denial of Service via crafted extglob patterns\n\nPicomatch is a glob matcher written JavaScript. Versions prior to 4.0.4, 3.0.2, and 2.3.2 are vulnerable to Regular Expression Denial of Service (ReDoS) when processing crafted extglob patterns. Certain patterns using extglob quantifiers such as `+()` and `*()`, especially when combined with overlapping alternatives or nested extglobs, are compiled into regular expressions that can exhibit catastrophic backtracking on non-matching input. Applications are impacted when they allow untrusted users \n\nPackage: picomatch\nInstalled: 2.3.1\nFixed in: 4.0.4, 3.0.2, 2.3.2\nSeverity: HIGH\nFix: Upgrade picomatch to 4.0.4, 3.0.2, 2.3.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-707f4fad866c380c", "name": "CVE-2026-33672: picomatch 2.3.1 \u2014 .migration-backup/package-lock.json", "shortDescription": {"text": "CVE-2026-33672: picomatch 2.3.1 \u2014 .migration-backup/package-lock.json"}, "fullDescription": {"text": "picomatch: Picomatch: Data integrity compromised via method injection with crafted POSIX bracket expressions\n\nPicomatch is a glob matcher written JavaScript. Versions prior to 4.0.4, 3.0.2, and 2.3.2 are vulnerable to a method injection vulnerability affecting the `POSIX_REGEX_SOURCE` object. Because the object inherits from `Object.prototype`, specially crafted POSIX bracket expressions (e.g., `[[:constructor:]]`) can reference inherited method names. These methods are implicitly converted to strings and injected into the generated regular expression. This leads to incorrect glob matching behavior (int\n\nPackage: picomatch\nInstalled: 2.3.1\nFixed in: 4.0.4, 3.0.2, 2.3.2\nSeverity: MEDIUM\nFix: Upgrade picomatch to 4.0.4, 3.0.2, 2.3.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-a92dbc5b7414c266", "name": "CVE-2026-33671: picomatch 4.0.3 \u2014 .migration-backup/package-lock.json", "shortDescription": {"text": "CVE-2026-33671: picomatch 4.0.3 \u2014 .migration-backup/package-lock.json"}, "fullDescription": {"text": "picomatch: Picomatch: Regular Expression Denial of Service via crafted extglob patterns\n\nPicomatch is a glob matcher written JavaScript. Versions prior to 4.0.4, 3.0.2, and 2.3.2 are vulnerable to Regular Expression Denial of Service (ReDoS) when processing crafted extglob patterns. Certain patterns using extglob quantifiers such as `+()` and `*()`, especially when combined with overlapping alternatives or nested extglobs, are compiled into regular expressions that can exhibit catastrophic backtracking on non-matching input. Applications are impacted when they allow untrusted users \n\nPackage: picomatch\nInstalled: 4.0.3\nFixed in: 4.0.4, 3.0.2, 2.3.2\nSeverity: HIGH\nFix: Upgrade picomatch to 4.0.4, 3.0.2, 2.3.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-9f8ff117c3e2e89f", "name": "CVE-2026-33672: picomatch 4.0.3 \u2014 .migration-backup/package-lock.json", "shortDescription": {"text": "CVE-2026-33672: picomatch 4.0.3 \u2014 .migration-backup/package-lock.json"}, "fullDescription": {"text": "picomatch: Picomatch: Data integrity compromised via method injection with crafted POSIX bracket expressions\n\nPicomatch is a glob matcher written JavaScript. Versions prior to 4.0.4, 3.0.2, and 2.3.2 are vulnerable to a method injection vulnerability affecting the `POSIX_REGEX_SOURCE` object. Because the object inherits from `Object.prototype`, specially crafted POSIX bracket expressions (e.g., `[[:constructor:]]`) can reference inherited method names. These methods are implicitly converted to strings and injected into the generated regular expression. This leads to incorrect glob matching behavior (int\n\nPackage: picomatch\nInstalled: 4.0.3\nFixed in: 4.0.4, 3.0.2, 2.3.2\nSeverity: MEDIUM\nFix: Upgrade picomatch to 4.0.4, 3.0.2, 2.3.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-a349fa5e2aa4d8eb", "name": "CVE-2026-45623: postcss 8.5.6 \u2014 .migration-backup/package-lock.json", "shortDescription": {"text": "CVE-2026-45623: postcss 8.5.6 \u2014 .migration-backup/package-lock.json"}, "fullDescription": {"text": "postcss: PostCSS: Information disclosure and denial of service via crafted CSS input\n\nPostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract Syntax Tree. In versions 8.5.11 and prior, the PreviousMap parses the /*# sourceMappingURL=PATH */ comment from any CSS string passed to process() and dereferences PATH against the local filesystem with no scheme, allowlist, or traversal check. An attacker who controls the CSS input can cause the host process to read any file readable by Node and leak the first ~10 bytes of its\n\nPackage: postcss\nInstalled: 8.5.6\nFixed in: 8.5.12\nSeverity: HIGH\nFix: Upgrade postcss to 8.5.12"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-45b65349a078e228", "name": "CVE-2026-73646: postcss 8.5.6 \u2014 .migration-backup/package-lock.json", "shortDescription": {"text": "CVE-2026-73646: postcss 8.5.6 \u2014 .migration-backup/package-lock.json"}, "fullDescription": {"text": "postcss: PostCSS: Information disclosure via path traversal in source map auto-loading\n\nPostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract Syntax Tree. Prior to 8.5.18, lib/previous-map.js loadMap() passes attacker-controlled sourceMappingURL values to join(dirname(opts.from), annotation), and loadFile() permits traversed or absolute .map paths, allowing untrusted CSS processed without map: false to disclose sourcesContent from arbitrary reachable .map files through result.map. This issue is fixed in version 8.5.1\n\nPackage: postcss\nInstalled: 8.5.6\nFixed in: 8.5.18\nSeverity: HIGH\nFix: Upgrade postcss to 8.5.18"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-28be461fec2be7c4", "name": "CVE-2026-41305: postcss 8.5.6 \u2014 .migration-backup/package-lock.json", "shortDescription": {"text": "CVE-2026-41305: postcss 8.5.6 \u2014 .migration-backup/package-lock.json"}, "fullDescription": {"text": "postcss: PostCSS: Cross-Site Scripting (XSS) via improper escaping of style closing tags\n\nPostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract Syntax Tree. Versions prior to 8.5.10 do not escape `</style>` sequences when stringifying CSS ASTs. When user-submitted CSS is parsed and re-stringified for embedding in HTML `<style>` tags, `</style>` in CSS values breaks out of the style context, enabling XSS. Version 8.5.10 fixes the issue.\n\nPackage: postcss\nInstalled: 8.5.6\nFixed in: 8.5.10\nSeverity: MEDIUM\nFix: Upgrade postcss to 8.5.10"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-add7f95db12e56fb", "name": "CVE-2026-69153: postcss 8.5.6 \u2014 .migration-backup/package-lock.json", "shortDescription": {"text": "CVE-2026-69153: postcss 8.5.6 \u2014 .migration-backup/package-lock.json"}, "fullDescription": {"text": "postcss: PostCSS: Information disclosure via crafted sourceMappingURL\n\nPostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract Syntax Tree. Prior to 8.5.19, if from is unset, an attacker can cause PreviousMap.loadFile() to read an unintended source-map file by supplying an absolute or directory-traversal sourceMappingURL. The resulting map\u2019s sources and sourcesContent may then be exposed to the application. This issue is fixed in version 8.5.19.\n\nPackage: postcss\nInstalled: 8.5.6\nFixed in: 8.5.23\nSeverity: MEDIUM\nFix: Upgrade postcss to 8.5.23"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-3eb656a98ce54baa", "name": "CVE-2026-41242: protobufjs 6.8.8 \u2014 .migration-backup/package-lock.json", "shortDescription": {"text": "CVE-2026-41242: protobufjs 6.8.8 \u2014 .migration-backup/package-lock.json"}, "fullDescription": {"text": "protobufjs: protobufjs: Arbitrary code execution via injected protobuf definition type fields\n\nprotobufjs compiles protobuf definitions into JavaScript (JS) functions. In versions prior to 8.0.1 and 7.5.5, attackers can inject arbitrary code in the \"type\" fields of protobuf definitions, which will then execute during object decoding using that definition. Versions 8.0.1 and 7.5.5 patch the issue.\n\nPackage: protobufjs\nInstalled: 6.8.8\nFixed in: 8.0.1, 7.5.5\nSeverity: CRITICAL\nFix: Upgrade protobufjs to 8.0.1, 7.5.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "critical", "confidence": 1.0}}, {"id": "scanner-eeaf71d7635bd9fa", "name": "CVE-2026-44289: protobufjs 6.8.8 \u2014 .migration-backup/package-lock.json", "shortDescription": {"text": "CVE-2026-44289: protobufjs 6.8.8 \u2014 .migration-backup/package-lock.json"}, "fullDescription": {"text": "protobufjs: protobufjs: Denial of Service via uncontrolled recursion in protobuf decoding\n\nprotobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.6 and 8.0.2, protobufjs could recurse without a depth limit while decoding nested protobuf data. This affected both skipping unknown group fields and generated decoding of nested message fields. A crafted protobuf binary payload could cause the JavaScript call stack to be exhausted during decoding. This vulnerability is fixed in 7.5.6 and 8.0.2.\n\nPackage: protobufjs\nInstalled: 6.8.8\nFixed in: 7.5.6, 8.0.2\nSeverity: HIGH\nFix: Upgrade protobufjs to 7.5.6, 8.0.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-af5cd88dbc92fd55", "name": "CVE-2026-44290: protobufjs 6.8.8 \u2014 .migration-backup/package-lock.json", "shortDescription": {"text": "CVE-2026-44290: protobufjs 6.8.8 \u2014 .migration-backup/package-lock.json"}, "fullDescription": {"text": "protobufjs: protobufjs: Denial of Service via crafted schema\n\nprotobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.6 and 8.0.2, protobufjs allowed certain schema option paths to traverse through inherited object properties while applying options. A crafted protobuf schema or JSON descriptor could cause option handling to write to properties on global JavaScript constructors, corrupting process-wide built-in functionality. This vulnerability is fixed in 7.5.6 and 8.0.2.\n\nPackage: protobufjs\nInstalled: 6.8.8\nFixed in: 7.5.6, 8.0.2\nSeverity: HIGH\nFix: Upgrade protobufjs to 7.5.6, 8.0.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-b9066ab308b9bcf6", "name": "CVE-2026-44291: protobufjs 6.8.8 \u2014 .migration-backup/package-lock.json", "shortDescription": {"text": "CVE-2026-44291: protobufjs 6.8.8 \u2014 .migration-backup/package-lock.json"}, "fullDescription": {"text": "protobufjs: protobufjs: Arbitrary Code Execution via prototype pollution\n\nprotobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.6 and 8.0.2, protobufjs used plain objects with inherited prototypes for internal type lookup tables used by generated encode and decode functions. If Object.prototype had already been polluted, those lookup tables could resolve attacker-controlled inherited properties as valid protobuf type information. This could cause attacker-controlled strings to be emitted into generated JavaScript code. This vulnerabilit\n\nPackage: protobufjs\nInstalled: 6.8.8\nFixed in: 7.5.6, 8.0.2\nSeverity: HIGH\nFix: Upgrade protobufjs to 7.5.6, 8.0.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-f04ee596bb375991", "name": "CVE-2026-44293: protobufjs 6.8.8 \u2014 .migration-backup/package-lock.json", "shortDescription": {"text": "CVE-2026-44293: protobufjs 6.8.8 \u2014 .migration-backup/package-lock.json"}, "fullDescription": {"text": "protobufjs: protobufjs: Arbitrary code execution due to unsafe expression generation from crafted protobuf descriptors\n\nprotobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.6 and 8.0.2, protobufjs generated JavaScript for toObject conversion could include an unsafe expression derived from a schema-controlled bytes field default value. A crafted descriptor with a non-string default value for a bytes field could cause attacker-controlled code to be emitted into the generated conversion function. This vulnerability is fixed in 7.5.6 and 8.0.2.\n\nPackage: protobufjs\nInstalled: 6.8.8\nFixed in: 7.5.6, 8.0.2\nSeverity: HIGH\nFix: Upgrade protobufjs to 7.5.6, 8.0.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-c9a946f2ad1ecfbf", "name": "CVE-2026-48712: protobufjs 6.8.8 \u2014 .migration-backup/package-lock.json", "shortDescription": {"text": "CVE-2026-48712: protobufjs 6.8.8 \u2014 .migration-backup/package-lock.json"}, "fullDescription": {"text": "protobufjs: protobufjs: Denial of Service via uncontrolled recursion with crafted protobuf payload\n\nprotobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.6.1 and 8.4.1, protobufjs could recurse without a depth limit while converting decoded messages to plain objects or JSON. This affected generated toObject() conversion and the custom google.protobuf.Any JSON conversion path. A crafted protobuf binary payload containing deeply nested Any values could cause the JavaScript call stack to be exhausted during conversion to JSON. This vulnerability is fixed in 7.6.1 and\n\nPackage: protobufjs\nInstalled: 6.8.8\nFixed in: 7.6.1, 8.4.1\nSeverity: HIGH\nFix: Upgrade protobufjs to 7.6.1, 8.4.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-a93f0568074bf08a", "name": "CVE-2026-44288: protobufjs 6.8.8 \u2014 .migration-backup/package-lock.json", "shortDescription": {"text": "CVE-2026-44288: protobufjs 6.8.8 \u2014 .migration-backup/package-lock.json"}, "fullDescription": {"text": "protobufjs: protobufjs: Security control bypass due to improper handling of overlong UTF-8 sequences\n\nprotobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.6 and 8.0.2, protobufjs includes a minimal UTF-8 decoder that accepted overlong UTF-8 byte sequences and decoded them to their canonical characters instead of replacing them. An attacker who can provide protobuf binary data decoded through the affected UTF-8 path may be able to bypass application-level checks that inspect raw bytes before protobuf string decoding. For example, bytes that do not contain certain \n\nPackage: protobufjs\nInstalled: 6.8.8\nFixed in: 7.5.6, 8.0.2\nSeverity: MEDIUM\nFix: Upgrade protobufjs to 7.5.6, 8.0.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-6f13dce92bda8ae5", "name": "CVE-2026-44292: protobufjs 6.8.8 \u2014 .migration-backup/package-lock.json", "shortDescription": {"text": "CVE-2026-44292: protobufjs 6.8.8 \u2014 .migration-backup/package-lock.json"}, "fullDescription": {"text": "protobufjs: protobufjs: Data integrity impact due to prototype pollution\n\nprotobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.6 and 8.0.2, protobufjs generated message constructors copied enumerable properties from a provided properties object without filtering the __proto__ key. If an application constructed a message from an attacker-controlled plain object, an own enumerable __proto__ property could alter the prototype of that individual message instance. This vulnerability is fixed in 7.5.6 and 8.0.2.\n\nPackage: protobufjs\nInstalled: 6.8.8\nFixed in: 7.5.6, 8.0.2\nSeverity: MEDIUM\nFix: Upgrade protobufjs to 7.5.6, 8.0.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b0a0483ac9aaafcc", "name": "CVE-2026-44294: protobufjs 6.8.8 \u2014 .migration-backup/package-lock.json", "shortDescription": {"text": "CVE-2026-44294: protobufjs 6.8.8 \u2014 .migration-backup/package-lock.json"}, "fullDescription": {"text": "protobufjs: protobufjs: Denial of Service due to unescaped control characters in field names\n\nprotobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.6 and 8.0.2, protobufjs generated JavaScript property accessors from schema-controlled field and oneof names. Certain control characters in field names were not escaped before being embedded into generated function bodies. A crafted schema or JSON descriptor could therefore cause generated encode, decode, verify, or conversion functions to fail during compilation. This vulnerability is fixed in 7.5.6 and 8.0.2.\n\nPackage: protobufjs\nInstalled: 6.8.8\nFixed in: 7.5.6, 8.0.2\nSeverity: MEDIUM\nFix: Upgrade protobufjs to 7.5.6, 8.0.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-46c37d099b6e72e7", "name": "CVE-2026-45740: protobufjs 6.8.8 \u2014 .migration-backup/package-lock.json", "shortDescription": {"text": "CVE-2026-45740: protobufjs 6.8.8 \u2014 .migration-backup/package-lock.json"}, "fullDescription": {"text": "protobufjs: protobufjs: Denial of Service via crafted JSON descriptors\n\nprotobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.8 and 8.2.0, protobufjs could recurse without a depth limit while expanding nested JSON descriptors through Root.fromJSON() and Namespace.addJSON(). A crafted JSON descriptor with deeply nested namespace definitions could cause the JavaScript call stack to be exhausted during descriptor loading. This vulnerability is fixed in 7.5.8 and 8.2.0.\n\nPackage: protobufjs\nInstalled: 6.8.8\nFixed in: 7.5.8, 8.2.0\nSeverity: MEDIUM\nFix: Upgrade protobufjs to 7.5.8, 8.2.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-72b80a42b8c67fd7", "name": "CVE-2026-54269: protobufjs 6.8.8 \u2014 .migration-backup/package-lock.json", "shortDescription": {"text": "CVE-2026-54269: protobufjs 6.8.8 \u2014 .migration-backup/package-lock.json"}, "fullDescription": {"text": "protobufjs: protobufjs-cli: protobufjs: Denial of Service due to name collision with runtime helpers\n\nprotobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 8.6.0 and 7.6.3, protobufjs accepted certain schema-derived names that could collide with properties used by protobufjs runtime helpers. The known affected names are fields named hasOwnProperty, field or oneof names such as $type when loaded through protobufjs JSON/reflection descriptors, and service methods whose generated helper name is rpcCall. When affected message or service types were used, protobufjs could r\n\nPackage: protobufjs\nInstalled: 6.8.8\nFixed in: 7.6.3, 8.6.0\nSeverity: MEDIUM\nFix: Upgrade protobufjs to 7.6.3, 8.6.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-a4c617e6e2be3a98", "name": "CVE-2026-48712: protobufjs 7.5.6 \u2014 .migration-backup/package-lock.json", "shortDescription": {"text": "CVE-2026-48712: protobufjs 7.5.6 \u2014 .migration-backup/package-lock.json"}, "fullDescription": {"text": "protobufjs: protobufjs: Denial of Service via uncontrolled recursion with crafted protobuf payload\n\nprotobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.6.1 and 8.4.1, protobufjs could recurse without a depth limit while converting decoded messages to plain objects or JSON. This affected generated toObject() conversion and the custom google.protobuf.Any JSON conversion path. A crafted protobuf binary payload containing deeply nested Any values could cause the JavaScript call stack to be exhausted during conversion to JSON. This vulnerability is fixed in 7.6.1 and\n\nPackage: protobufjs\nInstalled: 7.5.6\nFixed in: 7.6.1, 8.4.1\nSeverity: HIGH\nFix: Upgrade protobufjs to 7.6.1, 8.4.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-7cf47b34b31eb942", "name": "CVE-2026-45740: protobufjs 7.5.6 \u2014 .migration-backup/package-lock.json", "shortDescription": {"text": "CVE-2026-45740: protobufjs 7.5.6 \u2014 .migration-backup/package-lock.json"}, "fullDescription": {"text": "protobufjs: protobufjs: Denial of Service via crafted JSON descriptors\n\nprotobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.8 and 8.2.0, protobufjs could recurse without a depth limit while expanding nested JSON descriptors through Root.fromJSON() and Namespace.addJSON(). A crafted JSON descriptor with deeply nested namespace definitions could cause the JavaScript call stack to be exhausted during descriptor loading. This vulnerability is fixed in 7.5.8 and 8.2.0.\n\nPackage: protobufjs\nInstalled: 7.5.6\nFixed in: 7.5.8, 8.2.0\nSeverity: MEDIUM\nFix: Upgrade protobufjs to 7.5.8, 8.2.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-caa50897582e4a81", "name": "CVE-2026-54269: protobufjs 7.5.6 \u2014 .migration-backup/package-lock.json", "shortDescription": {"text": "CVE-2026-54269: protobufjs 7.5.6 \u2014 .migration-backup/package-lock.json"}, "fullDescription": {"text": "protobufjs: protobufjs-cli: protobufjs: Denial of Service due to name collision with runtime helpers\n\nprotobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 8.6.0 and 7.6.3, protobufjs accepted certain schema-derived names that could collide with properties used by protobufjs runtime helpers. The known affected names are fields named hasOwnProperty, field or oneof names such as $type when loaded through protobufjs JSON/reflection descriptors, and service methods whose generated helper name is rpcCall. When affected message or service types were used, protobufjs could r\n\nPackage: protobufjs\nInstalled: 7.5.6\nFixed in: 7.6.3, 8.6.0\nSeverity: MEDIUM\nFix: Upgrade protobufjs to 7.6.3, 8.6.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-bed3e6631e48bb90", "name": "CVE-2026-59877: protobufjs 7.5.6 \u2014 .migration-backup/package-lock.json", "shortDescription": {"text": "CVE-2026-59877: protobufjs 7.5.6 \u2014 .migration-backup/package-lock.json"}, "fullDescription": {"text": "protobufjs: protobufjs: Denial of Service via crafted .proto schema\n\nprotobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.6.5 and 8.6.6, protobufjs parsed option names by advancing through schema tokens until reaching an = token without checking for end of input, so a crafted .proto schema that opens an option declaration and ends prematurely can cause parse, Root.load, or Root.loadSync to loop indefinitely. This issue is fixed in versions 7.6.5 and 8.6.6.\n\nPackage: protobufjs\nInstalled: 7.5.6\nFixed in: 7.6.5, 8.6.6\nSeverity: MEDIUM\nFix: Upgrade protobufjs to 7.6.5, 8.6.6"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-441ff70db3c1eff8", "name": "CVE-2026-8723: qs 6.14.1 \u2014 .migration-backup/package-lock.json", "shortDescription": {"text": "CVE-2026-8723: qs 6.14.1 \u2014 .migration-backup/package-lock.json"}, "fullDescription": {"text": "qs: qs: Denial of Service due to improper handling of null/undefined array elements\n\n### Summary\n\n\n\n`qs.stringify` throws `TypeError` when called with `arrayFormat: 'comma'` and `encodeValuesOnly: true` on an array containing `null` or `undefined`. The throw is synchronous and not handled by any of qs's null-related options (`skipNulls`, `strictNullHandling`).\n\n\n\n### Details\n\n\n\nIn the comma + `encodeValuesOnly` branch, `lib/stringify.js:145` mapped the array through the raw encoder before joining:\n\n\n\n```js\n\n\n\nobj = utils.maybeMap(obj, encoder);\n\n\n\n```\n\n\n\n`utils.encode` (`lib/uti\n\nPackage: qs\nInstalled: 6.14.1\nFixed in: 6.15.2\nSeverity: MEDIUM\nFix: Upgrade qs to 6.15.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-94cb6c3a19037aa3", "name": "CVE-2026-2391: qs 6.14.1 \u2014 .migration-backup/package-lock.json", "shortDescription": {"text": "CVE-2026-2391: qs 6.14.1 \u2014 .migration-backup/package-lock.json"}, "fullDescription": {"text": "qs: qs's arrayLimit bypass in comma parsing allows denial of service\n\n### Summary\nThe `arrayLimit` option in qs does not enforce limits for comma-separated values when `comma: true` is enabled, allowing attackers to cause denial-of-service via memory exhaustion. This is a bypass of the array limit enforcement, similar to the bracket notation bypass addressed in GHSA-6rw7-vpxm-498p (CVE-2025-15284).\n\n### Details\nWhen the `comma` option is set to `true` (not the default, but configurable in applications), qs allows parsing comma-separated strings as arrays (e.g., `?\n\nPackage: qs\nInstalled: 6.14.1\nFixed in: 6.14.2\nSeverity: LOW\nFix: Upgrade qs to 6.14.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1e33b42f358a47b8", "name": "CVE-2026-27606: rollup 2.79.2 \u2014 .migration-backup/package-lock.json", "shortDescription": {"text": "CVE-2026-27606: rollup 2.79.2 \u2014 .migration-backup/package-lock.json"}, "fullDescription": {"text": "rollup: Rollup: Remote Code Execution via Path Traversal Vulnerability\n\nRollup is a module bundler for JavaScript. Versions prior to 2.80.0, 3.30.0, and 4.59.0 of the Rollup module bundler (specifically v4.x and present in current source) is vulnerable to an Arbitrary File Write via Path Traversal. Insecure file name sanitization in the core engine allows an attacker to control output filenames (e.g., via CLI named inputs, manual chunk aliases, or malicious plugins) and use traversal sequences (`../`) to overwrite files anywhere on the host filesystem that the build\n\nPackage: rollup\nInstalled: 2.79.2\nFixed in: 2.80.0, 3.30.0, 4.59.0\nSeverity: HIGH\nFix: Upgrade rollup to 2.80.0, 3.30.0, 4.59.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-3ec3e1ccb55bc2e7", "name": "CVE-2026-27606: rollup 4.54.0 \u2014 .migration-backup/package-lock.json", "shortDescription": {"text": "CVE-2026-27606: rollup 4.54.0 \u2014 .migration-backup/package-lock.json"}, "fullDescription": {"text": "rollup: Rollup: Remote Code Execution via Path Traversal Vulnerability\n\nRollup is a module bundler for JavaScript. Versions prior to 2.80.0, 3.30.0, and 4.59.0 of the Rollup module bundler (specifically v4.x and present in current source) is vulnerable to an Arbitrary File Write via Path Traversal. Insecure file name sanitization in the core engine allows an attacker to control output filenames (e.g., via CLI named inputs, manual chunk aliases, or malicious plugins) and use traversal sequences (`../`) to overwrite files anywhere on the host filesystem that the build\n\nPackage: rollup\nInstalled: 4.54.0\nFixed in: 2.80.0, 3.30.0, 4.59.0\nSeverity: HIGH\nFix: Upgrade rollup to 2.80.0, 3.30.0, 4.59.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-ae2aec0bcc922178", "name": "GHSA-5c6j-r48x-rmvq: serialize-javascript 6.0.2 \u2014 .migration-backup/package-lock.json", "shortDescription": {"text": "GHSA-5c6j-r48x-rmvq: serialize-javascript 6.0.2 \u2014 .migration-backup/package-lock.json"}, "fullDescription": {"text": "Serialize JavaScript is Vulnerable to RCE via RegExp.flags and Date.prototype.toISOString()\n\n### Impact\n\nThe serialize-javascript npm package (versions <= 7.0.2) contains a code injection vulnerability. It is an incomplete fix for CVE-2020-7660.\n\nWhile `RegExp.source` is sanitized, `RegExp.flags` is interpolated directly into the generated output without escaping. A similar issue exists in `Date.prototype.toISOString()`.\n\nIf an attacker can control the input object passed to `serialize()`, they can inject malicious JavaScript via the flags property of a RegExp object. When the serialize\n\nPackage: serialize-javascript\nInstalled: 6.0.2\nFixed in: 7.0.3\nSeverity: HIGH\nFix: Upgrade serialize-javascript to 7.0.3"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-8cafeb2a65700278", "name": "CVE-2026-34043: serialize-javascript 6.0.2 \u2014 .migration-backup/package-lock.json", "shortDescription": {"text": "CVE-2026-34043: serialize-javascript 6.0.2 \u2014 .migration-backup/package-lock.json"}, "fullDescription": {"text": "serialize-javascript: serialize-javascript: Denial of Service via specially crafted array-like object serialization\n\nSerialize JavaScript to a superset of JSON that includes regular expressions and functions. Prior to version 7.0.5, there is a Denial of Service (DoS) vulnerability caused by CPU exhaustion. When serializing a specially crafted \"array-like\" object (an object that inherits from Array.prototype but has a very large length property), the process enters an intensive loop that consumes 100% CPU and hangs indefinitely. This issue has been patched in version 7.0.5.\n\nPackage: serialize-javascript\nInstalled: 6.0.2\nFixed in: 7.0.5\nSeverity: MEDIUM\nFix: Upgrade serialize-javascript to 7.0.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-6c08ae89e4ace521", "name": "GHSA-f88m-g3jw-g9cj: sharp 0.34.5 \u2014 .migration-backup/package-lock.json", "shortDescription": {"text": "GHSA-f88m-g3jw-g9cj: sharp 0.34.5 \u2014 .migration-backup/package-lock.json"}, "fullDescription": {"text": "sharp inherited vulnerabilities in libvips: CVE-2026-33327, CVE-2026-33328, CVE-2026-35590, CVE-2026-35591\n\n### Impact\n\nA number of vulnerabilities, two rated as \"High\" severity using CVSSv4, have been discovered and fixed in the upstream libvips dependency.\n\nThose processing untrusted input with versions of sharp prior to 0.35.0 are affected.\n\n### Patches\n\n#### Using prebuilt binaries provided by sharp?\n\nMost people rely on the prebuilt binaries provided by sharp.\n\nPlease upgrade sharp to the latest version, currently 0.35.3, which provides libvips 8.18.3.\n\n#### Using a globally-installed libvips?\n\nP\n\nPackage: sharp\nInstalled: 0.34.5\nFixed in: 0.35.0\nSeverity: HIGH\nFix: Upgrade sharp to 0.35.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-7912e92029ca2121", "name": "CVE-2026-33151: socket.io-parser 4.2.5 \u2014 .migration-backup/package-lock.json", "shortDescription": {"text": "CVE-2026-33151: socket.io-parser 4.2.5 \u2014 .migration-backup/package-lock.json"}, "fullDescription": {"text": "socket.io: Socket.IO: Denial of Service due to excessive buffering of specially crafted packets\n\nSocket.IO is an open source, real-time, bidirectional, event-based, communication framework. Prior to versions 3.3.5, 3.4.4, and 4.2.6, a specially crafted Socket.IO packet can make the server wait for a large number of binary attachments and buffer them, which can be exploited to make the server run out of memory. This issue has been patched in versions 3.3.5, 3.4.4, and 4.2.6.\n\nPackage: socket.io-parser\nInstalled: 4.2.5\nFixed in: 3.3.5, 3.4.4, 4.2.6\nSeverity: HIGH\nFix: Upgrade socket.io-parser to 3.3.5, 3.4.4, 4.2.6"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-cb750782cefe9476", "name": "CVE-2026-69185: socket.io-parser 4.2.5 \u2014 .migration-backup/package-lock.json", "shortDescription": {"text": "CVE-2026-69185: socket.io-parser 4.2.5 \u2014 .migration-backup/package-lock.json"}, "fullDescription": {"text": "socket.io-parser: Socket.IO: Denial of Service via memory exhaustion from crafted packets\n\nSocket.IO enables bidirectional and low-latency communication for every platform. Prior to 4.2.7, 3.4.5, and 3.3.6, a specially crafted Socket.IO packet can make the server wait for a large number of binary attachments and buffer them, which can be exploited to make the server run out of memory. This vulnerability is fixed in 4.2.7, 3.4.5, and 3.3.6.\n\nPackage: socket.io-parser\nInstalled: 4.2.5\nFixed in: 4.2.7, 3.4.5, 3.3.6\nSeverity: HIGH\nFix: Upgrade socket.io-parser to 4.2.7, 3.4.5, 3.3.6"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-82dafd640f555a25", "name": "CVE-2026-59873: tar 6.2.1 \u2014 .migration-backup/package-lock.json", "shortDescription": {"text": "CVE-2026-59873: tar 6.2.1 \u2014 .migration-backup/package-lock.json"}, "fullDescription": {"text": "tar: node-tar: Denial of Service via crafted gzip bomb\n\nnode-tar is a tar archive manipulation library for Node.js. Prior to 7.5.19, node-tar does not enforce hard upper bounds on total decompressed data, entry counts, or decompression ratio in extraction and parsing paths such as src/extract.ts, allowing a small crafted gzip bomb to exhaust disk space and CPU. This issue is fixed in version 7.5.19.\n\nPackage: tar\nInstalled: 6.2.1\nFixed in: 7.5.19\nSeverity: CRITICAL\nFix: Upgrade tar to 7.5.19"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "critical", "confidence": 1.0}}, {"id": "scanner-14599c2197dc1e7b", "name": "CVE-2026-23745: tar 6.2.1 \u2014 .migration-backup/package-lock.json", "shortDescription": {"text": "CVE-2026-23745: tar 6.2.1 \u2014 .migration-backup/package-lock.json"}, "fullDescription": {"text": "node-tar: tar: node-tar: Arbitrary file overwrite and symlink poisoning via unsanitized linkpaths in archives\n\nnode-tar is a Tar for Node.js. The node-tar library (<= 7.5.2) fails to sanitize the linkpath of Link (hardlink) and SymbolicLink entries when preservePaths is false (the default secure behavior). This allows malicious archives to bypass the extraction root restriction, leading to Arbitrary File Overwrite via hardlinks and Symlink Poisoning via absolute symlink targets. This vulnerability is fixed in 7.5.3.\n\nPackage: tar\nInstalled: 6.2.1\nFixed in: 7.5.3\nSeverity: HIGH\nFix: Upgrade tar to 7.5.3"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-57c848c086e9cb1e", "name": "CVE-2026-23950: tar 6.2.1 \u2014 .migration-backup/package-lock.json", "shortDescription": {"text": "CVE-2026-23950: tar 6.2.1 \u2014 .migration-backup/package-lock.json"}, "fullDescription": {"text": "node-tar: tar: node-tar: Arbitrary file overwrite via Unicode path collision race condition\n\nnode-tar,a Tar for Node.js, has a race condition vulnerability in versions up to and including 7.5.3. This is due to an incomplete handling of Unicode path collisions in the `path-reservations` system. On case-insensitive or normalization-insensitive filesystems (such as macOS APFS, In which it has been tested), the library fails to lock colliding paths (e.g., `\u00df` and `ss`), allowing them to be processed in parallel. This bypasses the library's internal concurrency safeguards and permits Symlink\n\nPackage: tar\nInstalled: 6.2.1\nFixed in: 7.5.4\nSeverity: HIGH\nFix: Upgrade tar to 7.5.4"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-2e2ab3c0a8013a9e", "name": "CVE-2026-24842: tar 6.2.1 \u2014 .migration-backup/package-lock.json", "shortDescription": {"text": "CVE-2026-24842: tar 6.2.1 \u2014 .migration-backup/package-lock.json"}, "fullDescription": {"text": "node-tar: tar: node-tar: Arbitrary file creation via path traversal bypass in hardlink security check\n\nnode-tar,a Tar for Node.js, contains a vulnerability in versions prior to 7.5.7 where the security check for hardlink entries uses different path resolution semantics than the actual hardlink creation logic. This mismatch allows an attacker to craft a malicious TAR archive that bypasses path traversal protections and creates hardlinks to arbitrary files outside the extraction directory. Version 7.5.7 contains a fix for the issue.\n\nPackage: tar\nInstalled: 6.2.1\nFixed in: 7.5.7\nSeverity: HIGH\nFix: Upgrade tar to 7.5.7"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-6b479d648a8a3200", "name": "CVE-2026-26960: tar 6.2.1 \u2014 .migration-backup/package-lock.json", "shortDescription": {"text": "CVE-2026-26960: tar 6.2.1 \u2014 .migration-backup/package-lock.json"}, "fullDescription": {"text": "node-tar: node-tar: Arbitrary file read/write via malicious archive hardlink creation\n\nnode-tar is a full-featured Tar for Node.js. When using default options in versions 7.5.7 and below, an attacker-controlled archive can create a hardlink inside the extraction directory that points to a file outside the extraction root, enabling arbitrary file read and write as the extracting user. Severity is high because the primitive bypasses path protections and turns archive extraction into a direct filesystem access primitive. This issue has been fixed in version 7.5.8.\n\nPackage: tar\nInstalled: 6.2.1\nFixed in: 7.5.8\nSeverity: HIGH\nFix: Upgrade tar to 7.5.8"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-0aae322af35bedcc", "name": "CVE-2026-29786: tar 6.2.1 \u2014 .migration-backup/package-lock.json", "shortDescription": {"text": "CVE-2026-29786: tar 6.2.1 \u2014 .migration-backup/package-lock.json"}, "fullDescription": {"text": "node-tar: hardlink path traversal via drive-relative linkpath\n\nnode-tar is a full-featured Tar for Node.js. Prior to version 7.5.10, tar can be tricked into creating a hardlink that points outside the extraction directory by using a drive-relative link target such as C:../target.txt, which enables file overwrite outside cwd during normal tar.x() extraction. This issue has been patched in version 7.5.10.\n\nPackage: tar\nInstalled: 6.2.1\nFixed in: 7.5.10\nSeverity: HIGH\nFix: Upgrade tar to 7.5.10"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-37a8bf2fd82af8e1", "name": "CVE-2026-31802: tar 6.2.1 \u2014 .migration-backup/package-lock.json", "shortDescription": {"text": "CVE-2026-31802: tar 6.2.1 \u2014 .migration-backup/package-lock.json"}, "fullDescription": {"text": "tar: tar: File overwrite via drive-relative symlink traversal\n\nnode-tar is a full-featured Tar for Node.js. Prior to version 7.5.11, tar (npm) can be tricked into creating a symlink that points outside the extraction directory by using a drive-relative symlink target such as C:../../../target.txt, which enables file overwrite outside cwd during normal tar.x() extraction. This vulnerability is fixed in 7.5.11.\n\nPackage: tar\nInstalled: 6.2.1\nFixed in: 7.5.11\nSeverity: HIGH\nFix: Upgrade tar to 7.5.11"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-cbc4ecd0d4bbd8e9", "name": "CVE-2026-59874: tar 6.2.1 \u2014 .migration-backup/package-lock.json", "shortDescription": {"text": "CVE-2026-59874: tar 6.2.1 \u2014 .migration-backup/package-lock.json"}, "fullDescription": {"text": "tar: Node-tar: Denial of Service via malformed tar archive header\n\nnode-tar is a tar archive manipulation library for Node.js. Prior to 7.5.18, tar.replace accepts a checksum-valid tar header with a negative base-256 encoded entry size, causing the archive scanner to make no progress while repeatedly parsing the same header. This issue is fixed in version 7.5.18.\n\nPackage: tar\nInstalled: 6.2.1\nFixed in: 7.5.18\nSeverity: HIGH\nFix: Upgrade tar to 7.5.18"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-740b4b3bece6e000", "name": "CVE-2026-73566: tar 6.2.1 \u2014 .migration-backup/package-lock.json", "shortDescription": {"text": "CVE-2026-73566: tar 6.2.1 \u2014 .migration-backup/package-lock.json"}, "fullDescription": {"text": "tar: node-tar: Denial of Service via crafted long-path tar archive\n\nnode-tar is a tar archive manipulation library for Node.js. Prior to 7.5.21, node-tar's filesFilter in src/list.ts uses the recursive mapHas helper to walk an archive entry path upward with path.dirname() and no segment cap when tar.t(...) or tar.x(...) receives a non-empty member-selection list. A crafted GNU L or PAX x long-path header with thousands of slash-separated segments reaches this.filter(entry.path, entry) in Parser[CONSUMEHEADER] in src/parse.ts before Unpack[CHECKPATH] applies maxD\n\nPackage: tar\nInstalled: 6.2.1\nFixed in: 7.5.21\nSeverity: HIGH\nFix: Upgrade tar to 7.5.21"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-20f3f7b62620f536", "name": "CVE-2026-53655: tar 6.2.1 \u2014 .migration-backup/package-lock.json", "shortDescription": {"text": "CVE-2026-53655: tar 6.2.1 \u2014 .migration-backup/package-lock.json"}, "fullDescription": {"text": "node-tar: node-tar: File smuggling due to inconsistent tar archive parsing\n\nnode-tar is a full-featured Tar for Node.js. Prior to 7.5.16, tar (node-tar) applies a PAX extended header's size= record (and other PAX overrides) to the next header entry of any type, including intermediary metadata headers such as a GNU long-name (L) or long-link (K) entry. Per POSIX pax, a PAX extended header (x) describes the next file entry, not the intermediary extension headers that may sit between the x header and the file it annotates. Because node-tar lets the PAX size override the by\n\nPackage: tar\nInstalled: 6.2.1\nFixed in: 7.5.16\nSeverity: MEDIUM\nFix: Upgrade tar to 7.5.16"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-1d814b719e87cde0", "name": "CVE-2026-59871: tar 6.2.1 \u2014 .migration-backup/package-lock.json", "shortDescription": {"text": "CVE-2026-59871: tar 6.2.1 \u2014 .migration-backup/package-lock.json"}, "fullDescription": {"text": "node-tar: node-tar: Denial of Service due to incorrect PAX path handling\n\nnode-tar is a tar archive manipulation library for Node.js. Prior to 7.5.18, node-tar coerces all-digit PAX path and linkpath values in src/pax.ts to JavaScript numbers, causing downstream path handling such as normalizeWindowsPath(entry.path).split('/') to throw an uncaught TypeError. This issue is fixed in version 7.5.18.\n\nPackage: tar\nInstalled: 6.2.1\nFixed in: 7.5.18\nSeverity: MEDIUM\nFix: Upgrade tar to 7.5.18"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-4b0983b3865c39c2", "name": "CVE-2026-59875: tar 6.2.1 \u2014 .migration-backup/package-lock.json", "shortDescription": {"text": "CVE-2026-59875: tar 6.2.1 \u2014 .migration-backup/package-lock.json"}, "fullDescription": {"text": "node-tar: node-tar: Denial of Service via crafted archive with NUL bytes in metadata\n\nnode-tar is a tar archive manipulation library for Node.js. Prior to 7.5.17, node-tar does not strip NUL bytes from PAX path and linkpath records in src/pax.ts, allowing a crafted archive with values to reach fs.lstat or fs.open and terminate the process with an uncaught exception. This issue is fixed in version 7.5.17.\n\nPackage: tar\nInstalled: 6.2.1\nFixed in: 7.5.17\nSeverity: MEDIUM\nFix: Upgrade tar to 7.5.17"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-86d87e749b58d44d", "name": "CVE-2026-41907: uuid 8.3.2 \u2014 .migration-backup/package-lock.json", "shortDescription": {"text": "CVE-2026-41907: uuid 8.3.2 \u2014 .migration-backup/package-lock.json"}, "fullDescription": {"text": "uuid: uuid: Out-of-bounds write vulnerability impacts data integrity and confidentiality\n\nuuid is for the creation of RFC9562 (formerly RFC4122) UUIDs. Prior to 14.0.0, v3, v5, and v6 accept external output buffers but do not reject out-of-range writes (small buf or large offset). This allows silent partial writes into caller-provided buffers. This vulnerability is fixed in 14.0.0.\n\nPackage: uuid\nInstalled: 8.3.2\nFixed in: 11.1.1, 12.0.1, 13.0.1\nSeverity: MEDIUM\nFix: Upgrade uuid to 11.1.1, 12.0.1, 13.0.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-38be9278fc80ee8d", "name": "CVE-2026-41907: uuid 9.0.1 \u2014 .migration-backup/package-lock.json", "shortDescription": {"text": "CVE-2026-41907: uuid 9.0.1 \u2014 .migration-backup/package-lock.json"}, "fullDescription": {"text": "uuid: uuid: Out-of-bounds write vulnerability impacts data integrity and confidentiality\n\nuuid is for the creation of RFC9562 (formerly RFC4122) UUIDs. Prior to 14.0.0, v3, v5, and v6 accept external output buffers but do not reject out-of-range writes (small buf or large offset). This allows silent partial writes into caller-provided buffers. This vulnerability is fixed in 14.0.0.\n\nPackage: uuid\nInstalled: 9.0.1\nFixed in: 11.1.1, 12.0.1, 13.0.1\nSeverity: MEDIUM\nFix: Upgrade uuid to 11.1.1, 12.0.1, 13.0.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-0abeae27ae7b44f3", "name": "CVE-2026-39363: vite 7.3.0 \u2014 .migration-backup/package-lock.json", "shortDescription": {"text": "CVE-2026-39363: vite 7.3.0 \u2014 .migration-backup/package-lock.json"}, "fullDescription": {"text": "Vite: Vite: Information disclosure via WebSocket connection bypasses access control\n\nVite is a frontend tooling framework for JavaScript. From 6.0.0 to before 6.4.2, 7.3.2, and 8.0.5, if it is possible to connect to the Vite dev server\u2019s WebSocket without an Origin header, an attacker can invoke fetchModule via the custom WebSocket event vite:invoke and combine file://... with ?raw (or ?inline) to retrieve the contents of arbitrary files on the server as a JavaScript string (e.g., export default \"...\"). The access control enforced in the HTTP request path (such as server.fs.allo\n\nPackage: vite\nInstalled: 7.3.0\nFixed in: 8.0.5, 7.3.2, 6.4.2\nSeverity: HIGH\nFix: Upgrade vite to 8.0.5, 7.3.2, 6.4.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-c858ae6d8eacedc0", "name": "CVE-2026-39364: vite 7.3.0 \u2014 .migration-backup/package-lock.json", "shortDescription": {"text": "CVE-2026-39364: vite 7.3.0 \u2014 .migration-backup/package-lock.json"}, "fullDescription": {"text": "vite: Vite: Information disclosure via query parameter manipulation on the development server\n\nVite is a frontend tooling framework for JavaScript. From 7.1.0 to before 7.3.2 and 8.0.5, on the Vite dev server, files that should be blocked by server.fs.deny (e.g., .env, *.crt) can be retrieved with HTTP 200 responses when query parameters such as ?raw, ?import&raw, or ?import&url&inline are appended. This vulnerability is fixed in 7.3.2 and 8.0.5.\n\nPackage: vite\nInstalled: 7.3.0\nFixed in: 8.0.5, 7.3.2\nSeverity: HIGH\nFix: Upgrade vite to 8.0.5, 7.3.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-66f74a2eab1a5f58", "name": "CVE-2026-53571: vite 7.3.0 \u2014 .migration-backup/package-lock.json", "shortDescription": {"text": "CVE-2026-53571: vite 7.3.0 \u2014 .migration-backup/package-lock.json"}, "fullDescription": {"text": "vite: `server.fs.deny` bypass on Windows alternate paths\n\nVite is a frontend tooling framework for JavaScript. Prior to 8.0.16, 7.3.5, and 6.4.3, the contents of files that are specified by server.fs.deny can be returned to the browser on Windows. Vite\u2019s dev server denies direct access to sensitive files through server.fs.deny, including entries such as .env, .env.*, and *.{crt,pem}. However, on Windows, the deny logic does not correctly normalize NTFS ADS path forms before access checks are applied. Because of this, requests such as /.env::$DATA?raw a\n\nPackage: vite\nInstalled: 7.3.0\nFixed in: 8.0.16, 7.3.5, 6.4.3\nSeverity: HIGH\nFix: Upgrade vite to 8.0.16, 7.3.5, 6.4.3"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-12d90df76510846c", "name": "CVE-2026-39365: vite 7.3.0 \u2014 .migration-backup/package-lock.json", "shortDescription": {"text": "CVE-2026-39365: vite 7.3.0 \u2014 .migration-backup/package-lock.json"}, "fullDescription": {"text": "vite: Vite: Information disclosure via path traversal in dev server's .map request handling\n\nVite is a frontend tooling framework for JavaScript. From 6.0.0 to before 6.4.2, 7.3.2, and 8.0.5, the dev server\u2019s handling of .map requests for optimized dependencies resolves file paths and calls readFile without restricting ../ segments in the URL. As a result, it is possible to bypass the server.fs.strict allow list and retrieve .map files located outside the project root, provided they can be parsed as valid source map JSON. This vulnerability is fixed in 6.4.2, 7.3.2, and 8.0.5.\n\nPackage: vite\nInstalled: 7.3.0\nFixed in: 8.0.5, 7.3.2, 6.4.2\nSeverity: MEDIUM\nFix: Upgrade vite to 8.0.5, 7.3.2, 6.4.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-163d173273098cd6", "name": "CVE-2026-53632: vite 7.3.0 \u2014 .migration-backup/package-lock.json", "shortDescription": {"text": "CVE-2026-53632: vite 7.3.0 \u2014 .migration-backup/package-lock.json"}, "fullDescription": {"text": "launch-editor: launch-editor: Credential compromise via NTLMv2 password hash leak through UNC path access\n\nlaunch-editor allows users to open files with line numbers in editor from Node.js. Prior to 2.14.1, the launch-editor NPM package accesses arbitrary paths including Windows UNC paths. When a UNC path is opened, Windows automatically attempts NTLM authentication to the remote host, causing the user\u2019s NTLMv2 password hash to be leaked to an attacker-controlled SMB server. This can result in credential compromise through offline hash cracking. This vulnerability is fixed in 2.14.1.\n\nPackage: vite\nInstalled: 7.3.0\nFixed in: 8.0.16, 7.3.5, 6.4.3\nSeverity: MEDIUM\nFix: Upgrade vite to 8.0.16, 7.3.5, 6.4.3"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-45a7dc889e70f8f6", "name": "CVE-2026-48779: ws 8.18.3 \u2014 .migration-backup/package-lock.json", "shortDescription": {"text": "CVE-2026-48779: ws 8.18.3 \u2014 .migration-backup/package-lock.json"}, "fullDescription": {"text": "ws: ws: Denial of Service via memory exhaustion from small WebSocket fragments\n\nws is an open source WebSocket client and server for Node.js. All versions from 1.1.0 up to (but not including) 5.2.5, from 6.0.0 up to 6.2.4, from 7.0.0 up to 7.5.11, and from 8.0.0 up to 8.21.0 are affected by a memory exhaustion DoS vulnerability. A peer can send a high volume of exceptionally small fragments and data chunks, with modest network traffic, to force the remote peer into allocating and holding structural wrappers that consume far more memory than the default documented message-si\n\nPackage: ws\nInstalled: 8.18.3\nFixed in: 5.2.5, 6.2.4, 7.5.11, 8.21.0\nSeverity: HIGH\nFix: Upgrade ws to 5.2.5, 6.2.4, 7.5.11, 8.21.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-06da289904b17697", "name": "CVE-2026-45736: ws 8.18.3 \u2014 .migration-backup/package-lock.json", "shortDescription": {"text": "CVE-2026-45736: ws 8.18.3 \u2014 .migration-backup/package-lock.json"}, "fullDescription": {"text": "ws: ws: Uninitialized memory disclosure via `websocket.close()` with `TypedArray`\n\nws is an open source WebSocket client and server for Node.js. Prior to 8.20.1, the websocket.close() implementation is vulnerable to uninitialized memory disclosure when a TypedArray is passed as the reason argument. This vulnerability is fixed in 8.20.1.\n\nPackage: ws\nInstalled: 8.18.3\nFixed in: 8.20.1\nSeverity: MEDIUM\nFix: Upgrade ws to 8.20.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-a576e7c5c0b5986c", "name": "GHSA-gcfj-64vw-6mp9: axios 1.16.1 \u2014 pnpm-lock.yaml", "shortDescription": {"text": "GHSA-gcfj-64vw-6mp9: axios 1.16.1 \u2014 pnpm-lock.yaml"}, "fullDescription": {"text": "Axios Node HTTP adapter can use an inherited proxy after interceptor config cloning\n\n## Summary\n\nAxios\u2019 Node.js HTTP adapter can route requests through an attacker-controlled proxy when `Object.prototype.proxy` is polluted and request configuration is materialized as a regular object before dispatch.\n\nRecent axios releases harden merged request config by creating a null-prototype object. However, request interceptors run after that merge and may return a replacement config. A common immutable interceptor pattern such as `{...config}` or `Object.assign({}, config)` converts the h\n\nPackage: axios\nInstalled: 1.16.1\nFixed in: 0.33.0, 1.18.0\nSeverity: HIGH\nFix: Upgrade axios to 0.33.0, 1.18.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-e784448c0b604438", "name": "CVE-2026-67312: axios 1.16.1 \u2014 pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-67312: axios 1.16.1 \u2014 pnpm-lock.yaml"}, "fullDescription": {"text": "axios: axios: Denial of Service via uncontrolled recursion in form data processing\n\naxios versions from 0.28.0 before 0.33.0 and from 1.0.0 before 1.18.0 contain uncontrolled recursion in formDataToJSON (exposed as axios.formToJSON() and used internally when serializing FormData with Content-Type: application/json). When an application passes attacker-controlled FormData field names, a field name with thousands of nested bracket-delimited segments causes unbounded recursion in buildPath(), exhausting the JavaScript call stack (RangeError: Maximum call stack size exceeded) and c\n\nPackage: axios\nInstalled: 1.16.1\nFixed in: 0.33.0, 1.18.0\nSeverity: MEDIUM\nFix: Upgrade axios to 0.33.0, 1.18.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-03d6ebdfddb717e3", "name": "CVE-2026-67314: axios 1.16.1 \u2014 pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-67314: axios 1.16.1 \u2014 pnpm-lock.yaml"}, "fullDescription": {"text": "axios: axios: Outbound Request Tampering via Prototype Pollution in Basic Auth\n\naxios versions >=1.15.2 and <1.18.0 contain prototype-pollution read-side gadgets in Basic auth subfield handling (lib/adapters/http.js and lib/helpers/resolveConfig.js). When an application is already affected by a separate prototype-pollution primitive and makes an axios request with an own auth object that omits the username and/or password properties, axios reads the inherited Object.prototype.username and Object.prototype.password values and uses them to construct an outbound 'Authorization\n\nPackage: axios\nInstalled: 1.16.1\nFixed in: 1.18.0\nSeverity: MEDIUM\nFix: Upgrade axios to 1.18.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-8f2f12959f0ae229", "name": "CVE-2026-67316: axios 1.16.1 \u2014 pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-67316: axios 1.16.1 \u2014 pnpm-lock.yaml"}, "fullDescription": {"text": "axios: axios: Prototype Pollution allows unauthorized data transmission and network redirection\n\naxios is vulnerable to read-side prototype-pollution gadgets that can alter request construction when Object.prototype has already been polluted by a separate vulnerability or dependency. In the bodyless method aliases (axios.get(), axios.delete(), axios.head(), axios.options()), inherited data is read via (config || {}).data before config normalization, causing an attacker-controlled body to be sent on requests that did not set one. Additional low-level paths, only reachable when calling export\n\nPackage: axios\nInstalled: 1.16.1\nFixed in: 1.18.0, 0.33.0\nSeverity: MEDIUM\nFix: Upgrade axios to 1.18.0, 0.33.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-544929a9a8302ee6", "name": "GHSA-42h9-826w-cgv3: axios 1.16.1 \u2014 pnpm-lock.yaml", "shortDescription": {"text": "GHSA-42h9-826w-cgv3: axios 1.16.1 \u2014 pnpm-lock.yaml"}, "fullDescription": {"text": "Axios: Excessive recursion in formDataToJSON can cause denial of service\n\n## Summary\nAxios versions `0.28.0` and later contain uncontrolled recursion in `formDataToJSON`, the helper behind the public `axios.formToJSON()` / named `formToJSON` API and the default request transform used when FormData is sent with an `application/json` content type.\n\nApplications are affected when they pass attacker-controlled `FormData` field names into this functionality. A field name with thousands of nested bracket segments can exhaust the JavaScript call stack and throw `RangeError: \n\nPackage: axios\nInstalled: 1.16.1\nFixed in: 0.33.0, 1.18.0\nSeverity: MEDIUM\nFix: Upgrade axios to 0.33.0, 1.18.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-58f4705eb293437d", "name": "GHSA-7q8q-rj6j-mhjq: axios 1.16.1 \u2014 pnpm-lock.yaml", "shortDescription": {"text": "GHSA-7q8q-rj6j-mhjq: axios 1.16.1 \u2014 pnpm-lock.yaml"}, "fullDescription": {"text": "Axios: Nested axios option objects can consume polluted prototype values\n\n## Summary\n\nAxios can consume inherited properties from nested request option objects when the JavaScript process already has a polluted `Object.prototype`.\n\nThe top-level merged config is protected with a null prototype, but nested plain objects such as `auth` and `paramsSerializer` are cloned into ordinary objects. If application code passes placeholders such as `auth: {}` or `paramsSerializer: {}`, inherited `username`, `password`, `encode`, or `serialize` properties can influence outbound re\n\nPackage: axios\nInstalled: 1.16.1\nFixed in: 0.33.0, 1.18.0\nSeverity: MEDIUM\nFix: Upgrade axios to 0.33.0, 1.18.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-94cbdc8e41c2f067", "name": "GHSA-f4gw-2p7v-4548: axios 1.16.1 \u2014 pnpm-lock.yaml", "shortDescription": {"text": "GHSA-f4gw-2p7v-4548: axios 1.16.1 \u2014 pnpm-lock.yaml"}, "fullDescription": {"text": "Axios: NO_PROXY bypass for 0.0.0.0 local addresses in axios\n\n## Summary\n\nAxios versions containing `lib/helpers/shouldBypassProxy.js` do not treat `0.0.0.0` as a local address when evaluating `NO_PROXY` rules. In Node.js applications that use `HTTP_PROXY` or `HTTPS_PROXY` together with `NO_PROXY=localhost,127.0.0.1,::1` or similar, a request to `http://0.0.0.0:<port>/` can be routed through the configured proxy instead of bypassing it.\n\nThe issue is exploitable when an attacker can influence the axios request URL or a followed redirect target, and when th\n\nPackage: axios\nInstalled: 1.16.1\nFixed in: 1.18.0, 0.33.0\nSeverity: MEDIUM\nFix: Upgrade axios to 1.18.0, 0.33.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-c50bdc08ae566ea1", "name": "GHSA-hcpx-6fm6-wx23: axios 1.16.1 \u2014 pnpm-lock.yaml", "shortDescription": {"text": "GHSA-hcpx-6fm6-wx23: axios 1.16.1 \u2014 pnpm-lock.yaml"}, "fullDescription": {"text": "Axios form serializer maxDepth bypass via {} metatoken\n\n## Summary\n\nAxios versions in the fixed lines for GHSA-62hf-57xw-28j9 still contain an incomplete depth-limit bypass in `lib/helpers/toFormData.js`. When serializing an object with a top-level key ending in `{}`, axios calls `JSON.stringify()` on that value before the `formSerializer.maxDepth` guard can inspect the nested structure.\n\nAn attacker who can control object keys and nested values passed by an application into axios form or parameter serialization can trigger a raw `RangeError: Maximum\n\nPackage: axios\nInstalled: 1.16.1\nFixed in: 0.33.0, 1.18.0\nSeverity: MEDIUM\nFix: Upgrade axios to 0.33.0, 1.18.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-21eb42994744e3b8", "name": "GHSA-jqh4-m9w3-8hp9: axios 1.16.1 \u2014 pnpm-lock.yaml", "shortDescription": {"text": "GHSA-jqh4-m9w3-8hp9: axios 1.16.1 \u2014 pnpm-lock.yaml"}, "fullDescription": {"text": "Axios: Fetch adapter `ReadableStream` uploads bypass `maxBodyLength`\n\n## Summary\n\naxios\u2019 fetch adapter does not enforce `maxBodyLength` for live WHATWG `ReadableStream` request bodies whose size cannot be determined before dispatch. Applications that use `adapter: \"fetch\"` and rely on `maxBodyLength` to cap untrusted upload/proxy streams can send the full stream even when it exceeds the configured limit.\n\nThis affects fetch-adapter usage in edge runtimes where fetch is selected, and in Node.js or browser environments where the fetch adapter is explicitly selected.\n\nPackage: axios\nInstalled: 1.16.1\nFixed in: 1.18.0\nSeverity: MEDIUM\nFix: Upgrade axios to 1.18.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-d519fa97166f95fa", "name": "GHSA-mwf2-3pr3-8698: axios 1.16.1 \u2014 pnpm-lock.yaml", "shortDescription": {"text": "GHSA-mwf2-3pr3-8698: axios 1.16.1 \u2014 pnpm-lock.yaml"}, "fullDescription": {"text": "Axios: HTTP/2 streamed uploads bypass `maxBodyLength`\n\n## Summary\n\nAxios versions with Node.js HTTP/2 support allow streamed request bodies to bypass `maxBodyLength` enforcement when requests are sent with `httpVersion: 2`.\n\nThis affects applications that rely on `maxBodyLength` as a hard cap while forwarding attacker-controlled streams, such as upload endpoints proxying user data to an upstream HTTP/2 service. Buffered request bodies are still checked before the request is sent.\n\n## Impact\n\nAn attacker who can control a stream passed to axios can c\n\nPackage: axios\nInstalled: 1.16.1\nFixed in: 1.18.0\nSeverity: MEDIUM\nFix: Upgrade axios to 1.18.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-c9dadc5f9682a312", "name": "CVE-2026-12590: body-parser 2.2.2 \u2014 pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-12590: body-parser 2.2.2 \u2014 pnpm-lock.yaml"}, "fullDescription": {"text": "body-parser: body-parser: Denial of Service via invalid limit option\n\nImpact: In body-parser versions prior to 1.20.6 (1.x line) and 2.3.0 (2.x line), when the parser is configured with an invalid limit option value such as an unparseable string or NaN, bytes.parse returns null and the request body size check is silently skipped. Applications that rely on limit as their primary safeguard against oversized request bodies will accept arbitrarily large payloads, leading to excessive memory and CPU usage and denial of service. Patches: This issue is fixed in body-pars\n\nPackage: body-parser\nInstalled: 2.2.2\nFixed in: 1.20.6, 2.3.0\nSeverity: LOW\nFix: Upgrade body-parser to 1.20.6, 2.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-32938573f597b150", "name": "GHSA-g7r4-m6w7-qqqr: esbuild 0.27.3 \u2014 pnpm-lock.yaml", "shortDescription": {"text": "GHSA-g7r4-m6w7-qqqr: esbuild 0.27.3 \u2014 pnpm-lock.yaml"}, "fullDescription": {"text": "esbuild allows arbitrary file read when running the development server on Windows\n\n### Summary\n\nThe development server contains a path traversal vulnerability on Windows when serving files from `servedir`.\n\nDue to the use of `path.Clean()` (which only normalizes forward-slash `/` separators) instead of a Windows-aware path normalization function, it is possible to craft requests using backslashes (`\\`) that bypass the intended directory containment logic. An attacker can escape the configured `servedir` root and access arbitrary files on the filesystem.\nThis issue affects Wind\n\nPackage: esbuild\nInstalled: 0.27.3\nFixed in: 0.28.1\nSeverity: LOW\nFix: Upgrade esbuild to 0.28.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ac551d1241a4c012", "name": "CVE-2026-12143: form-data 2.5.5 \u2014 pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-12143: form-data 2.5.5 \u2014 pnpm-lock.yaml"}, "fullDescription": {"text": "form-data: form-data: Form field override via CRLF injection\n\nform-data is a library for creating readable multipart/form-data streams. In versions through 4.0.5, the `field` argument to `FormData#append` and the `filename` option are concatenated verbatim into the `Content-Disposition` header without escaping carriage return (CR), line feed (LF), or double-quote (\") characters. An application that passes attacker-controlled data as a field name or filename (for example, an API gateway that turns JSON object keys into multipart field names) allows the atta\n\nPackage: form-data\nInstalled: 2.5.5\nFixed in: 2.5.6, 3.0.5, 4.0.6\nSeverity: HIGH\nFix: Upgrade form-data to 2.5.6, 3.0.5, 4.0.6"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-8deda405a91487df", "name": "CVE-2026-12143: form-data 4.0.5 \u2014 pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-12143: form-data 4.0.5 \u2014 pnpm-lock.yaml"}, "fullDescription": {"text": "form-data: form-data: Form field override via CRLF injection\n\nform-data is a library for creating readable multipart/form-data streams. In versions through 4.0.5, the `field` argument to `FormData#append` and the `filename` option are concatenated verbatim into the `Content-Disposition` header without escaping carriage return (CR), line feed (LF), or double-quote (\") characters. An application that passes attacker-controlled data as a field name or filename (for example, an API gateway that turns JSON object keys into multipart field names) allows the atta\n\nPackage: form-data\nInstalled: 4.0.5\nFixed in: 2.5.6, 3.0.5, 4.0.6\nSeverity: HIGH\nFix: Upgrade form-data to 2.5.6, 3.0.5, 4.0.6"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-7dc8cc9a7e53fb4b", "name": "CVE-2026-5079: multer 2.1.1 \u2014 pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-5079: multer 2.1.1 \u2014 pnpm-lock.yaml"}, "fullDescription": {"text": "multer: Multer: Denial of Service via deeply nested field names in multipart form data\n\nImpact: multer versions 1.0.0 through 2.1.1 and 3.0.0-alpha.1 are vulnerable to a Denial of Service via deeply nested field names in multipart form data. The append-field dependency parses bracket notation in field names with no limit on nesting depth, allowing an attacker to force allocation of deeply nested object structures that consume CPU and memory. A single HTTP request with a crafted multipart body is sufficient to exploit this.\n\nPatches: Users should upgrade to multer 2.2.0 (2.x line) o\n\nPackage: multer\nInstalled: 2.1.1\nFixed in: 2.2.0, 3.0.0-alpha.2\nSeverity: HIGH\nFix: Upgrade multer to 2.2.0, 3.0.0-alpha.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-c54af1034846997f", "name": "CVE-2026-5038: multer 2.1.1 \u2014 pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-5038: multer 2.1.1 \u2014 pnpm-lock.yaml"}, "fullDescription": {"text": "multer: Multer: Denial of Service via aborted or malformed multipart uploads\n\nImpact: multer versions 2.0.0-alpha.1 through 2.1.1 and 3.0.0-alpha.1 are vulnerable to a Denial of Service when using diskStorage. Aborted or malformed multipart uploads leave orphaned partial files on disk because the Readable.pipe() call does not propagate the stream destroy signal to \nthe underlying fs.WriteStream. An attacker can exhaust disk space by triggering many aborted uploads, with no application bug required.\n\nPatches: Users should upgrade to multer 2.2.0 (2.x line) or 3.0.0-alpha.2\n\nPackage: multer\nInstalled: 2.1.1\nFixed in: 2.2.0, 3.0.0-alpha.2\nSeverity: MEDIUM\nFix: Upgrade multer to 2.2.0, 3.0.0-alpha.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-f8c09bd5c6f7951d", "name": "GHSA-rgwj-5xj2-c3m3: mysql2 3.22.4 \u2014 pnpm-lock.yaml", "shortDescription": {"text": "GHSA-rgwj-5xj2-c3m3: mysql2 3.22.4 \u2014 pnpm-lock.yaml"}, "fullDescription": {"text": "MySQL2: Unbounded zlib inflate in compressed MySQL protocol handler allows decompression-bomb DoS\n\n## Vulnerability Details\n\n**File**: `lib/compressed_protocol.js`\n**Line**: 43 (`zlib.inflate(body, (err, data) => { ... })` inside `handleCompressedPacket`)\n\n### Root Cause\nWhen a connection is created with `compress: true` (and the server advertises `CLIENT_COMPRESS`), every incoming packet is unwrapped by `handleCompressedPacket()` in `lib/compressed_protocol.js`, which calls:\n\n```js\nzlib.inflate(body, (err, data) => { ... });\n```\n\nNo options object (in particular, no `maxOutputLength`) is pas\n\nPackage: mysql2\nInstalled: 3.22.4\nFixed in: 3.23.1\nSeverity: MEDIUM\nFix: Upgrade mysql2 to 3.23.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-7f18721531ea7fdf", "name": "CVE-2026-67213: nanoid 3.3.12 \u2014 pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-67213: nanoid 3.3.12 \u2014 pnpm-lock.yaml"}, "fullDescription": {"text": "nanoid: nanoid: Denial of Service via infinite loop in random ID generation\n\nnanoid (Nano ID) before 5.1.6 contains an infinite loop in the customAlphabet and customRandom functions. When these functions are configured with a size of 0, the internal generation loop never satisfies its exit condition and spins indefinitely, hanging the calling thread. An application that passes an unvalidated, attacker-controlled size of 0 to these functions is exposed to a denial-of-service condition.\n\nPackage: nanoid\nInstalled: 3.3.12\nFixed in: 3.3.18, 5.1.6\nSeverity: HIGH\nFix: Upgrade nanoid to 3.3.18, 5.1.6"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-d80cfa387b678710", "name": "CVE-2026-67214: nanoid 3.3.12 \u2014 pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-67214: nanoid 3.3.12 \u2014 pnpm-lock.yaml"}, "fullDescription": {"text": "nanoid: nanoid: Denial of Service via negative size input in non-secure module functions\n\nnanoid (Nano ID) before 3.3.16 and 5.1.16 contains an infinite loop in the customAlphabet and nanoid functions of its non-secure module (nanoid/non-secure). When these functions are given a negative size, the loop counter is decremented from a negative value and never reaches its termination condition, spinning indefinitely and hanging the calling thread. An application that passes an unvalidated, attacker-controlled negative size to these functions is exposed to a denial-of-service condition.\n\nPackage: nanoid\nInstalled: 3.3.12\nFixed in: 3.3.16, 5.1.16\nSeverity: HIGH\nFix: Upgrade nanoid to 3.3.16, 5.1.16"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-09e24da193fe4066", "name": "CVE-2026-67214: nanoid 5.1.11 \u2014 pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-67214: nanoid 5.1.11 \u2014 pnpm-lock.yaml"}, "fullDescription": {"text": "nanoid: nanoid: Denial of Service via negative size input in non-secure module functions\n\nnanoid (Nano ID) before 3.3.16 and 5.1.16 contains an infinite loop in the customAlphabet and nanoid functions of its non-secure module (nanoid/non-secure). When these functions are given a negative size, the loop counter is decremented from a negative value and never reaches its termination condition, spinning indefinitely and hanging the calling thread. An application that passes an unvalidated, attacker-controlled negative size to these functions is exposed to a denial-of-service condition.\n\nPackage: nanoid\nInstalled: 5.1.11\nFixed in: 3.3.16, 5.1.16\nSeverity: HIGH\nFix: Upgrade nanoid to 3.3.16, 5.1.16"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-1e84f80a69fbddcc", "name": "CVE-2026-73646: postcss 8.5.15 \u2014 pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-73646: postcss 8.5.15 \u2014 pnpm-lock.yaml"}, "fullDescription": {"text": "postcss: PostCSS: Information disclosure via path traversal in source map auto-loading\n\nPostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract Syntax Tree. Prior to 8.5.18, lib/previous-map.js loadMap() passes attacker-controlled sourceMappingURL values to join(dirname(opts.from), annotation), and loadFile() permits traversed or absolute .map paths, allowing untrusted CSS processed without map: false to disclose sourcesContent from arbitrary reachable .map files through result.map. This issue is fixed in version 8.5.1\n\nPackage: postcss\nInstalled: 8.5.15\nFixed in: 8.5.18\nSeverity: HIGH\nFix: Upgrade postcss to 8.5.18"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-3c3a1034edfb46d7", "name": "CVE-2026-69153: postcss 8.5.15 \u2014 pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-69153: postcss 8.5.15 \u2014 pnpm-lock.yaml"}, "fullDescription": {"text": "postcss: PostCSS: Information disclosure via crafted sourceMappingURL\n\nPostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract Syntax Tree. Prior to 8.5.19, if from is unset, an attacker can cause PreviousMap.loadFile() to read an unintended source-map file by supplying an absolute or directory-traversal sourceMappingURL. The resulting map\u2019s sources and sourcesContent may then be exposed to the application. This issue is fixed in version 8.5.19.\n\nPackage: postcss\nInstalled: 8.5.15\nFixed in: 8.5.23\nSeverity: MEDIUM\nFix: Upgrade postcss to 8.5.23"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-d1ab401799daa269", "name": "CVE-2026-54269: protobufjs 7.6.1 \u2014 pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-54269: protobufjs 7.6.1 \u2014 pnpm-lock.yaml"}, "fullDescription": {"text": "protobufjs: protobufjs-cli: protobufjs: Denial of Service due to name collision with runtime helpers\n\nprotobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 8.6.0 and 7.6.3, protobufjs accepted certain schema-derived names that could collide with properties used by protobufjs runtime helpers. The known affected names are fields named hasOwnProperty, field or oneof names such as $type when loaded through protobufjs JSON/reflection descriptors, and service methods whose generated helper name is rpcCall. When affected message or service types were used, protobufjs could r\n\nPackage: protobufjs\nInstalled: 7.6.1\nFixed in: 7.6.3, 8.6.0\nSeverity: MEDIUM\nFix: Upgrade protobufjs to 7.6.3, 8.6.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-97320d7eeb91e3bc", "name": "CVE-2026-59877: protobufjs 7.6.1 \u2014 pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-59877: protobufjs 7.6.1 \u2014 pnpm-lock.yaml"}, "fullDescription": {"text": "protobufjs: protobufjs: Denial of Service via crafted .proto schema\n\nprotobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.6.5 and 8.6.6, protobufjs parsed option names by advancing through schema tokens until reaching an = token without checking for end of input, so a crafted .proto schema that opens an option declaration and ends prematurely can cause parse, Root.load, or Root.loadSync to loop indefinitely. This issue is fixed in versions 7.6.5 and 8.6.6.\n\nPackage: protobufjs\nInstalled: 7.6.1\nFixed in: 7.6.5, 8.6.6\nSeverity: MEDIUM\nFix: Upgrade protobufjs to 7.6.5, 8.6.6"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-618f3c6532aa65ef", "name": "CVE-2026-8723: qs 6.15.1 \u2014 pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-8723: qs 6.15.1 \u2014 pnpm-lock.yaml"}, "fullDescription": {"text": "qs: qs: Denial of Service due to improper handling of null/undefined array elements\n\n### Summary\n\n\n\n`qs.stringify` throws `TypeError` when called with `arrayFormat: 'comma'` and `encodeValuesOnly: true` on an array containing `null` or `undefined`. The throw is synchronous and not handled by any of qs's null-related options (`skipNulls`, `strictNullHandling`).\n\n\n\n### Details\n\n\n\nIn the comma + `encodeValuesOnly` branch, `lib/stringify.js:145` mapped the array through the raw encoder before joining:\n\n\n\n```js\n\n\n\nobj = utils.maybeMap(obj, encoder);\n\n\n\n```\n\n\n\n`utils.encode` (`lib/uti\n\nPackage: qs\nInstalled: 6.15.1\nFixed in: 6.15.2\nSeverity: MEDIUM\nFix: Upgrade qs to 6.15.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-158c4afdf77b4dcf", "name": "CVE-2026-69185: socket.io-parser 4.2.6 \u2014 pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-69185: socket.io-parser 4.2.6 \u2014 pnpm-lock.yaml"}, "fullDescription": {"text": "socket.io-parser: Socket.IO: Denial of Service via memory exhaustion from crafted packets\n\nSocket.IO enables bidirectional and low-latency communication for every platform. Prior to 4.2.7, 3.4.5, and 3.3.6, a specially crafted Socket.IO packet can make the server wait for a large number of binary attachments and buffer them, which can be exploited to make the server run out of memory. This vulnerability is fixed in 4.2.7, 3.4.5, and 3.3.6.\n\nPackage: socket.io-parser\nInstalled: 4.2.6\nFixed in: 4.2.7, 3.4.5, 3.3.6\nSeverity: HIGH\nFix: Upgrade socket.io-parser to 4.2.7, 3.4.5, 3.3.6"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-226e1bc058ae11ed", "name": "CVE-2026-41907: uuid 8.3.2 \u2014 pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-41907: uuid 8.3.2 \u2014 pnpm-lock.yaml"}, "fullDescription": {"text": "uuid: uuid: Out-of-bounds write vulnerability impacts data integrity and confidentiality\n\nuuid is for the creation of RFC9562 (formerly RFC4122) UUIDs. Prior to 14.0.0, v3, v5, and v6 accept external output buffers but do not reject out-of-range writes (small buf or large offset). This allows silent partial writes into caller-provided buffers. This vulnerability is fixed in 14.0.0.\n\nPackage: uuid\nInstalled: 8.3.2\nFixed in: 11.1.1, 12.0.1, 13.0.1\nSeverity: MEDIUM\nFix: Upgrade uuid to 11.1.1, 12.0.1, 13.0.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-d57769a75313f0c2", "name": "CVE-2026-41907: uuid 9.0.1 \u2014 pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-41907: uuid 9.0.1 \u2014 pnpm-lock.yaml"}, "fullDescription": {"text": "uuid: uuid: Out-of-bounds write vulnerability impacts data integrity and confidentiality\n\nuuid is for the creation of RFC9562 (formerly RFC4122) UUIDs. Prior to 14.0.0, v3, v5, and v6 accept external output buffers but do not reject out-of-range writes (small buf or large offset). This allows silent partial writes into caller-provided buffers. This vulnerability is fixed in 14.0.0.\n\nPackage: uuid\nInstalled: 9.0.1\nFixed in: 11.1.1, 12.0.1, 13.0.1\nSeverity: MEDIUM\nFix: Upgrade uuid to 11.1.1, 12.0.1, 13.0.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-df43818ec803dac6", "name": "CVE-2026-48779: ws 8.20.1 \u2014 pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-48779: ws 8.20.1 \u2014 pnpm-lock.yaml"}, "fullDescription": {"text": "ws: ws: Denial of Service via memory exhaustion from small WebSocket fragments\n\nws is an open source WebSocket client and server for Node.js. All versions from 1.1.0 up to (but not including) 5.2.5, from 6.0.0 up to 6.2.4, from 7.0.0 up to 7.5.11, and from 8.0.0 up to 8.21.0 are affected by a memory exhaustion DoS vulnerability. A peer can send a high volume of exceptionally small fragments and data chunks, with modest network traffic, to force the remote peer into allocating and holding structural wrappers that consume far more memory than the default documented message-si\n\nPackage: ws\nInstalled: 8.20.1\nFixed in: 5.2.5, 6.2.4, 7.5.11, 8.21.0\nSeverity: HIGH\nFix: Upgrade ws to 5.2.5, 6.2.4, 7.5.11, 8.21.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-f4def1fa4a4e776c", "name": "DS-0002: Image user should not be 'root' \u2014 .migration-backup/Dockerfile", "shortDescription": {"text": "DS-0002: Image user should not be 'root' \u2014 .migration-backup/Dockerfile"}, "fullDescription": {"text": "Image user should not be 'root'\n\nSpecify at least 1 USER command in Dockerfile with non-root user as argument\n\nRule: DS-0002\nSeverity: HIGH\nTarget: .migration-backup/Dockerfile"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-ed0f059f269da3b5", "name": "DS-0026: No HEALTHCHECK defined \u2014 .migration-backup/Dockerfile", "shortDescription": {"text": "DS-0026: No HEALTHCHECK defined \u2014 .migration-backup/Dockerfile"}, "fullDescription": {"text": "No HEALTHCHECK defined\n\nAdd HEALTHCHECK instruction in your Dockerfile\n\nRule: DS-0026\nSeverity: LOW\nTarget: .migration-backup/Dockerfile"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3a3527e70129fb18", "name": "DS-0002: Image user should not be 'root' \u2014 Dockerfile", "shortDescription": {"text": "DS-0002: Image user should not be 'root' \u2014 Dockerfile"}, "fullDescription": {"text": "Image user should not be 'root'\n\nSpecify at least 1 USER command in Dockerfile with non-root user as argument\n\nRule: DS-0002\nSeverity: HIGH\nTarget: Dockerfile"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-72ff79e0f8219b60", "name": "DS-0013: 'RUN cd ...' to change directory \u2014 Dockerfile", "shortDescription": {"text": "DS-0013: 'RUN cd ...' to change directory \u2014 Dockerfile"}, "fullDescription": {"text": "'RUN cd ...' to change directory\n\nRUN should not be used to change directory: 'cd artifacts/pregasquad-manager && PORT=8000 BASE_PATH=/ pnpm run build'. Use 'WORKDIR' statement instead.\n\nRule: DS-0013\nSeverity: MEDIUM\nTarget: Dockerfile"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-3c4041c454cda88e", "name": "DS-0026: No HEALTHCHECK defined \u2014 Dockerfile", "shortDescription": {"text": "DS-0026: No HEALTHCHECK defined \u2014 Dockerfile"}, "fullDescription": {"text": "No HEALTHCHECK defined\n\nAdd HEALTHCHECK instruction in your Dockerfile\n\nRule: DS-0026\nSeverity: LOW\nTarget: Dockerfile"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f12fd58d443fd86f", "name": "DS-0002: Image user should not be 'root' \u2014 Dockerfile.api", "shortDescription": {"text": "DS-0002: Image user should not be 'root' \u2014 Dockerfile.api"}, "fullDescription": {"text": "Image user should not be 'root'\n\nSpecify at least 1 USER command in Dockerfile with non-root user as argument\n\nRule: DS-0002\nSeverity: HIGH\nTarget: Dockerfile.api"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-7440a4d260cc223a", "name": "DS-0026: No HEALTHCHECK defined \u2014 Dockerfile.api", "shortDescription": {"text": "DS-0026: No HEALTHCHECK defined \u2014 Dockerfile.api"}, "fullDescription": {"text": "No HEALTHCHECK defined\n\nAdd HEALTHCHECK instruction in your Dockerfile\n\nRule: DS-0026\nSeverity: LOW\nTarget: Dockerfile.api"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8ea271d955e28e4a", "name": "DS-0029: 'apt-get' missing '--no-install-recommends' \u2014 Dockerfile.api", "shortDescription": {"text": "DS-0029: 'apt-get' missing '--no-install-recommends' \u2014 Dockerfile.api"}, "fullDescription": {"text": "'apt-get' missing '--no-install-recommends'\n\n'--no-install-recommends' flag is missed: 'apt-get update && apt-get install -y python3 make g++ && rm -rf /var/lib/apt/lists/*'\n\nRule: DS-0029\nSeverity: HIGH\nTarget: Dockerfile.api"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-5d012ea0e358b226", "name": "DS-0002: Image user should not be 'root' \u2014 Dockerfile.manager", "shortDescription": {"text": "DS-0002: Image user should not be 'root' \u2014 Dockerfile.manager"}, "fullDescription": {"text": "Image user should not be 'root'\n\nSpecify at least 1 USER command in Dockerfile with non-root user as argument\n\nRule: DS-0002\nSeverity: HIGH\nTarget: Dockerfile.manager"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-379e564e599d0fbf", "name": "DS-0026: No HEALTHCHECK defined \u2014 Dockerfile.manager", "shortDescription": {"text": "DS-0026: No HEALTHCHECK defined \u2014 Dockerfile.manager"}, "fullDescription": {"text": "No HEALTHCHECK defined\n\nAdd HEALTHCHECK instruction in your Dockerfile\n\nRule: DS-0026\nSeverity: LOW\nTarget: Dockerfile.manager"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-fa25f052682e3e23", "name": "Secret leak: Asymmetric Private Key \u2014 .migration-backup/server/certs/qz-private-key.pem", "shortDescription": {"text": "Secret leak: Asymmetric Private Key \u2014 .migration-backup/server/certs/qz-private-key.pem"}, "fullDescription": {"text": "Trivy detected a possible secret in `.migration-backup/server/certs/qz-private-key.pem`.\n\nRule: private-key\nSeverity: HIGH\nMatch (redacted): ****************************************************************\n\nAction: rotate the credential and remove it from the repo. Use a secrets manager or environment variables."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-2165df432f868b6b", "name": "Secret leak: Asymmetric Private Key \u2014 artifacts/api-server/server/certs/qz-private-key.pem", "shortDescription": {"text": "Secret leak: Asymmetric Private Key \u2014 artifacts/api-server/server/certs/qz-private-key.pem"}, "fullDescription": {"text": "Trivy detected a possible secret in `artifacts/api-server/server/certs/qz-private-key.pem`.\n\nRule: private-key\nSeverity: HIGH\nMatch (redacted): ****************************************************************\n\nAction: rotate the credential and remove it from the repo. Use a secrets manager or environment variables."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-2c5a37784607d195", "name": "Secret leak: Asymmetric Private Key \u2014 artifacts/api-server/src/certs/qz-private-key.pem", "shortDescription": {"text": "Secret leak: Asymmetric Private Key \u2014 artifacts/api-server/src/certs/qz-private-key.pem"}, "fullDescription": {"text": "Trivy detected a possible secret in `artifacts/api-server/src/certs/qz-private-key.pem`.\n\nRule: private-key\nSeverity: HIGH\nMatch (redacted): ****************************************************************\n\nAction: rotate the credential and remove it from the repo. Use a secrets manager or environment variables."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-b23183c45ac454b1", "name": "Secret leak: Asymmetric Private Key \u2014 server/certs/qz-private-key.pem", "shortDescription": {"text": "Secret leak: Asymmetric Private Key \u2014 server/certs/qz-private-key.pem"}, "fullDescription": {"text": "Trivy detected a possible secret in `server/certs/qz-private-key.pem`.\n\nRule: private-key\nSeverity: HIGH\nMatch (redacted): ****************************************************************\n\nAction: rotate the credential and remove it from the repo. Use a secrets manager or environment variables."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-d63da3583b14afc0", "name": "Dockerfile runs as root: Dockerfile", "shortDescription": {"text": "Dockerfile runs as root: Dockerfile"}, "fullDescription": {"text": "No non-root USER set. Containers running as root expand the blast radius of any vulnerability inside the image."}, "properties": {"scanner": "scanner-primary", "layer": "hardware", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-25de52372c63f233", "name": "Docker base image is tag-pinned but not digest-pinned: node:24-slim", "shortDescription": {"text": "Docker base image is tag-pinned but not digest-pinned: node:24-slim"}, "fullDescription": {"text": "Container tags can be retagged upstream. Pin production base images to a reviewed digest (`image@sha256:...`) when reproducibility and supply-chain integrity matter."}, "properties": {"scanner": "scanner-primary", "layer": "hardware", "severity": "low", "confidence": 1.0}}, {"id": "scanner-48e5a2876fc80d5c", "name": "Insecure pattern 'local_storage_auth_token' in artifacts/pregasquad-manager/src/main.tsx:35", "shortDescription": {"text": "Insecure pattern 'local_storage_auth_token' in artifacts/pregasquad-manager/src/main.tsx:35"}, "fullDescription": {"text": "Found a known-risky pattern (local_storage_auth_token). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-025da1ad06f81388", "name": "Insecure pattern 'local_storage_auth_token' in artifacts/pregasquad-manager/src/components/layout/FirstLogin.tsx:96", "shortDescription": {"text": "Insecure pattern 'local_storage_auth_token' in artifacts/pregasquad-manager/src/components/layout/FirstLogin.tsx:96"}, "fullDescription": {"text": "Found a known-risky pattern (local_storage_auth_token). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-69ae226a68090585", "name": "Insecure pattern 'dangerous_innerhtml' in artifacts/pregasquad-manager/src/components/ui/chart.tsx:81", "shortDescription": {"text": "Insecure pattern 'dangerous_innerhtml' in artifacts/pregasquad-manager/src/components/ui/chart.tsx:81"}, "fullDescription": {"text": "Found a known-risky pattern (dangerous_innerhtml). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.65}}, {"id": "scanner-8be6a5fc36902a6f", "name": "Insecure pattern 'dangerous_innerhtml' in artifacts/mockup-sandbox/src/components/ui/chart.tsx:79", "shortDescription": {"text": "Insecure pattern 'dangerous_innerhtml' in artifacts/mockup-sandbox/src/components/ui/chart.tsx:79"}, "fullDescription": {"text": "Found a known-risky pattern (dangerous_innerhtml). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.65}}, {"id": "scanner-e5f9a03d756818c5", "name": "Insecure pattern 'cors_wildcard' in artifacts/api-server/src/app.ts:8", "shortDescription": {"text": "Insecure pattern 'cors_wildcard' in artifacts/api-server/src/app.ts:8"}, "fullDescription": {"text": "Found a known-risky pattern (cors_wildcard). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-5b201e37e7306271", "name": "Insecure pattern 'cors_wildcard' in artifacts/api-server/src/routes/routes.ts:542", "shortDescription": {"text": "Insecure pattern 'cors_wildcard' in artifacts/api-server/src/routes/routes.ts:542"}, "fullDescription": {"text": "Found a known-risky pattern (cors_wildcard). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-cb639d9a10a47b23", "name": "package.json defines install-time lifecycle scripts", "shortDescription": {"text": "package.json defines install-time lifecycle scripts"}, "fullDescription": {"text": "preinstall/install/postinstall/prepare scripts execute during dependency installation. Review them carefully for network calls, obfuscation, shell execution, or credential access."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d2bbeabe4013d568", "name": "Very large file: artifacts/pregasquad-manager/src/pages/AdminSettings.tsx (2186 lines)", "shortDescription": {"text": "Very large file: artifacts/pregasquad-manager/src/pages/AdminSettings.tsx (2186 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-dfae44774be69d50", "name": "Very large file: artifacts/pregasquad-manager/src/pages/Salaries.tsx (2447 lines)", "shortDescription": {"text": "Very large file: artifacts/pregasquad-manager/src/pages/Salaries.tsx (2447 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-57f10e7c21b381ff", "name": "Very large file: artifacts/pregasquad-manager/src/pages/WhatsApp.tsx (3431 lines)", "shortDescription": {"text": "Very large file: artifacts/pregasquad-manager/src/pages/WhatsApp.tsx (3431 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f1651c68f64e43c7", "name": "Very large file: artifacts/pregasquad-manager/src/pages/Website.tsx (1157 lines)", "shortDescription": {"text": "Very large file: artifacts/pregasquad-manager/src/pages/Website.tsx (1157 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-83b8a5eb5a17efb5", "name": "Very large file: artifacts/pregasquad-manager/src/pages/Clients.tsx (1370 lines)", "shortDescription": {"text": "Very large file: artifacts/pregasquad-manager/src/pages/Clients.tsx (1370 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-0bef888905140f39", "name": "Very large file: artifacts/pregasquad-manager/src/pages/Charges.tsx (1112 lines)", "shortDescription": {"text": "Very large file: artifacts/pregasquad-manager/src/pages/Charges.tsx (1112 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-49c141f8db7fb738", "name": "Very large file: artifacts/pregasquad-manager/src/pages/Planning.tsx (4883 lines)", "shortDescription": {"text": "Very large file: artifacts/pregasquad-manager/src/pages/Planning.tsx (4883 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-0bae98eab61865d8", "name": "Very large file: artifacts/pregasquad-manager/src/pages/Booking.tsx (1311 lines)", "shortDescription": {"text": "Very large file: artifacts/pregasquad-manager/src/pages/Booking.tsx (1311 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8143d7963cf091a0", "name": "Very large file: artifacts/pregasquad-manager/src/hooks/use-salon-data.ts (1527 lines)", "shortDescription": {"text": "Very large file: artifacts/pregasquad-manager/src/hooks/use-salon-data.ts (1527 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2191b9ce86040ede", "name": "Very large file: artifacts/api-server/src/storage.ts (1694 lines)", "shortDescription": {"text": "Very large file: artifacts/api-server/src/storage.ts (1694 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3b9e20e2012234e8", "name": "Very large file: artifacts/api-server/src/gemini.ts (1703 lines)", "shortDescription": {"text": "Very large file: artifacts/api-server/src/gemini.ts (1703 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-22ff002102036496", "name": "Very large file: artifacts/api-server/src/db.ts (2811 lines)", "shortDescription": {"text": "Very large file: artifacts/api-server/src/db.ts (2811 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8ed40d7926ed8994", "name": "Very large file: artifacts/api-server/src/routes/routes.ts (7388 lines)", "shortDescription": {"text": "Very large file: artifacts/api-server/src/routes/routes.ts (7388 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6893a6c8b0861585", "name": "Very low test-to-source ratio", "shortDescription": {"text": "Very low test-to-source ratio"}, "fullDescription": {"text": "0 test file(s) for 251 source file(s) (ratio 0.00). Consider adding integration or unit tests for critical paths."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-141b30a41e03817b", "name": "No license file detected", "shortDescription": {"text": "No license file detected"}, "fullDescription": {"text": "No LICENSE/COPYING/NOTICE file was found. Generated repositories often omit licensing, which blocks reuse and automated intake."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-faccb9061e9b52a0", "name": "No README detected", "shortDescription": {"text": "No README detected"}, "fullDescription": {"text": "No README file was found. Generated repos without README context are hard to operate, validate, or safely hand off."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2cc1d1055f9af446", "name": "Node manifest has dependencies but no lockfile: scripts/package.json", "shortDescription": {"text": "Node manifest has dependencies but no lockfile: scripts/package.json"}, "fullDescription": {"text": "`package.json` declares dependencies, but no same-directory npm/pnpm/yarn/bun lockfile was found. Generated projects without lockfiles are less reproducible and harder to secure-scan precisely."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c34cfbe6f531799c", "name": "Node manifest has dependencies but no lockfile: lib/api-spec/package.json", "shortDescription": {"text": "Node manifest has dependencies but no lockfile: lib/api-spec/package.json"}, "fullDescription": {"text": "`package.json` declares dependencies, but no same-directory npm/pnpm/yarn/bun lockfile was found. Generated projects without lockfiles are less reproducible and harder to secure-scan precisely."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 1.0}}, {"id": "scanner-fc09d08ad5b813b9", "name": "Node manifest has dependencies but no lockfile: lib/db/package.json", "shortDescription": {"text": "Node manifest has dependencies but no lockfile: lib/db/package.json"}, "fullDescription": {"text": "`package.json` declares dependencies, but no same-directory npm/pnpm/yarn/bun lockfile was found. Generated projects without lockfiles are less reproducible and harder to secure-scan precisely."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4876ea1389cf2faf", "name": "Node manifest has dependencies but no lockfile: lib/api-zod/package.json", "shortDescription": {"text": "Node manifest has dependencies but no lockfile: lib/api-zod/package.json"}, "fullDescription": {"text": "`package.json` declares dependencies, but no same-directory npm/pnpm/yarn/bun lockfile was found. Generated projects without lockfiles are less reproducible and harder to secure-scan precisely."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 1.0}}, {"id": "scanner-64d389a127f7f14c", "name": "Node manifest has dependencies but no lockfile: lib/api-client-react/package.json", "shortDescription": {"text": "Node manifest has dependencies but no lockfile: lib/api-client-react/package.json"}, "fullDescription": {"text": "`package.json` declares dependencies, but no same-directory npm/pnpm/yarn/bun lockfile was found. Generated projects without lockfiles are less reproducible and harder to secure-scan precisely."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8d4d073a77500fa6", "name": "Node manifest has dependencies but no lockfile: artifacts/pregasquad-manager/package.json", "shortDescription": {"text": "Node manifest has dependencies but no lockfile: artifacts/pregasquad-manager/package.json"}, "fullDescription": {"text": "`package.json` declares dependencies, but no same-directory npm/pnpm/yarn/bun lockfile was found. Generated projects without lockfiles are less reproducible and harder to secure-scan precisely."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 1.0}}, {"id": "scanner-12ffb37512252714", "name": "Node manifest has dependencies but no lockfile: artifacts/api-server/package.json", "shortDescription": {"text": "Node manifest has dependencies but no lockfile: artifacts/api-server/package.json"}, "fullDescription": {"text": "`package.json` declares dependencies, but no same-directory npm/pnpm/yarn/bun lockfile was found. Generated projects without lockfiles are less reproducible and harder to secure-scan precisely."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3ab5d313dda8e5f9", "name": "Debug logging residue appears in source files", "shortDescription": {"text": "Debug logging residue appears in source files"}, "fullDescription": {"text": "Found 298 console/debugger/print-style debug statements in non-test source. This is a common fast-generation residue before production cleanup."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-72b2a6250083a784", "name": "Placeholder or mock-heavy implementation detected", "shortDescription": {"text": "Placeholder or mock-heavy implementation detected"}, "fullDescription": {"text": "Found 118 placeholder/mock markers across 32 source files. This often means the repo looks complete while core flows still use generated scaffolding or fake data."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-9d79c4077342a7d0", "name": "Runtime service client appears to use placeholder configuration", "shortDescription": {"text": "Runtime service client appears to use placeholder configuration"}, "fullDescription": {"text": "A runtime source file appears to wire Supabase/Firebase/AI/payment-style clients to placeholder URLs, keys, or fallback values. In the Fable corpus this often means the UI/API shape is present while the backend service is not actually configured."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-2d0c7b7ab8f8aacf", "name": "Critical user flow still appears backed by mock or placeholder data", "shortDescription": {"text": "Critical user flow still appears backed by mock or placeholder data"}, "fullDescription": {"text": "A payment/auth/admin/order/billing-style flow contains mock, fake, TODO, dummy, or placeholder markers in runtime source. In the Fable corpus this is a high-leverage completeness smell: the app can look finished while the money, identity, or tenant flow is still scaffolded."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b9088664ace7f748", "name": "Composite production-readiness gap", "shortDescription": {"text": "Composite production-readiness gap"}, "fullDescription": {"text": "Multiple low-cost hardening controls are missing together: license, ci, tests, operator-readme, lockfile. Opus verification showed these co-occurring gaps are a better readiness signal than reading each flag in isolation."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-672accf751fc6bfc", "name": "Fire-and-forget `fetch()` has no rejection handler \u2014 artifacts/pregasquad-manager/src/App.tsx:312", "shortDescription": {"text": "Fire-and-forget `fetch()` has no rejection handler \u2014 artifacts/pregasquad-manager/src/App.tsx:312"}, "fullDescription": {"text": "This fetch result is neither awaited, returned, assigned, nor followed by `.catch(...)`. A network failure can therefore become an unhandled promise rejection. Await/return the promise or attach an explicit rejection handler."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-fde86c89f4bc2fb6", "name": "Fire-and-forget `fetch()` has no rejection handler \u2014 artifacts/pregasquad-manager/src/lib/qzPrint.ts:52", "shortDescription": {"text": "Fire-and-forget `fetch()` has no rejection handler \u2014 artifacts/pregasquad-manager/src/lib/qzPrint.ts:52"}, "fullDescription": {"text": "This fetch result is neither awaited, returned, assigned, nor followed by `.catch(...)`. A network failure can therefore become an unhandled promise rejection. Await/return the promise or attach an explicit rejection handler."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-4636dc5108a5af7c", "name": "Fire-and-forget `fetch()` has no rejection handler \u2014 artifacts/pregasquad-manager/src/pages/WhatsApp.tsx:1016", "shortDescription": {"text": "Fire-and-forget `fetch()` has no rejection handler \u2014 artifacts/pregasquad-manager/src/pages/WhatsApp.tsx:1016"}, "fullDescription": {"text": "This fetch result is neither awaited, returned, assigned, nor followed by `.catch(...)`. A network failure can therefore become an unhandled promise rejection. Await/return the promise or attach an explicit rejection handler."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-7ff4f48319566139", "name": "Fire-and-forget `fetch()` has no rejection handler \u2014 artifacts/pregasquad-manager/src/pages/Planning.tsx:757", "shortDescription": {"text": "Fire-and-forget `fetch()` has no rejection handler \u2014 artifacts/pregasquad-manager/src/pages/Planning.tsx:757"}, "fullDescription": {"text": "This fetch result is neither awaited, returned, assigned, nor followed by `.catch(...)`. A network failure can therefore become an unhandled promise rejection. Await/return the promise or attach an explicit rejection handler."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-98809848c4b57e22", "name": "Fire-and-forget `fetch()` has no rejection handler \u2014 artifacts/pregasquad-manager/src/pages/Booking.tsx:140", "shortDescription": {"text": "Fire-and-forget `fetch()` has no rejection handler \u2014 artifacts/pregasquad-manager/src/pages/Booking.tsx:140"}, "fullDescription": {"text": "This fetch result is neither awaited, returned, assigned, nor followed by `.catch(...)`. A network failure can therefore become an unhandled promise rejection. Await/return the promise or attach an explicit rejection handler."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-0d2ddca6e169fabc", "name": "Fire-and-forget `fetch()` has no rejection handler \u2014 artifacts/pregasquad-manager/src/pages/Logs.tsx:109", "shortDescription": {"text": "Fire-and-forget `fetch()` has no rejection handler \u2014 artifacts/pregasquad-manager/src/pages/Logs.tsx:109"}, "fullDescription": {"text": "This fetch result is neither awaited, returned, assigned, nor followed by `.catch(...)`. A network failure can therefore become an unhandled promise rejection. Await/return the promise or attach an explicit rejection handler."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-a9d48ab77a6ee2ea", "name": "Fire-and-forget `fetch()` has no rejection handler \u2014 artifacts/pregasquad-manager/src/pages/Website1.tsx:88", "shortDescription": {"text": "Fire-and-forget `fetch()` has no rejection handler \u2014 artifacts/pregasquad-manager/src/pages/Website1.tsx:88"}, "fullDescription": {"text": "This fetch result is neither awaited, returned, assigned, nor followed by `.catch(...)`. A network failure can therefore become an unhandled promise rejection. Await/return the promise or attach an explicit rejection handler."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-3f655669718d4e68", "name": "Frontend route `/staff-portal/:token` has no Link/navigate to it \u2014 artifacts/pregasquad-manager/src/App.tsx", "shortDescription": {"text": "Frontend route `/staff-portal/:token` has no Link/navigate to it \u2014 artifacts/pregasquad-manager/src/App.tsx"}, "fullDescription": {"text": "The route is registered but no `<Link to=\u2026>` or `navigate(\u2026)` in the codebase navigates here. Either it's reachable only via direct URL (intentional), it's dead, or the link broke during a refactor."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-9169f714ff7b7b1d", "name": "Vulnerable dependency esbuild 0.27.7: GHSA-g7r4-m6w7-qqqr", "shortDescription": {"text": "Vulnerable dependency esbuild 0.27.7: GHSA-g7r4-m6w7-qqqr"}, "fullDescription": {"text": "OSV.dev reports `esbuild` at version `0.27.7` (resolved in `artifacts/mockup-sandbox/package-lock.json`) is affected by GHSA-g7r4-m6w7-qqqr.\n\nesbuild allows arbitrary file read when running the development server on Windows\n\nAdvisory: https://osv.dev/vulnerability/GHSA-g7r4-m6w7-qqqr\nFix: upgrade `esbuild` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 0.9}}, {"id": "scanner-857deb3a99c6ced1", "name": "Vulnerable dependency nanoid 3.3.12: GHSA-28wg-ghj8-5hjv", "shortDescription": {"text": "Vulnerable dependency nanoid 3.3.12: GHSA-28wg-ghj8-5hjv"}, "fullDescription": {"text": "OSV.dev reports `nanoid` at version `3.3.12` (resolved in `artifacts/mockup-sandbox/package-lock.json`) is affected by GHSA-28wg-ghj8-5hjv (aka CVE-2026-67214).\n\nnanoid: non-secure generators can loop indefinitely with negative size\n\nAliases: CVE-2026-67214\nAdvisory: https://osv.dev/vulnerability/GHSA-28wg-ghj8-5hjv\nFix: upgrade `nanoid` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 0.9}}, {"id": "scanner-9484bb7b5b522ccb", "name": "Vulnerable dependency nanoid 3.3.12: GHSA-2v37-7h3g-55p8", "shortDescription": {"text": "Vulnerable dependency nanoid 3.3.12: GHSA-2v37-7h3g-55p8"}, "fullDescription": {"text": "OSV.dev reports `nanoid` at version `3.3.12` (resolved in `artifacts/mockup-sandbox/package-lock.json`) is affected by GHSA-2v37-7h3g-55p8 (aka CVE-2026-67213).\n\nnanoid: custom generators can loop indefinitely when size is zero\n\nAliases: CVE-2026-67213\nAdvisory: https://osv.dev/vulnerability/GHSA-2v37-7h3g-55p8\nFix: upgrade `nanoid` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 0.9}}, {"id": "scanner-2979aecac39eb079", "name": "Vulnerable dependency postcss 8.5.15: GHSA-fxqj-rqcc-2cmp", "shortDescription": {"text": "Vulnerable dependency postcss 8.5.15: GHSA-fxqj-rqcc-2cmp"}, "fullDescription": {"text": "OSV.dev reports `postcss` at version `8.5.15` (resolved in `pnpm-lock.yaml`) is affected by GHSA-fxqj-rqcc-2cmp.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-fxqj-rqcc-2cmp\nFix: upgrade `postcss` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-a71a7d7d7dbd0d2f", "name": "Vulnerable dependency postcss 8.5.15: GHSA-r28c-9q8g-f849", "shortDescription": {"text": "Vulnerable dependency postcss 8.5.15: GHSA-r28c-9q8g-f849"}, "fullDescription": {"text": "OSV.dev reports `postcss` at version `8.5.15` (resolved in `pnpm-lock.yaml`) is affected by GHSA-r28c-9q8g-f849.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-r28c-9q8g-f849\nFix: upgrade `postcss` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-6aa9fbcbb60bed0a", "name": "Vulnerable dependency vite 7.3.3: GHSA-fx2h-pf6j-xcff", "shortDescription": {"text": "Vulnerable dependency vite 7.3.3: GHSA-fx2h-pf6j-xcff"}, "fullDescription": {"text": "OSV.dev reports `vite` at version `7.3.3` (resolved in `artifacts/mockup-sandbox/package-lock.json`) is affected by GHSA-fx2h-pf6j-xcff (aka CVE-2026-53571).\n\nvite: `server.fs.deny` bypass on Windows alternate paths\n\nAliases: CVE-2026-53571\nAdvisory: https://osv.dev/vulnerability/GHSA-fx2h-pf6j-xcff\nFix: upgrade `vite` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 0.9}}, {"id": "scanner-803164d68cf1a938", "name": "Vulnerable dependency vite 7.3.3: GHSA-v6wh-96g9-6wx3", "shortDescription": {"text": "Vulnerable dependency vite 7.3.3: GHSA-v6wh-96g9-6wx3"}, "fullDescription": {"text": "OSV.dev reports `vite` at version `7.3.3` (resolved in `artifacts/mockup-sandbox/package-lock.json`) is affected by GHSA-v6wh-96g9-6wx3.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-v6wh-96g9-6wx3\nFix: upgrade `vite` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-bd723825e360c985", "name": "Vulnerable dependency esbuild 0.27.3: GHSA-g7r4-m6w7-qqqr", "shortDescription": {"text": "Vulnerable dependency esbuild 0.27.3: GHSA-g7r4-m6w7-qqqr"}, "fullDescription": {"text": "OSV.dev reports `esbuild` at version `0.27.3` (resolved in `pnpm-lock.yaml`) is affected by GHSA-g7r4-m6w7-qqqr.\n\nesbuild allows arbitrary file read when running the development server on Windows\n\nAdvisory: https://osv.dev/vulnerability/GHSA-g7r4-m6w7-qqqr\nFix: upgrade `esbuild` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 0.9}}, {"id": "scanner-7cafadac43283f61", "name": "Vulnerable dependency multer 2.1.1: GHSA-3p4h-7m6x-2hcm", "shortDescription": {"text": "Vulnerable dependency multer 2.1.1: GHSA-3p4h-7m6x-2hcm"}, "fullDescription": {"text": "OSV.dev reports `multer` at version `2.1.1` (resolved in `pnpm-lock.yaml`) is affected by GHSA-3p4h-7m6x-2hcm (aka CVE-2026-5038).\n\nMulter vulnerable to Denial of Service via incomplete cleanup of aborted uploads\n\nAliases: CVE-2026-5038\nAdvisory: https://osv.dev/vulnerability/GHSA-3p4h-7m6x-2hcm\nFix: upgrade `multer` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b30c11bb8470aae8", "name": "Vulnerable dependency multer 2.1.1: GHSA-72gw-mp4g-v24j", "shortDescription": {"text": "Vulnerable dependency multer 2.1.1: GHSA-72gw-mp4g-v24j"}, "fullDescription": {"text": "OSV.dev reports `multer` at version `2.1.1` (resolved in `pnpm-lock.yaml`) is affected by GHSA-72gw-mp4g-v24j (aka CVE-2026-5079).\n\nMulter vulnerable to Denial of Service via deeply nested field names\n\nAliases: CVE-2026-5079\nAdvisory: https://osv.dev/vulnerability/GHSA-72gw-mp4g-v24j\nFix: upgrade `multer` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 1.0}}, {"id": "scanner-4ca1329ae57c3c8c", "name": "Vulnerable dependency mysql2 3.22.4: GHSA-rgwj-5xj2-c3m3", "shortDescription": {"text": "Vulnerable dependency mysql2 3.22.4: GHSA-rgwj-5xj2-c3m3"}, "fullDescription": {"text": "OSV.dev reports `mysql2` at version `3.22.4` (resolved in `pnpm-lock.yaml`) is affected by GHSA-rgwj-5xj2-c3m3.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-rgwj-5xj2-c3m3\nFix: upgrade `mysql2` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-bd5046a49b16b8cb", "name": "Vulnerable dependency nanoid 5.1.11: GHSA-28wg-ghj8-5hjv", "shortDescription": {"text": "Vulnerable dependency nanoid 5.1.11: GHSA-28wg-ghj8-5hjv"}, "fullDescription": {"text": "OSV.dev reports `nanoid` at version `5.1.11` (resolved in `pnpm-lock.yaml`) is affected by GHSA-28wg-ghj8-5hjv (aka CVE-2026-67214).\n\nnanoid: non-secure generators can loop indefinitely with negative size\n\nAliases: CVE-2026-67214\nAdvisory: https://osv.dev/vulnerability/GHSA-28wg-ghj8-5hjv\nFix: upgrade `nanoid` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 1.0}}, {"id": "scanner-50a0ccef57d8b8f3", "name": "Vulnerable dependency ws 8.20.1: GHSA-96hv-2xvq-fx4p", "shortDescription": {"text": "Vulnerable dependency ws 8.20.1: GHSA-96hv-2xvq-fx4p"}, "fullDescription": {"text": "OSV.dev reports `ws` at version `8.20.1` (resolved in `pnpm-lock.yaml`) is affected by GHSA-96hv-2xvq-fx4p (aka CVE-2026-48779).\n\nws: Memory exhaustion DoS from tiny fragments and data chunks\n\nAliases: CVE-2026-48779\nAdvisory: https://osv.dev/vulnerability/GHSA-96hv-2xvq-fx4p\nFix: upgrade `ws` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 1.0}}, {"id": "scanner-9ce290f81268f4e5", "name": "Vulnerable dependency @babel/core 7.29.0: GHSA-4x5r-pxfx-6jf8", "shortDescription": {"text": "Vulnerable dependency @babel/core 7.29.0: GHSA-4x5r-pxfx-6jf8"}, "fullDescription": {"text": "OSV.dev reports `@babel/core` at version `7.29.0` (resolved in `artifacts/mockup-sandbox/package-lock.json`) is affected by GHSA-4x5r-pxfx-6jf8 (aka CVE-2026-49356).\nNote: `@babel/core` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\n@babel/core: Arbitrary File Read via sourceMappingURL Comment\n\nAliases: CVE-2026-49356\nAdvisory: https://osv.dev/vulnerability/GHSA-4x5r-pxfx-6jf8\nFix: upgrade `@babel/core` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 0.9}}, {"id": "scanner-9614dd79a5c65dac", "name": "Dependency @google-cloud/storage is a major version behind", "shortDescription": {"text": "Dependency @google-cloud/storage is a major version behind"}, "fullDescription": {"text": "`@google-cloud/storage` is pinned at `7.19.0` in `artifacts/api-server/package.json` while the latest release on the npm registry is `8.0.1` \u2014 1 major version(s) behind. Old majors stop receiving security backports and accumulate known CVEs. Review the upstream changelog / migration guide and upgrade `@google-cloud/storage` to `8.0.1`."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 0.9}}, {"id": "scanner-afd1fe5046bc0607", "name": "Dependency date-fns is a major version behind", "shortDescription": {"text": "Dependency date-fns is a major version behind"}, "fullDescription": {"text": "`date-fns` is pinned at `3.6.0` in `artifacts/api-server/package.json` while the latest release on the npm registry is `4.4.0` \u2014 1 major version(s) behind. Old majors stop receiving security backports and accumulate known CVEs. Review the upstream changelog / migration guide and upgrade `date-fns` to `4.4.0`."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 0.9}}, {"id": "scanner-747ce365c4150d64", "name": "Dependency nanoid is a major version behind", "shortDescription": {"text": "Dependency nanoid is a major version behind"}, "fullDescription": {"text": "`nanoid` is pinned at `5.1.11` in `artifacts/api-server/package.json` while the latest release on the npm registry is `6.0.1` \u2014 1 major version(s) behind. Old majors stop receiving security backports and accumulate known CVEs. Review the upstream changelog / migration guide and upgrade `nanoid` to `6.0.1`."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 0.9}}, {"id": "scanner-8401c240841914fc", "name": "Dependency pino-http is a major version behind", "shortDescription": {"text": "Dependency pino-http is a major version behind"}, "fullDescription": {"text": "`pino-http` is pinned at `10.5.0` in `artifacts/api-server/package.json` while the latest release on the npm registry is `11.0.0` \u2014 1 major version(s) behind. Old majors stop receiving security backports and accumulate known CVEs. Review the upstream changelog / migration guide and upgrade `pino-http` to `11.0.0`."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 0.9}}, {"id": "scanner-8261eac145992d6c", "name": "Dependency pino is a major version behind", "shortDescription": {"text": "Dependency pino is a major version behind"}, "fullDescription": {"text": "`pino` is pinned at `9.14.0` in `artifacts/api-server/package.json` while the latest release on the npm registry is `10.3.1` \u2014 1 major version(s) behind. Old majors stop receiving security backports and accumulate known CVEs. Review the upstream changelog / migration guide and upgrade `pino` to `10.3.1`."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 0.9}}, {"id": "scanner-28bcd8de999454c2", "name": "Dangling fetch: GET /api/export/${type} (artifacts/pregasquad-manager/src/pages/AdminSettings.tsx:531)", "shortDescription": {"text": "Dangling fetch: GET /api/export/${type} (artifacts/pregasquad-manager/src/pages/AdminSettings.tsx:531)"}, "fullDescription": {"text": "`artifacts/pregasquad-manager/src/pages/AdminSettings.tsx:531` calls `GET /api/export/${type}` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/export/<p>`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-a78ff2da1b49b4aa", "name": "Dangling fetch: GET /api/notifications/broadcast/last (artifacts/pregasquad-manager/src/pages/WhatsApp.tsx:1025)", "shortDescription": {"text": "Dangling fetch: GET /api/notifications/broadcast/last (artifacts/pregasquad-manager/src/pages/WhatsApp.tsx:1025)"}, "fullDescription": {"text": "`artifacts/pregasquad-manager/src/pages/WhatsApp.tsx:1025` calls `GET /api/notifications/broadcast/last` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/notifications/broadcast/last`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-bf703dd27600eed2", "name": "Dangling fetch: PUT /api/appointments/${id} (artifacts/pregasquad-manager/src/pages/BookingHistory.tsx:92)", "shortDescription": {"text": "Dangling fetch: PUT /api/appointments/${id} (artifacts/pregasquad-manager/src/pages/BookingHistory.tsx:92)"}, "fullDescription": {"text": "`artifacts/pregasquad-manager/src/pages/BookingHistory.tsx:92` calls `PUT /api/appointments/${id}` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/appointments/<p>`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-ed48be944fb57876", "name": "Dangling fetch: POST /api/appointments (artifacts/pregasquad-manager/src/pages/BookingHistory.tsx:108)", "shortDescription": {"text": "Dangling fetch: POST /api/appointments (artifacts/pregasquad-manager/src/pages/BookingHistory.tsx:108)"}, "fullDescription": {"text": "`artifacts/pregasquad-manager/src/pages/BookingHistory.tsx:108` calls `POST /api/appointments` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/appointments`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-bde11d5593469fad", "name": "Dangling fetch: DELETE /api/appointments/${id} (artifacts/pregasquad-manager/src/pages/BookingHistory.tsx:131)", "shortDescription": {"text": "Dangling fetch: DELETE /api/appointments/${id} (artifacts/pregasquad-manager/src/pages/BookingHistory.tsx:131)"}, "fullDescription": {"text": "`artifacts/pregasquad-manager/src/pages/BookingHistory.tsx:131` calls `DELETE /api/appointments/${id}` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/appointments/<p>`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-926824cd381e9d40", "name": "Dangling fetch: POST /api/appointments (artifacts/pregasquad-manager/src/pages/Clients.tsx:264)", "shortDescription": {"text": "Dangling fetch: POST /api/appointments (artifacts/pregasquad-manager/src/pages/Clients.tsx:264)"}, "fullDescription": {"text": "`artifacts/pregasquad-manager/src/pages/Clients.tsx:264` calls `POST /api/appointments` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/appointments`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-576dfb4153565f90", "name": "Dangling fetch: POST /api/appointments (artifacts/pregasquad-manager/src/pages/POS.tsx:195)", "shortDescription": {"text": "Dangling fetch: POST /api/appointments (artifacts/pregasquad-manager/src/pages/POS.tsx:195)"}, "fullDescription": {"text": "`artifacts/pregasquad-manager/src/pages/POS.tsx:195` calls `POST /api/appointments` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/appointments`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-b05683ef40d20d3d", "name": "146 backend endpoints not called by scanned frontend", "shortDescription": {"text": "146 backend endpoints not called by scanned frontend"}, "fullDescription": {"text": "No scanned frontend call matched these backend routes. Sample: USE /uploads, GET /logs/stream, GET /api/logs, GET /api/logs/stream, GET /api/public/page-views, POST /api/public/page-views, GET /api/public/website-testimonials, GET /api/website-testimonials + 138 more. This is fine when endpoints serve external clients (mobile apps, SDKs, third-party integrations, server-side webhooks). Otherwise document consumers or remove dead routes."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}]}}, "automationDetails": {"id": "repobility/30822"}, "properties": {"repository": "pregasquad/PREGA", "repoUrl": "https://github.com/pregasquad/PREGA", "branch": "main"}, "results": [{"ruleId": "scanner-401215081ff3098f", "level": "note", "message": {"text": "Debug `console.log` remains in browser-facing code \u2014 artifacts/pregasquad-manager/src/main.tsx:20"}, "properties": {"repobilityId": "f2226e334b391c94", "scanner": "scanner-primary", "fingerprint": "401215081ff3098f", "layer": "frontend", "severity": "low", "confidence": 0.85, "tags": ["frontend-quality", "fq.console-leak"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "artifacts/pregasquad-manager/src/main.tsx"}, "region": {"startLine": 20}}}]}, {"ruleId": "scanner-8a918d1607d8ed0f", "level": "none", "message": {"text": "Truncated text has no discoverable full-value affordance \u2014 artifacts/pregasquad-manager/src/components/GlobalSearch.tsx:127"}, "properties": {"repobilityId": "8eb2c6c84f40aaec", "scanner": "scanner-primary", "fingerprint": "8a918d1607d8ed0f", "layer": "frontend", "severity": "info", "confidence": 0.65, "tags": ["frontend-quality", "fq.truncate.no-title"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "artifacts/pregasquad-manager/src/components/GlobalSearch.tsx"}, "region": {"startLine": 127}}}]}, {"ruleId": "scanner-44c3fe3ca2def34c", "level": "none", "message": {"text": "Truncated text has no discoverable full-value affordance \u2014 artifacts/pregasquad-manager/src/components/ServiceRecommendations.tsx:112"}, "properties": {"repobilityId": "7a2942881b58ab9f", "scanner": "scanner-primary", "fingerprint": "44c3fe3ca2def34c", "layer": "frontend", "severity": "info", "confidence": 0.65, "tags": ["frontend-quality", "fq.truncate.no-title"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "artifacts/pregasquad-manager/src/components/ServiceRecommendations.tsx"}, "region": {"startLine": 112}}}]}, {"ruleId": "scanner-83496ea7438f8772", "level": "note", "message": {"text": "Debug `console.log` remains in browser-facing code \u2014 artifacts/pregasquad-manager/src/components/PushNotifications.tsx:48"}, "properties": {"repobilityId": "36b070b442f9e83b", "scanner": "scanner-primary", "fingerprint": "83496ea7438f8772", "layer": "frontend", "severity": "low", "confidence": 0.85, "tags": ["frontend-quality", "fq.console-leak"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "artifacts/pregasquad-manager/src/components/PushNotifications.tsx"}, "region": {"startLine": 48}}}]}, {"ruleId": "scanner-854eec80b29c2779", "level": "none", "message": {"text": "Truncated text has no discoverable full-value affordance \u2014 artifacts/pregasquad-manager/src/components/layout/BottomNav.tsx:331"}, "properties": {"repobilityId": "f06dd95b3e37c043", "scanner": "scanner-primary", "fingerprint": "854eec80b29c2779", "layer": "frontend", "severity": "info", "confidence": 0.65, "tags": ["frontend-quality", "fq.truncate.no-title"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "artifacts/pregasquad-manager/src/components/layout/BottomNav.tsx"}, "region": {"startLine": 331}}}]}, {"ruleId": "scanner-452f1d42c3a0c04c", "level": "none", "message": {"text": "Truncated text has no discoverable full-value affordance \u2014 artifacts/pregasquad-manager/src/components/layout/Sidebar.tsx:413"}, "properties": {"repobilityId": "874e80468fc1e461", "scanner": "scanner-primary", "fingerprint": "452f1d42c3a0c04c", "layer": "frontend", "severity": "info", "confidence": 0.65, "tags": ["frontend-quality", "fq.truncate.no-title"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "artifacts/pregasquad-manager/src/components/layout/Sidebar.tsx"}, "region": {"startLine": 413}}}]}, {"ruleId": "scanner-9b50c99d3d6a0d9e", "level": "note", "message": {"text": "Debug `console.log` remains in browser-facing code \u2014 artifacts/pregasquad-manager/src/components/layout/Sidebar.tsx:185"}, "properties": {"repobilityId": "978249ba99ff0205", "scanner": "scanner-primary", "fingerprint": "9b50c99d3d6a0d9e", "layer": "frontend", "severity": "low", "confidence": 0.85, "tags": ["frontend-quality", "fq.console-leak"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "artifacts/pregasquad-manager/src/components/layout/Sidebar.tsx"}, "region": {"startLine": 185}}}]}, {"ruleId": "scanner-7a4b9fa3039828b6", "level": "warning", "message": {"text": "`dangerouslySetInnerHTML` used in a React component \u2014 artifacts/pregasquad-manager/src/components/ui/chart.tsx:81"}, "properties": {"repobilityId": "21a09d34a17c755f", "scanner": "scanner-primary", "fingerprint": "7a4b9fa3039828b6", "layer": "frontend", "severity": "medium", "confidence": 0.8, "tags": ["frontend-quality", "fq.dangerous-html"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "artifacts/pregasquad-manager/src/components/ui/chart.tsx"}, "region": {"startLine": 81}}}]}, {"ruleId": "scanner-1c22a9c89fb05def", "level": "note", "message": {"text": "Debug `console.log` remains in browser-facing code \u2014 artifacts/pregasquad-manager/src/lib/qzPrint.ts:13"}, "properties": {"repobilityId": "666a95f9a56baf55", "scanner": "scanner-primary", "fingerprint": "1c22a9c89fb05def", "layer": "frontend", "severity": "low", "confidence": 0.85, "tags": ["frontend-quality", "fq.console-leak"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "artifacts/pregasquad-manager/src/lib/qzPrint.ts"}, "region": {"startLine": 13}}}]}, {"ruleId": "scanner-a66df0e2bf117c3b", "level": "note", "message": {"text": "Debug `console.log` remains in browser-facing code \u2014 artifacts/pregasquad-manager/src/lib/queryClient.ts:144"}, "properties": {"repobilityId": "cba36383b52c0b01", "scanner": "scanner-primary", "fingerprint": "a66df0e2bf117c3b", "layer": "frontend", "severity": "low", "confidence": 0.85, "tags": ["frontend-quality", "fq.console-leak"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "artifacts/pregasquad-manager/src/lib/queryClient.ts"}, "region": {"startLine": 144}}}]}, {"ruleId": "scanner-5552cefcf8a546c7", "level": "note", "message": {"text": "Debug `console.log` remains in browser-facing code \u2014 artifacts/pregasquad-manager/src/lib/syncService.ts:149"}, "properties": {"repobilityId": "a6d59f655b9fc574", "scanner": "scanner-primary", "fingerprint": "5552cefcf8a546c7", "layer": "frontend", "severity": "low", "confidence": 0.85, "tags": ["frontend-quality", "fq.console-leak"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "artifacts/pregasquad-manager/src/lib/syncService.ts"}, "region": {"startLine": 149}}}]}, {"ruleId": "scanner-b16f35fd04438a69", "level": "none", "message": {"text": "Truncated text has no discoverable full-value affordance \u2014 artifacts/pregasquad-manager/src/pages/Services.tsx:324"}, "properties": {"repobilityId": "f725d1343d595f0b", "scanner": "scanner-primary", "fingerprint": "b16f35fd04438a69", "layer": "frontend", "severity": "info", "confidence": 0.65, "tags": ["frontend-quality", "fq.truncate.no-title"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "artifacts/pregasquad-manager/src/pages/Services.tsx"}, "region": {"startLine": 324}}}]}, {"ruleId": "scanner-790fc5d52de89fcb", "level": "none", "message": {"text": "Truncated text has no discoverable full-value affordance \u2014 artifacts/pregasquad-manager/src/pages/StaffPerformance.tsx:490"}, "properties": {"repobilityId": "fa00a6c73bba11fb", "scanner": "scanner-primary", "fingerprint": "790fc5d52de89fcb", "layer": "frontend", "severity": "info", "confidence": 0.65, "tags": ["frontend-quality", "fq.truncate.no-title"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "artifacts/pregasquad-manager/src/pages/StaffPerformance.tsx"}, "region": {"startLine": 490}}}]}, {"ruleId": "scanner-bf827ac710a93a28", "level": "none", "message": {"text": "Truncated text has no discoverable full-value affordance \u2014 artifacts/pregasquad-manager/src/pages/AdminSettings.tsx:150"}, "properties": {"repobilityId": "bab87007848ce8ab", "scanner": "scanner-primary", "fingerprint": "bf827ac710a93a28", "layer": "frontend", "severity": "info", "confidence": 0.65, "tags": ["frontend-quality", "fq.truncate.no-title"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "artifacts/pregasquad-manager/src/pages/AdminSettings.tsx"}, "region": {"startLine": 150}}}]}, {"ruleId": "scanner-85a978b358941902", "level": "none", "message": {"text": "Truncated text has no discoverable full-value affordance \u2014 artifacts/pregasquad-manager/src/pages/Salaries.tsx:1059"}, "properties": {"repobilityId": "2537932526bba44d", "scanner": "scanner-primary", "fingerprint": "85a978b358941902", "layer": "frontend", "severity": "info", "confidence": 0.65, "tags": ["frontend-quality", "fq.truncate.no-title"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "artifacts/pregasquad-manager/src/pages/Salaries.tsx"}, "region": {"startLine": 1059}}}]}, {"ruleId": "scanner-862031268a039f5c", "level": "none", "message": {"text": "Truncated text has no discoverable full-value affordance \u2014 artifacts/pregasquad-manager/src/pages/WhatsApp.tsx:1144"}, "properties": {"repobilityId": "5597fe01f2488ce5", "scanner": "scanner-primary", "fingerprint": "862031268a039f5c", "layer": "frontend", "severity": "info", "confidence": 0.65, "tags": ["frontend-quality", "fq.truncate.no-title"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "artifacts/pregasquad-manager/src/pages/WhatsApp.tsx"}, "region": {"startLine": 1144}}}]}, {"ruleId": "scanner-941a30c5b41d1dc8", "level": "none", "message": {"text": "Truncated text has no discoverable full-value affordance \u2014 artifacts/pregasquad-manager/src/pages/BookingHistory.tsx:497"}, "properties": {"repobilityId": "b4dfbe5ffc4d6612", "scanner": "scanner-primary", "fingerprint": "941a30c5b41d1dc8", "layer": "frontend", "severity": "info", "confidence": 0.65, "tags": ["frontend-quality", "fq.truncate.no-title"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "artifacts/pregasquad-manager/src/pages/BookingHistory.tsx"}, "region": {"startLine": 497}}}]}, {"ruleId": "scanner-a4560e52955bb091", "level": "none", "message": {"text": "Truncated text has no discoverable full-value affordance \u2014 artifacts/pregasquad-manager/src/pages/Clients.tsx:709"}, "properties": {"repobilityId": "ce1295af4aa7e5aa", "scanner": "scanner-primary", "fingerprint": "a4560e52955bb091", "layer": "frontend", "severity": "info", "confidence": 0.65, "tags": ["frontend-quality", "fq.truncate.no-title"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "artifacts/pregasquad-manager/src/pages/Clients.tsx"}, "region": {"startLine": 709}}}]}, {"ruleId": "scanner-b06db29af3df354d", "level": "none", "message": {"text": "Truncated text has no discoverable full-value affordance \u2014 artifacts/pregasquad-manager/src/pages/Charges.tsx:777"}, "properties": {"repobilityId": "3d7d1bc373085327", "scanner": "scanner-primary", "fingerprint": "b06db29af3df354d", "layer": "frontend", "severity": "info", "confidence": 0.65, "tags": ["frontend-quality", "fq.truncate.no-title"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "artifacts/pregasquad-manager/src/pages/Charges.tsx"}, "region": {"startLine": 777}}}]}, {"ruleId": "scanner-2c000fde0e374262", "level": "none", "message": {"text": "Truncated text has no discoverable full-value affordance \u2014 artifacts/pregasquad-manager/src/pages/Planning.tsx:230"}, "properties": {"repobilityId": "b8cd5075e358b68c", "scanner": "scanner-primary", "fingerprint": "2c000fde0e374262", "layer": "frontend", "severity": "info", "confidence": 0.65, "tags": ["frontend-quality", "fq.truncate.no-title"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "artifacts/pregasquad-manager/src/pages/Planning.tsx"}, "region": {"startLine": 230}}}]}, {"ruleId": "scanner-8389b3861444e72a", "level": "none", "message": {"text": "Truncated text has no discoverable full-value affordance \u2014 artifacts/pregasquad-manager/src/pages/StaffPortal.tsx:215"}, "properties": {"repobilityId": "a1892ee1655cd38c", "scanner": "scanner-primary", "fingerprint": "8389b3861444e72a", "layer": "frontend", "severity": "info", "confidence": 0.65, "tags": ["frontend-quality", "fq.truncate.no-title"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "artifacts/pregasquad-manager/src/pages/StaffPortal.tsx"}, "region": {"startLine": 215}}}]}, {"ruleId": "scanner-c0a4dca8d8cb1c96", "level": "none", "message": {"text": "Truncated text has no discoverable full-value affordance \u2014 artifacts/pregasquad-manager/src/pages/Staff.tsx:677"}, "properties": {"repobilityId": "ad9474253c858011", "scanner": "scanner-primary", "fingerprint": "c0a4dca8d8cb1c96", "layer": "frontend", "severity": "info", "confidence": 0.65, "tags": ["frontend-quality", "fq.truncate.no-title"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "artifacts/pregasquad-manager/src/pages/Staff.tsx"}, "region": {"startLine": 677}}}]}, {"ruleId": "scanner-bf2120a0dc582006", "level": "none", "message": {"text": "Truncated text has no discoverable full-value affordance \u2014 artifacts/pregasquad-manager/src/pages/POS.tsx:367"}, "properties": {"repobilityId": "b684f3be41f1f9c4", "scanner": "scanner-primary", "fingerprint": "bf2120a0dc582006", "layer": "frontend", "severity": "info", "confidence": 0.65, "tags": ["frontend-quality", "fq.truncate.no-title"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "artifacts/pregasquad-manager/src/pages/POS.tsx"}, "region": {"startLine": 367}}}]}, {"ruleId": "scanner-e97daf58d73ca27b", "level": "none", "message": {"text": "Truncated text has no discoverable full-value affordance \u2014 artifacts/pregasquad-manager/src/pages/Home.tsx:190"}, "properties": {"repobilityId": "136ebd2fd6f23a6e", "scanner": "scanner-primary", "fingerprint": "e97daf58d73ca27b", "layer": "frontend", "severity": "info", "confidence": 0.65, "tags": ["frontend-quality", "fq.truncate.no-title"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "artifacts/pregasquad-manager/src/pages/Home.tsx"}, "region": {"startLine": 190}}}]}, {"ruleId": "scanner-92559aaae451c545", "level": "none", "message": {"text": "Truncated text has no discoverable full-value affordance \u2014 artifacts/pregasquad-manager/src/pages/MyBookings.tsx:429"}, "properties": {"repobilityId": "39347ed1e6aae54f", "scanner": "scanner-primary", "fingerprint": "92559aaae451c545", "layer": "frontend", "severity": "info", "confidence": 0.65, "tags": ["frontend-quality", "fq.truncate.no-title"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "artifacts/pregasquad-manager/src/pages/MyBookings.tsx"}, "region": {"startLine": 429}}}]}, {"ruleId": "scanner-ba2b5c25bd90752b", "level": "none", "message": {"text": "Truncated text has no discoverable full-value affordance \u2014 artifacts/pregasquad-manager/src/pages/Reports.tsx:792"}, "properties": {"repobilityId": "eff06523e2c1141c", "scanner": "scanner-primary", "fingerprint": "ba2b5c25bd90752b", "layer": "frontend", "severity": "info", "confidence": 0.65, "tags": ["frontend-quality", "fq.truncate.no-title"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "artifacts/pregasquad-manager/src/pages/Reports.tsx"}, "region": {"startLine": 792}}}]}, {"ruleId": "scanner-99859ea00b66de04", "level": "note", "message": {"text": "Debug `console.log` remains in browser-facing code \u2014 artifacts/pregasquad-manager/src/hooks/use-salon-data.ts:51"}, "properties": {"repobilityId": "e4f98852582c092d", "scanner": "scanner-primary", "fingerprint": "99859ea00b66de04", "layer": "frontend", "severity": "low", "confidence": 0.85, "tags": ["frontend-quality", "fq.console-leak"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "artifacts/pregasquad-manager/src/hooks/use-salon-data.ts"}, "region": {"startLine": 51}}}]}, {"ruleId": "scanner-0416a48934a0f560", "level": "warning", "message": {"text": "`dangerouslySetInnerHTML` used in a React component \u2014 artifacts/mockup-sandbox/src/components/ui/chart.tsx:79"}, "properties": {"repobilityId": "5e73f33ec5db7797", "scanner": "scanner-primary", "fingerprint": "0416a48934a0f560", "layer": "frontend", "severity": "medium", "confidence": 0.8, "tags": ["frontend-quality", "fq.dangerous-html"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "artifacts/mockup-sandbox/src/components/ui/chart.tsx"}, "region": {"startLine": 79}}}]}, {"ruleId": "scanner-02482d7c6ffd044e", "level": "none", "message": {"text": "Truncated text has no discoverable full-value affordance \u2014 artifacts/mockup-sandbox/src/components/mockups/appointment-dialog/SoftRoseLuxury.tsx:105"}, "properties": {"repobilityId": "6d53fd354fe08191", "scanner": "scanner-primary", "fingerprint": "02482d7c6ffd044e", "layer": "frontend", "severity": "info", "confidence": 0.65, "tags": ["frontend-quality", "fq.truncate.no-title"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "artifacts/mockup-sandbox/src/components/mockups/appointment-dialog/SoftRoseLuxury.tsx"}, "region": {"startLine": 105}}}]}, {"ruleId": "scanner-2927d1589dd71f0d", "level": "none", "message": {"text": "Truncated text has no discoverable full-value affordance \u2014 artifacts/mockup-sandbox/src/components/mockups/charges/GlassWater.tsx:362"}, "properties": {"repobilityId": "e9d7cb0967465a94", "scanner": "scanner-primary", "fingerprint": "2927d1589dd71f0d", "layer": "frontend", "severity": "info", "confidence": 0.65, "tags": ["frontend-quality", "fq.truncate.no-title"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "artifacts/mockup-sandbox/src/components/mockups/charges/GlassWater.tsx"}, "region": {"startLine": 362}}}]}, {"ruleId": "scanner-4f765ae778431dec", "level": "error", "message": {"text": "react insecure request \u2014 .migration-backup/server/replit_integrations/object_storage/objectStorage.ts:280"}, "properties": {"repobilityId": "801ce51603d14ed2", "scanner": "scanner-primary", "fingerprint": "4f765ae778431dec", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["semgrep", "security", "react"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".migration-backup/server/replit_integrations/object_storage/objectStorage.ts"}, "region": {"startLine": 280}}}]}, {"ruleId": "scanner-b4fe1f6cd3164883", "level": "error", "message": {"text": "react insecure request \u2014 artifacts/api-server/src/replit_integrations/object_storage/objectStorage.ts:280"}, "properties": {"repobilityId": "ae3a6313e3b88b98", "scanner": "scanner-primary", "fingerprint": "b4fe1f6cd3164883", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["semgrep", "security", "react"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "artifacts/api-server/src/replit_integrations/object_storage/objectStorage.ts"}, "region": {"startLine": 280}}}]}, {"ruleId": "scanner-c6c38f15b5b6e7b5", "level": "note", "message": {"text": "CVE-2026-49356: @babel/core 7.28.5 \u2014 .migration-backup/package-lock.json"}, "properties": {"repobilityId": "3a415c726e9d6cc7", "scanner": "scanner-primary", "fingerprint": "c6c38f15b5b6e7b5", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-49356"]}}, {"ruleId": "scanner-243b608fd15dc34f", "level": "error", "message": {"text": "CVE-2026-44728: @babel/plugin-transform-modules-systemjs 7.28.5 \u2014 .migration-backup/package-lock.json"}, "properties": {"repobilityId": "b43976ef2f3828b7", "scanner": "scanner-primary", "fingerprint": "243b608fd15dc34f", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44728"]}}, {"ruleId": "scanner-b3dd3ee231a565ba", "level": "error", "message": {"text": "CVE-2026-25547: @isaacs/brace-expansion 5.0.0 \u2014 .migration-backup/package-lock.json"}, "properties": {"repobilityId": "ce2c3d7717954b33", "scanner": "scanner-primary", "fingerprint": "b3dd3ee231a565ba", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-25547"]}}, {"ruleId": "scanner-3ebddbcdf2d43bf3", "level": "note", "message": {"text": "CVE-2026-3449: @tootallnate/once 2.0.0 \u2014 .migration-backup/package-lock.json"}, "properties": {"repobilityId": "4772dfbc4c1b4b49", "scanner": "scanner-primary", "fingerprint": "3ebddbcdf2d43bf3", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-3449"]}}, {"ruleId": "scanner-45f864647e7bdd6b", "level": "error", "message": {"text": "CVE-2026-48063: @whiskeysockets/baileys 7.0.0-rc.9 \u2014 .migration-backup/package-lock.json"}, "properties": {"repobilityId": "6123bd6d3f79c206", "scanner": "scanner-primary", "fingerprint": "45f864647e7bdd6b", "layer": "security", "severity": "critical", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-48063"]}}, {"ruleId": "scanner-09f0c1b4ec446233", "level": "error", "message": {"text": "CVE-2026-34601: @xmldom/xmldom 0.8.11 \u2014 .migration-backup/package-lock.json"}, "properties": {"repobilityId": "c28487a6159a3aff", "scanner": "scanner-primary", "fingerprint": "09f0c1b4ec446233", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-34601"]}}, {"ruleId": "scanner-85c657f0396a33a3", "level": "error", "message": {"text": "CVE-2026-41672: @xmldom/xmldom 0.8.11 \u2014 .migration-backup/package-lock.json"}, "properties": {"repobilityId": "1d91400fb14fbfba", "scanner": "scanner-primary", "fingerprint": "85c657f0396a33a3", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-41672"]}}, {"ruleId": "scanner-0426ac768c965ab7", "level": "error", "message": {"text": "CVE-2026-41673: @xmldom/xmldom 0.8.11 \u2014 .migration-backup/package-lock.json"}, "properties": {"repobilityId": "179db6b171d92eeb", "scanner": "scanner-primary", "fingerprint": "0426ac768c965ab7", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-41673"]}}, {"ruleId": "scanner-f17131c5c6eb8788", "level": "error", "message": {"text": "CVE-2026-41674: @xmldom/xmldom 0.8.11 \u2014 .migration-backup/package-lock.json"}, "properties": {"repobilityId": "58aad3c9c072763c", "scanner": "scanner-primary", "fingerprint": "f17131c5c6eb8788", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-41674"]}}, {"ruleId": "scanner-d7a1daec34fe551d", "level": "error", "message": {"text": "CVE-2026-41675: @xmldom/xmldom 0.8.11 \u2014 .migration-backup/package-lock.json"}, "properties": {"repobilityId": "68d77c5b091ddfa3", "scanner": "scanner-primary", "fingerprint": "d7a1daec34fe551d", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-41675"]}}, {"ruleId": "scanner-8165fb42f4e4865e", "level": "warning", "message": {"text": "CVE-2025-69873: ajv 8.17.1 \u2014 .migration-backup/package-lock.json"}, "properties": {"repobilityId": "0257bb8e409917e8", "scanner": "scanner-primary", "fingerprint": "8165fb42f4e4865e", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-69873"]}}, {"ruleId": "scanner-a618b02681693506", "level": "error", "message": {"text": "CVE-2026-25639: axios 1.13.2 \u2014 .migration-backup/package-lock.json"}, "properties": {"repobilityId": "9421ec8c2d9b497a", "scanner": "scanner-primary", "fingerprint": "a618b02681693506", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-25639"]}}, {"ruleId": "scanner-ab9c5d9bd2e0af69", "level": "error", "message": {"text": "CVE-2026-42033: axios 1.13.2 \u2014 .migration-backup/package-lock.json"}, "properties": {"repobilityId": "0e97413396476ffd", "scanner": "scanner-primary", "fingerprint": "ab9c5d9bd2e0af69", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-42033"]}}, {"ruleId": "scanner-4f3c06f7a72b2b2d", "level": "error", "message": {"text": "CVE-2026-42035: axios 1.13.2 \u2014 .migration-backup/package-lock.json"}, "properties": {"repobilityId": "27a394da77aa6297", "scanner": "scanner-primary", "fingerprint": "4f3c06f7a72b2b2d", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-42035"]}}, {"ruleId": "scanner-513f5fff3af09297", "level": "error", "message": {"text": "CVE-2026-42043: axios 1.13.2 \u2014 .migration-backup/package-lock.json"}, "properties": {"repobilityId": "038e97d922b3fe3e", "scanner": "scanner-primary", "fingerprint": "513f5fff3af09297", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-42043"]}}, {"ruleId": "scanner-2e247d7abfd33a26", "level": "error", "message": {"text": "CVE-2026-42264: axios 1.13.2 \u2014 .migration-backup/package-lock.json"}, "properties": {"repobilityId": "82d21962ca40e99d", "scanner": "scanner-primary", "fingerprint": "2e247d7abfd33a26", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-42264"]}}, {"ruleId": "scanner-19e173bfdef24743", "level": "error", "message": {"text": "CVE-2026-44486: axios 1.13.2 \u2014 .migration-backup/package-lock.json"}, "properties": {"repobilityId": "1279b2e813cdfb33", "scanner": "scanner-primary", "fingerprint": "19e173bfdef24743", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44486"]}}, {"ruleId": "scanner-756f54d231cb9b76", "level": "error", "message": {"text": "CVE-2026-44487: axios 1.13.2 \u2014 .migration-backup/package-lock.json"}, "properties": {"repobilityId": "0295308f8b122442", "scanner": "scanner-primary", "fingerprint": "756f54d231cb9b76", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44487"]}}, {"ruleId": "scanner-c7fe83d58fe64294", "level": "error", "message": {"text": "CVE-2026-44488: axios 1.13.2 \u2014 .migration-backup/package-lock.json"}, "properties": {"repobilityId": "93d6305ca5814fb6", "scanner": "scanner-primary", "fingerprint": "c7fe83d58fe64294", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44488"]}}, {"ruleId": "scanner-627a9eec7dc4855f", "level": "error", "message": {"text": "CVE-2026-44494: axios 1.13.2 \u2014 .migration-backup/package-lock.json"}, "properties": {"repobilityId": "c0cfd6e719cd0072", "scanner": "scanner-primary", "fingerprint": "627a9eec7dc4855f", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44494"]}}, {"ruleId": "scanner-d4e02ed22235f31b", "level": "error", "message": {"text": "CVE-2026-44495: axios 1.13.2 \u2014 .migration-backup/package-lock.json"}, "properties": {"repobilityId": "42757f2cd0578a03", "scanner": "scanner-primary", "fingerprint": "d4e02ed22235f31b", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44495"]}}, {"ruleId": "scanner-497b05574f32e2f1", "level": "error", "message": {"text": "CVE-2026-44496: axios 1.13.2 \u2014 .migration-backup/package-lock.json"}, "properties": {"repobilityId": "481ab0a2d3ba58f8", "scanner": "scanner-primary", "fingerprint": "497b05574f32e2f1", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44496"]}}, {"ruleId": "scanner-a0edcfccff66eedf", "level": "warning", "message": {"text": "CVE-2025-62718: axios 1.13.2 \u2014 .migration-backup/package-lock.json"}, "properties": {"repobilityId": "247793b26a147791", "scanner": "scanner-primary", "fingerprint": "a0edcfccff66eedf", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-62718"]}}, {"ruleId": "scanner-122a3ac56316b0f6", "level": "warning", "message": {"text": "CVE-2026-40175: axios 1.13.2 \u2014 .migration-backup/package-lock.json"}, "properties": {"repobilityId": "422eec8aa7eadf69", "scanner": "scanner-primary", "fingerprint": "122a3ac56316b0f6", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-40175"]}}, {"ruleId": "scanner-e53212f9f7a81b44", "level": "warning", "message": {"text": "CVE-2026-42034: axios 1.13.2 \u2014 .migration-backup/package-lock.json"}, "properties": {"repobilityId": "a712c748b6c9de2f", "scanner": "scanner-primary", "fingerprint": "e53212f9f7a81b44", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-42034"]}}, {"ruleId": "scanner-a7b8751ef3ac9afe", "level": "warning", "message": {"text": "CVE-2026-42036: axios 1.13.2 \u2014 .migration-backup/package-lock.json"}, "properties": {"repobilityId": "8a8543cf5be8edb7", "scanner": "scanner-primary", "fingerprint": "a7b8751ef3ac9afe", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-42036"]}}, {"ruleId": "scanner-b44965bb351b6428", "level": "warning", "message": {"text": "CVE-2026-42037: axios 1.13.2 \u2014 .migration-backup/package-lock.json"}, "properties": {"repobilityId": "7a64179dd49d0245", "scanner": "scanner-primary", "fingerprint": "b44965bb351b6428", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-42037"]}}, {"ruleId": "scanner-0f9337daebe843cd", "level": "warning", "message": {"text": "CVE-2026-42038: axios 1.13.2 \u2014 .migration-backup/package-lock.json"}, "properties": {"repobilityId": "669a57fcf0ed6fda", "scanner": "scanner-primary", "fingerprint": "0f9337daebe843cd", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-42038"]}}, {"ruleId": "scanner-4ab4953dfdf824c3", "level": "warning", "message": {"text": "CVE-2026-42039: axios 1.13.2 \u2014 .migration-backup/package-lock.json"}, "properties": {"repobilityId": "e0d420704702a3a3", "scanner": "scanner-primary", "fingerprint": "4ab4953dfdf824c3", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-42039"]}}, {"ruleId": "scanner-ddeccb35106b6107", "level": "warning", "message": {"text": "CVE-2026-42041: axios 1.13.2 \u2014 .migration-backup/package-lock.json"}, "properties": {"repobilityId": "8e9d2af775cc17bb", "scanner": "scanner-primary", "fingerprint": "ddeccb35106b6107", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-42041"]}}, {"ruleId": "scanner-de36057e8b24c101", "level": "warning", "message": {"text": "CVE-2026-42042: axios 1.13.2 \u2014 .migration-backup/package-lock.json"}, "properties": {"repobilityId": "7b83d951c16b365d", "scanner": "scanner-primary", "fingerprint": "de36057e8b24c101", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-42042"]}}, {"ruleId": "scanner-2f1031dd461089db", "level": "warning", "message": {"text": "CVE-2026-42044: axios 1.13.2 \u2014 .migration-backup/package-lock.json"}, "properties": {"repobilityId": "638f2fae80145a76", "scanner": "scanner-primary", "fingerprint": "2f1031dd461089db", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-42044"]}}, {"ruleId": "scanner-5c0ad999116faa59", "level": "warning", "message": {"text": "CVE-2026-44490: axios 1.13.2 \u2014 .migration-backup/package-lock.json"}, "properties": {"repobilityId": "7a26ae8d1c1e6963", "scanner": "scanner-primary", "fingerprint": "5c0ad999116faa59", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44490"]}}, {"ruleId": "scanner-db815f5d5fa0cd03", "level": "warning", "message": {"text": "CVE-2026-67312: axios 1.13.2 \u2014 .migration-backup/package-lock.json"}, "properties": {"repobilityId": "6c3d246f21bf6bbe", "scanner": "scanner-primary", "fingerprint": "db815f5d5fa0cd03", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-67312"]}}, {"ruleId": "scanner-1efb0227c205b2fe", "level": "warning", "message": {"text": "CVE-2026-67316: axios 1.13.2 \u2014 .migration-backup/package-lock.json"}, "properties": {"repobilityId": "0ff1d99b5a9af920", "scanner": "scanner-primary", "fingerprint": "1efb0227c205b2fe", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-67316"]}}, {"ruleId": "scanner-becd814d7b613c04", "level": "warning", "message": {"text": "GHSA-42h9-826w-cgv3: axios 1.13.2 \u2014 .migration-backup/package-lock.json"}, "properties": {"repobilityId": "6f297697d555553a", "scanner": "scanner-primary", "fingerprint": "becd814d7b613c04", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-42h9-826w-cgv3"]}}, {"ruleId": "scanner-073e9ca5b0a3309f", "level": "warning", "message": {"text": "GHSA-7q8q-rj6j-mhjq: axios 1.13.2 \u2014 .migration-backup/package-lock.json"}, "properties": {"repobilityId": "1dbf97d997c59040", "scanner": "scanner-primary", "fingerprint": "073e9ca5b0a3309f", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-7q8q-rj6j-mhjq"]}}, {"ruleId": "scanner-483496a466bd40fb", "level": "warning", "message": {"text": "GHSA-jqh4-m9w3-8hp9: axios 1.13.2 \u2014 .migration-backup/package-lock.json"}, "properties": {"repobilityId": "986cf93c34faa446", "scanner": "scanner-primary", "fingerprint": "483496a466bd40fb", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-jqh4-m9w3-8hp9"]}}, {"ruleId": "scanner-f57372826c3d9ea7", "level": "warning", "message": {"text": "GHSA-mwf2-3pr3-8698: axios 1.13.2 \u2014 .migration-backup/package-lock.json"}, "properties": {"repobilityId": "4fc02f878761f941", "scanner": "scanner-primary", "fingerprint": "f57372826c3d9ea7", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-mwf2-3pr3-8698"]}}, {"ruleId": "scanner-f3b4273fb283a749", "level": "note", "message": {"text": "CVE-2026-42040: axios 1.13.2 \u2014 .migration-backup/package-lock.json"}, "properties": {"repobilityId": "3fd0344776ec7252", "scanner": "scanner-primary", "fingerprint": "f3b4273fb283a749", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-42040"]}}, {"ruleId": "scanner-2f2b98bf2f78ae98", "level": "warning", "message": {"text": "CVE-2026-2739: bn.js 4.12.2 \u2014 .migration-backup/package-lock.json"}, "properties": {"repobilityId": "cc97f5b7f6188a76", "scanner": "scanner-primary", "fingerprint": "2f2b98bf2f78ae98", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-2739"]}}, {"ruleId": "scanner-74044c26d670987b", "level": "note", "message": {"text": "CVE-2026-12590: body-parser 1.20.4 \u2014 .migration-backup/package-lock.json"}, "properties": {"repobilityId": "0bf2fa738d48cf61", "scanner": "scanner-primary", "fingerprint": "74044c26d670987b", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-12590"]}}, {"ruleId": "scanner-43550612bada21fa", "level": "error", "message": {"text": "CVE-2026-13149: brace-expansion 2.0.2 \u2014 .migration-backup/package-lock.json"}, "properties": {"repobilityId": "e7c29e333ac6438a", "scanner": "scanner-primary", "fingerprint": "43550612bada21fa", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-13149"]}}, {"ruleId": "scanner-52df6a19078a083b", "level": "error", "message": {"text": "CVE-2026-14257: brace-expansion 2.0.2 \u2014 .migration-backup/package-lock.json"}, "properties": {"repobilityId": "1f6753b7556bc826", "scanner": "scanner-primary", "fingerprint": "52df6a19078a083b", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-14257"]}}, {"ruleId": "scanner-7d3d39ff0adba768", "level": "error", "message": {"text": "CVE-2026-69152: brace-expansion 2.0.2 \u2014 .migration-backup/package-lock.json"}, "properties": {"repobilityId": "58e0dfd51e3be723", "scanner": "scanner-primary", "fingerprint": "7d3d39ff0adba768", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-69152"]}}, {"ruleId": "scanner-2f2b5f4facd665c9", "level": "warning", "message": {"text": "CVE-2026-33750: brace-expansion 2.0.2 \u2014 .migration-backup/package-lock.json"}, "properties": {"repobilityId": "2f84446587b890fd", "scanner": "scanner-primary", "fingerprint": "2f2b5f4facd665c9", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-33750"]}}, {"ruleId": "scanner-a4d831c90fffeb9c", "level": "error", "message": {"text": "CVE-2026-39356: drizzle-orm 0.39.3 \u2014 .migration-backup/package-lock.json"}, "properties": {"repobilityId": "6b02c9aa3f7f1486", "scanner": "scanner-primary", "fingerprint": "a4d831c90fffeb9c", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-39356"]}}, {"ruleId": "scanner-0b27f2e566913181", "level": "error", "message": {"text": "CVE-2026-59724: engine.io 6.6.5 \u2014 .migration-backup/package-lock.json"}, "properties": {"repobilityId": "1c7e4236e63b7c93", "scanner": "scanner-primary", "fingerprint": "0b27f2e566913181", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-59724"]}}, {"ruleId": "scanner-12ae96f103d48a0d", "level": "error", "message": {"text": "CVE-2026-59725: engine.io 6.6.5 \u2014 .migration-backup/package-lock.json"}, "properties": {"repobilityId": "cfcb078b2adcd3d7", "scanner": "scanner-primary", "fingerprint": "12ae96f103d48a0d", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-59725"]}}, {"ruleId": "scanner-eb6f9fcf16589539", "level": "error", "message": {"text": "CVE-2026-13676: fast-uri 3.1.0 \u2014 .migration-backup/package-lock.json"}, "properties": {"repobilityId": "0a90c94079e889a2", "scanner": "scanner-primary", "fingerprint": "eb6f9fcf16589539", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-13676"]}}, {"ruleId": "scanner-87ff36bc4d55b755", "level": "error", "message": {"text": "CVE-2026-16221: fast-uri 3.1.0 \u2014 .migration-backup/package-lock.json"}, "properties": {"repobilityId": "f84639a9ae2b29e5", "scanner": "scanner-primary", "fingerprint": "87ff36bc4d55b755", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-16221"]}}, {"ruleId": "scanner-57bbc7c08a7c9ebc", "level": "error", "message": {"text": "CVE-2026-18446: fast-uri 3.1.0 \u2014 .migration-backup/package-lock.json"}, "properties": {"repobilityId": "67e83b43318b4a66", "scanner": "scanner-primary", "fingerprint": "57bbc7c08a7c9ebc", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-18446"]}}, {"ruleId": "scanner-c1b42fe08d5bbb53", "level": "error", "message": {"text": "CVE-2026-6321: fast-uri 3.1.0 \u2014 .migration-backup/package-lock.json"}, "properties": {"repobilityId": "f344991747cad214", "scanner": "scanner-primary", "fingerprint": "c1b42fe08d5bbb53", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-6321"]}}, {"ruleId": "scanner-d02be77c25b740b5", "level": "error", "message": {"text": "CVE-2026-6322: fast-uri 3.1.0 \u2014 .migration-backup/package-lock.json"}, "properties": {"repobilityId": "70b67485d94f219c", "scanner": "scanner-primary", "fingerprint": "d02be77c25b740b5", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-6322"]}}, {"ruleId": "scanner-f568e41d12dac34c", "level": "error", "message": {"text": "CVE-2026-26278: fast-xml-parser 5.3.5 \u2014 .migration-backup/package-lock.json"}, "properties": {"repobilityId": "772e797ee939b5e6", "scanner": "scanner-primary", "fingerprint": "f568e41d12dac34c", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-26278"]}}, {"ruleId": "scanner-5b278a5cd0e59dea", "level": "error", "message": {"text": "CVE-2026-33036: fast-xml-parser 5.3.5 \u2014 .migration-backup/package-lock.json"}, "properties": {"repobilityId": "f93e95395aaf419e", "scanner": "scanner-primary", "fingerprint": "5b278a5cd0e59dea", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-33036"]}}, {"ruleId": "scanner-35eb9baad8ccd72b", "level": "warning", "message": {"text": "CVE-2026-33349: fast-xml-parser 5.3.5 \u2014 .migration-backup/package-lock.json"}, "properties": {"repobilityId": "8079329f144a07fd", "scanner": "scanner-primary", "fingerprint": "35eb9baad8ccd72b", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-33349"]}}, {"ruleId": "scanner-693422d7e76a261b", "level": "warning", "message": {"text": "CVE-2026-41650: fast-xml-parser 5.3.5 \u2014 .migration-backup/package-lock.json"}, "properties": {"repobilityId": "f3ca99d0994133bf", "scanner": "scanner-primary", "fingerprint": "693422d7e76a261b", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-41650"]}}, {"ruleId": "scanner-f7ad91af0f09b344", "level": "note", "message": {"text": "CVE-2026-27942: fast-xml-parser 5.3.5 \u2014 .migration-backup/package-lock.json"}, "properties": {"repobilityId": "807920b64c6bba33", "scanner": "scanner-primary", "fingerprint": "f7ad91af0f09b344", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-27942"]}}, {"ruleId": "scanner-037e54325f081875", "level": "warning", "message": {"text": "GHSA-r4q5-vmmm-2653: follow-redirects 1.15.11 \u2014 .migration-backup/package-lock.json"}, "properties": {"repobilityId": "4c5fd1f3edfc0c6f", "scanner": "scanner-primary", "fingerprint": "037e54325f081875", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-r4q5-vmmm-2653"]}}, {"ruleId": "scanner-e7c6a241869a7c30", "level": "error", "message": {"text": "CVE-2026-12143: form-data 2.5.5 \u2014 .migration-backup/package-lock.json"}, "properties": {"repobilityId": "7211132d11986f38", "scanner": "scanner-primary", "fingerprint": "e7c6a241869a7c30", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-12143"]}}, {"ruleId": "scanner-0cf91d1eb6007d04", "level": "error", "message": {"text": "CVE-2026-12143: form-data 4.0.5 \u2014 .migration-backup/package-lock.json"}, "properties": {"repobilityId": "7211132d11986f38", "scanner": "scanner-primary", "fingerprint": "0cf91d1eb6007d04", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-12143"]}}, {"ruleId": "scanner-5e66669a33bed215", "level": "error", "message": {"text": "CVE-2026-4800: lodash 4.17.23 \u2014 .migration-backup/package-lock.json"}, "properties": {"repobilityId": "87073c0da3259c49", "scanner": "scanner-primary", "fingerprint": "5e66669a33bed215", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-4800"]}}, {"ruleId": "scanner-30ec4a6de706b35a", "level": "warning", "message": {"text": "CVE-2026-2950: lodash 4.17.23 \u2014 .migration-backup/package-lock.json"}, "properties": {"repobilityId": "457e40c4507b4191", "scanner": "scanner-primary", "fingerprint": "30ec4a6de706b35a", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-2950"]}}, {"ruleId": "scanner-b139460868786224", "level": "error", "message": {"text": "CVE-2026-26996: minimatch 10.1.1 \u2014 .migration-backup/package-lock.json"}, "properties": {"repobilityId": "0031abe4f0b77c55", "scanner": "scanner-primary", "fingerprint": "b139460868786224", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-26996"]}}, {"ruleId": "scanner-2e065c23622703e5", "level": "error", "message": {"text": "CVE-2026-27903: minimatch 10.1.1 \u2014 .migration-backup/package-lock.json"}, "properties": {"repobilityId": "c490c4d2764d5c3e", "scanner": "scanner-primary", "fingerprint": "2e065c23622703e5", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-27903"]}}, {"ruleId": "scanner-0e78b535468db104", "level": "error", "message": {"text": "CVE-2026-27904: minimatch 10.1.1 \u2014 .migration-backup/package-lock.json"}, "properties": {"repobilityId": "775c088766d4fcb7", "scanner": "scanner-primary", "fingerprint": "0e78b535468db104", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-27904"]}}, {"ruleId": "scanner-c8ab983c94610f21", "level": "error", "message": {"text": "CVE-2026-26996: minimatch 5.1.6 \u2014 .migration-backup/package-lock.json"}, "properties": {"repobilityId": "0031abe4f0b77c55", "scanner": "scanner-primary", "fingerprint": "c8ab983c94610f21", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-26996"]}}, {"ruleId": "scanner-d509576ab53e8e36", "level": "error", "message": {"text": "CVE-2026-27903: minimatch 5.1.6 \u2014 .migration-backup/package-lock.json"}, "properties": {"repobilityId": "c490c4d2764d5c3e", "scanner": "scanner-primary", "fingerprint": "d509576ab53e8e36", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-27903"]}}, {"ruleId": "scanner-656d4fde2313d517", "level": "error", "message": {"text": "CVE-2026-27904: minimatch 5.1.6 \u2014 .migration-backup/package-lock.json"}, "properties": {"repobilityId": "775c088766d4fcb7", "scanner": "scanner-primary", "fingerprint": "656d4fde2313d517", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-27904"]}}, {"ruleId": "scanner-784bae0fb5049433", "level": "error", "message": {"text": "CVE-2026-26996: minimatch 9.0.5 \u2014 .migration-backup/package-lock.json"}, "properties": {"repobilityId": "0031abe4f0b77c55", "scanner": "scanner-primary", "fingerprint": "784bae0fb5049433", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-26996"]}}, {"ruleId": "scanner-b37a04641b97221e", "level": "error", "message": {"text": "CVE-2026-27903: minimatch 9.0.5 \u2014 .migration-backup/package-lock.json"}, "properties": {"repobilityId": "c490c4d2764d5c3e", "scanner": "scanner-primary", "fingerprint": "b37a04641b97221e", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-27903"]}}, {"ruleId": "scanner-fd8d89a27e151543", "level": "error", "message": {"text": "CVE-2026-27904: minimatch 9.0.5 \u2014 .migration-backup/package-lock.json"}, "properties": {"repobilityId": "775c088766d4fcb7", "scanner": "scanner-primary", "fingerprint": "fd8d89a27e151543", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-27904"]}}, {"ruleId": "scanner-099b9273041be41f", "level": "error", "message": {"text": "CVE-2026-5079: multer 2.1.1 \u2014 .migration-backup/package-lock.json"}, "properties": {"repobilityId": "f6d1f1fcb7dc4c07", "scanner": "scanner-primary", "fingerprint": "099b9273041be41f", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-5079"]}}, {"ruleId": "scanner-c5b0f76a1d8af59a", "level": "warning", "message": {"text": "CVE-2026-5038: multer 2.1.1 \u2014 .migration-backup/package-lock.json"}, "properties": {"repobilityId": "5019c38898e30128", "scanner": "scanner-primary", "fingerprint": "c5b0f76a1d8af59a", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-5038"]}}, {"ruleId": "scanner-14a15098389f477e", "level": "warning", "message": {"text": "GHSA-rgwj-5xj2-c3m3: mysql2 3.16.3 \u2014 .migration-backup/package-lock.json"}, "properties": {"repobilityId": "8464d3a0a0807882", "scanner": "scanner-primary", "fingerprint": "14a15098389f477e", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-rgwj-5xj2-c3m3"]}}, {"ruleId": "scanner-12a263cc878c854c", "level": "error", "message": {"text": "CVE-2026-67213: nanoid 3.3.11 \u2014 .migration-backup/package-lock.json"}, "properties": {"repobilityId": "d82214e58335bdbb", "scanner": "scanner-primary", "fingerprint": "12a263cc878c854c", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-67213"]}}, {"ruleId": "scanner-a687079dd22cf128", "level": "error", "message": {"text": "CVE-2026-67214: nanoid 3.3.11 \u2014 .migration-backup/package-lock.json"}, "properties": {"repobilityId": "bdfe30999ea2b7b0", "scanner": "scanner-primary", "fingerprint": "a687079dd22cf128", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-67214"]}}, {"ruleId": "scanner-13e2f2635a20c5d4", "level": "error", "message": {"text": "CVE-2026-67214: nanoid 5.1.6 \u2014 .migration-backup/package-lock.json"}, "properties": {"repobilityId": "bdfe30999ea2b7b0", "scanner": "scanner-primary", "fingerprint": "13e2f2635a20c5d4", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-67214"]}}, {"ruleId": "scanner-c26e7ef39b91c66b", "level": "error", "message": {"text": "CVE-2026-4867: path-to-regexp 0.1.12 \u2014 .migration-backup/package-lock.json"}, "properties": {"repobilityId": "f6e770857c5b3521", "scanner": "scanner-primary", "fingerprint": "c26e7ef39b91c66b", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-4867"]}}, {"ruleId": "scanner-76ebe13d5084bb02", "level": "error", "message": {"text": "CVE-2026-33671: picomatch 2.3.1 \u2014 .migration-backup/package-lock.json"}, "properties": {"repobilityId": "e0ff42fb6a28759e", "scanner": "scanner-primary", "fingerprint": "76ebe13d5084bb02", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-33671"]}}, {"ruleId": "scanner-707f4fad866c380c", "level": "warning", "message": {"text": "CVE-2026-33672: picomatch 2.3.1 \u2014 .migration-backup/package-lock.json"}, "properties": {"repobilityId": "97a6ecea238f3c26", "scanner": "scanner-primary", "fingerprint": "707f4fad866c380c", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-33672"]}}, {"ruleId": "scanner-a92dbc5b7414c266", "level": "error", "message": {"text": "CVE-2026-33671: picomatch 4.0.3 \u2014 .migration-backup/package-lock.json"}, "properties": {"repobilityId": "e0ff42fb6a28759e", "scanner": "scanner-primary", "fingerprint": "a92dbc5b7414c266", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-33671"]}}, {"ruleId": "scanner-9f8ff117c3e2e89f", "level": "warning", "message": {"text": "CVE-2026-33672: picomatch 4.0.3 \u2014 .migration-backup/package-lock.json"}, "properties": {"repobilityId": "97a6ecea238f3c26", "scanner": "scanner-primary", "fingerprint": "9f8ff117c3e2e89f", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-33672"]}}, {"ruleId": "scanner-a349fa5e2aa4d8eb", "level": "error", "message": {"text": "CVE-2026-45623: postcss 8.5.6 \u2014 .migration-backup/package-lock.json"}, "properties": {"repobilityId": "be865a26b0bdb4a3", "scanner": "scanner-primary", "fingerprint": "a349fa5e2aa4d8eb", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-45623"]}}, {"ruleId": "scanner-45b65349a078e228", "level": "error", "message": {"text": "CVE-2026-73646: postcss 8.5.6 \u2014 .migration-backup/package-lock.json"}, "properties": {"repobilityId": "31db8c532933ac96", "scanner": "scanner-primary", "fingerprint": "45b65349a078e228", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-73646"]}}, {"ruleId": "scanner-28be461fec2be7c4", "level": "warning", "message": {"text": "CVE-2026-41305: postcss 8.5.6 \u2014 .migration-backup/package-lock.json"}, "properties": {"repobilityId": "a85e9f12f2f342f8", "scanner": "scanner-primary", "fingerprint": "28be461fec2be7c4", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-41305"]}}, {"ruleId": "scanner-add7f95db12e56fb", "level": "warning", "message": {"text": "CVE-2026-69153: postcss 8.5.6 \u2014 .migration-backup/package-lock.json"}, "properties": {"repobilityId": "35c40fc3c8cf195f", "scanner": "scanner-primary", "fingerprint": "add7f95db12e56fb", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-69153"]}}, {"ruleId": "scanner-3eb656a98ce54baa", "level": "error", "message": {"text": "CVE-2026-41242: protobufjs 6.8.8 \u2014 .migration-backup/package-lock.json"}, "properties": {"repobilityId": "3cfb1b5cc7270da6", "scanner": "scanner-primary", "fingerprint": "3eb656a98ce54baa", "layer": "security", "severity": "critical", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-41242"]}}, {"ruleId": "scanner-eeaf71d7635bd9fa", "level": "error", "message": {"text": "CVE-2026-44289: protobufjs 6.8.8 \u2014 .migration-backup/package-lock.json"}, "properties": {"repobilityId": "6a585b4d555f71e3", "scanner": "scanner-primary", "fingerprint": "eeaf71d7635bd9fa", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44289"]}}, {"ruleId": "scanner-af5cd88dbc92fd55", "level": "error", "message": {"text": "CVE-2026-44290: protobufjs 6.8.8 \u2014 .migration-backup/package-lock.json"}, "properties": {"repobilityId": "e2420a1b47664e35", "scanner": "scanner-primary", "fingerprint": "af5cd88dbc92fd55", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44290"]}}, {"ruleId": "scanner-b9066ab308b9bcf6", "level": "error", "message": {"text": "CVE-2026-44291: protobufjs 6.8.8 \u2014 .migration-backup/package-lock.json"}, "properties": {"repobilityId": "17c33ba617e45bad", "scanner": "scanner-primary", "fingerprint": "b9066ab308b9bcf6", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44291"]}}, {"ruleId": "scanner-f04ee596bb375991", "level": "error", "message": {"text": "CVE-2026-44293: protobufjs 6.8.8 \u2014 .migration-backup/package-lock.json"}, "properties": {"repobilityId": "f1a947f38904205b", "scanner": "scanner-primary", "fingerprint": "f04ee596bb375991", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44293"]}}, {"ruleId": "scanner-c9a946f2ad1ecfbf", "level": "error", "message": {"text": "CVE-2026-48712: protobufjs 6.8.8 \u2014 .migration-backup/package-lock.json"}, "properties": {"repobilityId": "6760e1bb91c2e48e", "scanner": "scanner-primary", "fingerprint": "c9a946f2ad1ecfbf", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-48712"]}}, {"ruleId": "scanner-a93f0568074bf08a", "level": "warning", "message": {"text": "CVE-2026-44288: protobufjs 6.8.8 \u2014 .migration-backup/package-lock.json"}, "properties": {"repobilityId": "51e33b4030613afb", "scanner": "scanner-primary", "fingerprint": "a93f0568074bf08a", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44288"]}}, {"ruleId": "scanner-6f13dce92bda8ae5", "level": "warning", "message": {"text": "CVE-2026-44292: protobufjs 6.8.8 \u2014 .migration-backup/package-lock.json"}, "properties": {"repobilityId": "bd59ef485ad347df", "scanner": "scanner-primary", "fingerprint": "6f13dce92bda8ae5", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44292"]}}, {"ruleId": "scanner-b0a0483ac9aaafcc", "level": "warning", "message": {"text": "CVE-2026-44294: protobufjs 6.8.8 \u2014 .migration-backup/package-lock.json"}, "properties": {"repobilityId": "22e20bae3e40831b", "scanner": "scanner-primary", "fingerprint": "b0a0483ac9aaafcc", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44294"]}}, {"ruleId": "scanner-46c37d099b6e72e7", "level": "warning", "message": {"text": "CVE-2026-45740: protobufjs 6.8.8 \u2014 .migration-backup/package-lock.json"}, "properties": {"repobilityId": "f081d4720e689b30", "scanner": "scanner-primary", "fingerprint": "46c37d099b6e72e7", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-45740"]}}, {"ruleId": "scanner-72b80a42b8c67fd7", "level": "warning", "message": {"text": "CVE-2026-54269: protobufjs 6.8.8 \u2014 .migration-backup/package-lock.json"}, "properties": {"repobilityId": "e3e39dae22c08218", "scanner": "scanner-primary", "fingerprint": "72b80a42b8c67fd7", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-54269"]}}, {"ruleId": "scanner-a4c617e6e2be3a98", "level": "error", "message": {"text": "CVE-2026-48712: protobufjs 7.5.6 \u2014 .migration-backup/package-lock.json"}, "properties": {"repobilityId": "6760e1bb91c2e48e", "scanner": "scanner-primary", "fingerprint": "a4c617e6e2be3a98", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-48712"]}}, {"ruleId": "scanner-7cf47b34b31eb942", "level": "warning", "message": {"text": "CVE-2026-45740: protobufjs 7.5.6 \u2014 .migration-backup/package-lock.json"}, "properties": {"repobilityId": "f081d4720e689b30", "scanner": "scanner-primary", "fingerprint": "7cf47b34b31eb942", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-45740"]}}, {"ruleId": "scanner-caa50897582e4a81", "level": "warning", "message": {"text": "CVE-2026-54269: protobufjs 7.5.6 \u2014 .migration-backup/package-lock.json"}, "properties": {"repobilityId": "e3e39dae22c08218", "scanner": "scanner-primary", "fingerprint": "caa50897582e4a81", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-54269"]}}, {"ruleId": "scanner-bed3e6631e48bb90", "level": "warning", "message": {"text": "CVE-2026-59877: protobufjs 7.5.6 \u2014 .migration-backup/package-lock.json"}, "properties": {"repobilityId": "b5271a18af1b174e", "scanner": "scanner-primary", "fingerprint": "bed3e6631e48bb90", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-59877"]}}, {"ruleId": "scanner-441ff70db3c1eff8", "level": "warning", "message": {"text": "CVE-2026-8723: qs 6.14.1 \u2014 .migration-backup/package-lock.json"}, "properties": {"repobilityId": "a18a2179a47fac3e", "scanner": "scanner-primary", "fingerprint": "441ff70db3c1eff8", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-8723"]}}, {"ruleId": "scanner-94cb6c3a19037aa3", "level": "note", "message": {"text": "CVE-2026-2391: qs 6.14.1 \u2014 .migration-backup/package-lock.json"}, "properties": {"repobilityId": "60dea9f49a7b65be", "scanner": "scanner-primary", "fingerprint": "94cb6c3a19037aa3", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-2391"]}}, {"ruleId": "scanner-1e33b42f358a47b8", "level": "error", "message": {"text": "CVE-2026-27606: rollup 2.79.2 \u2014 .migration-backup/package-lock.json"}, "properties": {"repobilityId": "65862205ccabe4e2", "scanner": "scanner-primary", "fingerprint": "1e33b42f358a47b8", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-27606"]}}, {"ruleId": "scanner-3ec3e1ccb55bc2e7", "level": "error", "message": {"text": "CVE-2026-27606: rollup 4.54.0 \u2014 .migration-backup/package-lock.json"}, "properties": {"repobilityId": "65862205ccabe4e2", "scanner": "scanner-primary", "fingerprint": "3ec3e1ccb55bc2e7", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-27606"]}}, {"ruleId": "scanner-ae2aec0bcc922178", "level": "error", "message": {"text": "GHSA-5c6j-r48x-rmvq: serialize-javascript 6.0.2 \u2014 .migration-backup/package-lock.json"}, "properties": {"repobilityId": "3557eacb070674d1", "scanner": "scanner-primary", "fingerprint": "ae2aec0bcc922178", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-5c6j-r48x-rmvq"]}}, {"ruleId": "scanner-8cafeb2a65700278", "level": "warning", "message": {"text": "CVE-2026-34043: serialize-javascript 6.0.2 \u2014 .migration-backup/package-lock.json"}, "properties": {"repobilityId": "9ffd3394e73dfde2", "scanner": "scanner-primary", "fingerprint": "8cafeb2a65700278", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-34043"]}}, {"ruleId": "scanner-6c08ae89e4ace521", "level": "error", "message": {"text": "GHSA-f88m-g3jw-g9cj: sharp 0.34.5 \u2014 .migration-backup/package-lock.json"}, "properties": {"repobilityId": "f3a6ce7b46ffe5d7", "scanner": "scanner-primary", "fingerprint": "6c08ae89e4ace521", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-f88m-g3jw-g9cj"]}}, {"ruleId": "scanner-7912e92029ca2121", "level": "error", "message": {"text": "CVE-2026-33151: socket.io-parser 4.2.5 \u2014 .migration-backup/package-lock.json"}, "properties": {"repobilityId": "2aba0066a1987593", "scanner": "scanner-primary", "fingerprint": "7912e92029ca2121", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-33151"]}}, {"ruleId": "scanner-cb750782cefe9476", "level": "error", "message": {"text": "CVE-2026-69185: socket.io-parser 4.2.5 \u2014 .migration-backup/package-lock.json"}, "properties": {"repobilityId": "1cade83567245479", "scanner": "scanner-primary", "fingerprint": "cb750782cefe9476", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-69185"]}}, {"ruleId": "scanner-82dafd640f555a25", "level": "error", "message": {"text": "CVE-2026-59873: tar 6.2.1 \u2014 .migration-backup/package-lock.json"}, "properties": {"repobilityId": "2675266778d2a549", "scanner": "scanner-primary", "fingerprint": "82dafd640f555a25", "layer": "security", "severity": "critical", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-59873"]}}, {"ruleId": "scanner-14599c2197dc1e7b", "level": "error", "message": {"text": "CVE-2026-23745: tar 6.2.1 \u2014 .migration-backup/package-lock.json"}, "properties": {"repobilityId": "6c37c418b7b784bc", "scanner": "scanner-primary", "fingerprint": "14599c2197dc1e7b", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-23745"]}}, {"ruleId": "scanner-57c848c086e9cb1e", "level": "error", "message": {"text": "CVE-2026-23950: tar 6.2.1 \u2014 .migration-backup/package-lock.json"}, "properties": {"repobilityId": "c546a4eebba761a4", "scanner": "scanner-primary", "fingerprint": "57c848c086e9cb1e", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-23950"]}}, {"ruleId": "scanner-2e2ab3c0a8013a9e", "level": "error", "message": {"text": "CVE-2026-24842: tar 6.2.1 \u2014 .migration-backup/package-lock.json"}, "properties": {"repobilityId": "f5e0b6dd00c83f4c", "scanner": "scanner-primary", "fingerprint": "2e2ab3c0a8013a9e", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-24842"]}}, {"ruleId": "scanner-6b479d648a8a3200", "level": "error", "message": {"text": "CVE-2026-26960: tar 6.2.1 \u2014 .migration-backup/package-lock.json"}, "properties": {"repobilityId": "6dec7a4d0d5aa228", "scanner": "scanner-primary", "fingerprint": "6b479d648a8a3200", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-26960"]}}, {"ruleId": "scanner-0aae322af35bedcc", "level": "error", "message": {"text": "CVE-2026-29786: tar 6.2.1 \u2014 .migration-backup/package-lock.json"}, "properties": {"repobilityId": "d88a771d1cd0d97b", "scanner": "scanner-primary", "fingerprint": "0aae322af35bedcc", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-29786"]}}, {"ruleId": "scanner-37a8bf2fd82af8e1", "level": "error", "message": {"text": "CVE-2026-31802: tar 6.2.1 \u2014 .migration-backup/package-lock.json"}, "properties": {"repobilityId": "98cfe492b4b23436", "scanner": "scanner-primary", "fingerprint": "37a8bf2fd82af8e1", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-31802"]}}, {"ruleId": "scanner-cbc4ecd0d4bbd8e9", "level": "error", "message": {"text": "CVE-2026-59874: tar 6.2.1 \u2014 .migration-backup/package-lock.json"}, "properties": {"repobilityId": "b2d24a3884818db5", "scanner": "scanner-primary", "fingerprint": "cbc4ecd0d4bbd8e9", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-59874"]}}, {"ruleId": "scanner-740b4b3bece6e000", "level": "error", "message": {"text": "CVE-2026-73566: tar 6.2.1 \u2014 .migration-backup/package-lock.json"}, "properties": {"repobilityId": "de9dadb0d18cb2a7", "scanner": "scanner-primary", "fingerprint": "740b4b3bece6e000", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-73566"]}}, {"ruleId": "scanner-20f3f7b62620f536", "level": "warning", "message": {"text": "CVE-2026-53655: tar 6.2.1 \u2014 .migration-backup/package-lock.json"}, "properties": {"repobilityId": "e084a4de66cf3ed1", "scanner": "scanner-primary", "fingerprint": "20f3f7b62620f536", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-53655"]}}, {"ruleId": "scanner-1d814b719e87cde0", "level": "warning", "message": {"text": "CVE-2026-59871: tar 6.2.1 \u2014 .migration-backup/package-lock.json"}, "properties": {"repobilityId": "62c7181eddcf5e7f", "scanner": "scanner-primary", "fingerprint": "1d814b719e87cde0", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-59871"]}}, {"ruleId": "scanner-4b0983b3865c39c2", "level": "warning", "message": {"text": "CVE-2026-59875: tar 6.2.1 \u2014 .migration-backup/package-lock.json"}, "properties": {"repobilityId": "8c376aeffd8a70e3", "scanner": "scanner-primary", "fingerprint": "4b0983b3865c39c2", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-59875"]}}, {"ruleId": "scanner-86d87e749b58d44d", "level": "warning", "message": {"text": "CVE-2026-41907: uuid 8.3.2 \u2014 .migration-backup/package-lock.json"}, "properties": {"repobilityId": "85ac3b73a18c8dcb", "scanner": "scanner-primary", "fingerprint": "86d87e749b58d44d", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-41907"]}}, {"ruleId": "scanner-38be9278fc80ee8d", "level": "warning", "message": {"text": "CVE-2026-41907: uuid 9.0.1 \u2014 .migration-backup/package-lock.json"}, "properties": {"repobilityId": "85ac3b73a18c8dcb", "scanner": "scanner-primary", "fingerprint": "38be9278fc80ee8d", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-41907"]}}, {"ruleId": "scanner-0abeae27ae7b44f3", "level": "error", "message": {"text": "CVE-2026-39363: vite 7.3.0 \u2014 .migration-backup/package-lock.json"}, "properties": {"repobilityId": "bd5a9ee81ca8b054", "scanner": "scanner-primary", "fingerprint": "0abeae27ae7b44f3", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-39363"]}}, {"ruleId": "scanner-c858ae6d8eacedc0", "level": "error", "message": {"text": "CVE-2026-39364: vite 7.3.0 \u2014 .migration-backup/package-lock.json"}, "properties": {"repobilityId": "9d3df9c8ad8a3c16", "scanner": "scanner-primary", "fingerprint": "c858ae6d8eacedc0", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-39364"]}}, {"ruleId": "scanner-66f74a2eab1a5f58", "level": "error", "message": {"text": "CVE-2026-53571: vite 7.3.0 \u2014 .migration-backup/package-lock.json"}, "properties": {"repobilityId": "dd2384599be32058", "scanner": "scanner-primary", "fingerprint": "66f74a2eab1a5f58", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-53571"]}}, {"ruleId": "scanner-12d90df76510846c", "level": "warning", "message": {"text": "CVE-2026-39365: vite 7.3.0 \u2014 .migration-backup/package-lock.json"}, "properties": {"repobilityId": "89140c2a283043a3", "scanner": "scanner-primary", "fingerprint": "12d90df76510846c", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-39365"]}}, {"ruleId": "scanner-163d173273098cd6", "level": "warning", "message": {"text": "CVE-2026-53632: vite 7.3.0 \u2014 .migration-backup/package-lock.json"}, "properties": {"repobilityId": "d8ae99a0066eb4fa", "scanner": "scanner-primary", "fingerprint": "163d173273098cd6", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-53632"]}}, {"ruleId": "scanner-45a7dc889e70f8f6", "level": "error", "message": {"text": "CVE-2026-48779: ws 8.18.3 \u2014 .migration-backup/package-lock.json"}, "properties": {"repobilityId": "d1a2e966aa2baf8a", "scanner": "scanner-primary", "fingerprint": "45a7dc889e70f8f6", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-48779"]}}, {"ruleId": "scanner-06da289904b17697", "level": "warning", "message": {"text": "CVE-2026-45736: ws 8.18.3 \u2014 .migration-backup/package-lock.json"}, "properties": {"repobilityId": "d99a6385cf7c0986", "scanner": "scanner-primary", "fingerprint": "06da289904b17697", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-45736"]}}, {"ruleId": "scanner-a576e7c5c0b5986c", "level": "error", "message": {"text": "GHSA-gcfj-64vw-6mp9: axios 1.16.1 \u2014 pnpm-lock.yaml"}, "properties": {"repobilityId": "7a3a049bf13038c4", "scanner": "scanner-primary", "fingerprint": "a576e7c5c0b5986c", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-gcfj-64vw-6mp9"]}}, {"ruleId": "scanner-e784448c0b604438", "level": "warning", "message": {"text": "CVE-2026-67312: axios 1.16.1 \u2014 pnpm-lock.yaml"}, "properties": {"repobilityId": "72d995657595750b", "scanner": "scanner-primary", "fingerprint": "e784448c0b604438", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-67312"]}}, {"ruleId": "scanner-03d6ebdfddb717e3", "level": "warning", "message": {"text": "CVE-2026-67314: axios 1.16.1 \u2014 pnpm-lock.yaml"}, "properties": {"repobilityId": "eb9ed5afa086e404", "scanner": "scanner-primary", "fingerprint": "03d6ebdfddb717e3", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-67314"]}}, {"ruleId": "scanner-8f2f12959f0ae229", "level": "warning", "message": {"text": "CVE-2026-67316: axios 1.16.1 \u2014 pnpm-lock.yaml"}, "properties": {"repobilityId": "1d4923d2f4e44ee8", "scanner": "scanner-primary", "fingerprint": "8f2f12959f0ae229", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-67316"]}}, {"ruleId": "scanner-544929a9a8302ee6", "level": "warning", "message": {"text": "GHSA-42h9-826w-cgv3: axios 1.16.1 \u2014 pnpm-lock.yaml"}, "properties": {"repobilityId": "409c1d451b064a26", "scanner": "scanner-primary", "fingerprint": "544929a9a8302ee6", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-42h9-826w-cgv3"]}}, {"ruleId": "scanner-58f4705eb293437d", "level": "warning", "message": {"text": "GHSA-7q8q-rj6j-mhjq: axios 1.16.1 \u2014 pnpm-lock.yaml"}, "properties": {"repobilityId": "1a4451756d106aee", "scanner": "scanner-primary", "fingerprint": "58f4705eb293437d", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-7q8q-rj6j-mhjq"]}}, {"ruleId": "scanner-94cbdc8e41c2f067", "level": "warning", "message": {"text": "GHSA-f4gw-2p7v-4548: axios 1.16.1 \u2014 pnpm-lock.yaml"}, "properties": {"repobilityId": "3e47e0f4557178c4", "scanner": "scanner-primary", "fingerprint": "94cbdc8e41c2f067", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-f4gw-2p7v-4548"]}}, {"ruleId": "scanner-c50bdc08ae566ea1", "level": "warning", "message": {"text": "GHSA-hcpx-6fm6-wx23: axios 1.16.1 \u2014 pnpm-lock.yaml"}, "properties": {"repobilityId": "27c7509d82fa9629", "scanner": "scanner-primary", "fingerprint": "c50bdc08ae566ea1", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-hcpx-6fm6-wx23"]}}, {"ruleId": "scanner-21eb42994744e3b8", "level": "warning", "message": {"text": "GHSA-jqh4-m9w3-8hp9: axios 1.16.1 \u2014 pnpm-lock.yaml"}, "properties": {"repobilityId": "863c8e3812872636", "scanner": "scanner-primary", "fingerprint": "21eb42994744e3b8", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-jqh4-m9w3-8hp9"]}}, {"ruleId": "scanner-d519fa97166f95fa", "level": "warning", "message": {"text": "GHSA-mwf2-3pr3-8698: axios 1.16.1 \u2014 pnpm-lock.yaml"}, "properties": {"repobilityId": "4fc87d7f29ad69a9", "scanner": "scanner-primary", "fingerprint": "d519fa97166f95fa", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-mwf2-3pr3-8698"]}}, {"ruleId": "scanner-c9dadc5f9682a312", "level": "note", "message": {"text": "CVE-2026-12590: body-parser 2.2.2 \u2014 pnpm-lock.yaml"}, "properties": {"repobilityId": "c52a5d8da171f050", "scanner": "scanner-primary", "fingerprint": "c9dadc5f9682a312", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-12590"]}}, {"ruleId": "scanner-32938573f597b150", "level": "note", "message": {"text": "GHSA-g7r4-m6w7-qqqr: esbuild 0.27.3 \u2014 pnpm-lock.yaml"}, "properties": {"repobilityId": "e19cc30c5c9b0a60", "scanner": "scanner-primary", "fingerprint": "32938573f597b150", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-g7r4-m6w7-qqqr"]}}, {"ruleId": "scanner-ac551d1241a4c012", "level": "error", "message": {"text": "CVE-2026-12143: form-data 2.5.5 \u2014 pnpm-lock.yaml"}, "properties": {"repobilityId": "16e14df320a76e59", "scanner": "scanner-primary", "fingerprint": "ac551d1241a4c012", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-12143"]}}, {"ruleId": "scanner-8deda405a91487df", "level": "error", "message": {"text": "CVE-2026-12143: form-data 4.0.5 \u2014 pnpm-lock.yaml"}, "properties": {"repobilityId": "16e14df320a76e59", "scanner": "scanner-primary", "fingerprint": "8deda405a91487df", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-12143"]}}, {"ruleId": "scanner-7dc8cc9a7e53fb4b", "level": "error", "message": {"text": "CVE-2026-5079: multer 2.1.1 \u2014 pnpm-lock.yaml"}, "properties": {"repobilityId": "b9cee62feacf7012", "scanner": "scanner-primary", "fingerprint": "7dc8cc9a7e53fb4b", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-5079"]}}, {"ruleId": "scanner-c54af1034846997f", "level": "warning", "message": {"text": "CVE-2026-5038: multer 2.1.1 \u2014 pnpm-lock.yaml"}, "properties": {"repobilityId": "4bcf22f3d1838367", "scanner": "scanner-primary", "fingerprint": "c54af1034846997f", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-5038"]}}, {"ruleId": "scanner-f8c09bd5c6f7951d", "level": "warning", "message": {"text": "GHSA-rgwj-5xj2-c3m3: mysql2 3.22.4 \u2014 pnpm-lock.yaml"}, "properties": {"repobilityId": "98681a350b3345ef", "scanner": "scanner-primary", "fingerprint": "f8c09bd5c6f7951d", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-rgwj-5xj2-c3m3"]}}, {"ruleId": "scanner-7f18721531ea7fdf", "level": "error", "message": {"text": "CVE-2026-67213: nanoid 3.3.12 \u2014 pnpm-lock.yaml"}, "properties": {"repobilityId": "1829eec4af0189ba", "scanner": "scanner-primary", "fingerprint": "7f18721531ea7fdf", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-67213"]}}, {"ruleId": "scanner-d80cfa387b678710", "level": "error", "message": {"text": "CVE-2026-67214: nanoid 3.3.12 \u2014 pnpm-lock.yaml"}, "properties": {"repobilityId": "6788d29a1fb323d7", "scanner": "scanner-primary", "fingerprint": "d80cfa387b678710", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-67214"]}}, {"ruleId": "scanner-09e24da193fe4066", "level": "error", "message": {"text": "CVE-2026-67214: nanoid 5.1.11 \u2014 pnpm-lock.yaml"}, "properties": {"repobilityId": "6788d29a1fb323d7", "scanner": "scanner-primary", "fingerprint": "09e24da193fe4066", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-67214"]}}, {"ruleId": "scanner-1e84f80a69fbddcc", "level": "error", "message": {"text": "CVE-2026-73646: postcss 8.5.15 \u2014 pnpm-lock.yaml"}, "properties": {"repobilityId": "3f82db90803ec520", "scanner": "scanner-primary", "fingerprint": "1e84f80a69fbddcc", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-73646"]}}, {"ruleId": "scanner-3c3a1034edfb46d7", "level": "warning", "message": {"text": "CVE-2026-69153: postcss 8.5.15 \u2014 pnpm-lock.yaml"}, "properties": {"repobilityId": "3b55d85234cfd451", "scanner": "scanner-primary", "fingerprint": "3c3a1034edfb46d7", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-69153"]}}, {"ruleId": "scanner-d1ab401799daa269", "level": "warning", "message": {"text": "CVE-2026-54269: protobufjs 7.6.1 \u2014 pnpm-lock.yaml"}, "properties": {"repobilityId": "bc7be1a11f0831e7", "scanner": "scanner-primary", "fingerprint": "d1ab401799daa269", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-54269"]}}, {"ruleId": "scanner-97320d7eeb91e3bc", "level": "warning", "message": {"text": "CVE-2026-59877: protobufjs 7.6.1 \u2014 pnpm-lock.yaml"}, "properties": {"repobilityId": "e476f049a4a11e8e", "scanner": "scanner-primary", "fingerprint": "97320d7eeb91e3bc", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-59877"]}}, {"ruleId": "scanner-618f3c6532aa65ef", "level": "warning", "message": {"text": "CVE-2026-8723: qs 6.15.1 \u2014 pnpm-lock.yaml"}, "properties": {"repobilityId": "a7adafc808d1b7c4", "scanner": "scanner-primary", "fingerprint": "618f3c6532aa65ef", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-8723"]}}, {"ruleId": "scanner-158c4afdf77b4dcf", "level": "error", "message": {"text": "CVE-2026-69185: socket.io-parser 4.2.6 \u2014 pnpm-lock.yaml"}, "properties": {"repobilityId": "1db43928bb71ab8e", "scanner": "scanner-primary", "fingerprint": "158c4afdf77b4dcf", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-69185"]}}, {"ruleId": "scanner-226e1bc058ae11ed", "level": "warning", "message": {"text": "CVE-2026-41907: uuid 8.3.2 \u2014 pnpm-lock.yaml"}, "properties": {"repobilityId": "ce64d4a91b418955", "scanner": "scanner-primary", "fingerprint": "226e1bc058ae11ed", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-41907"]}}, {"ruleId": "scanner-d57769a75313f0c2", "level": "warning", "message": {"text": "CVE-2026-41907: uuid 9.0.1 \u2014 pnpm-lock.yaml"}, "properties": {"repobilityId": "ce64d4a91b418955", "scanner": "scanner-primary", "fingerprint": "d57769a75313f0c2", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-41907"]}}, {"ruleId": "scanner-df43818ec803dac6", "level": "error", "message": {"text": "CVE-2026-48779: ws 8.20.1 \u2014 pnpm-lock.yaml"}, "properties": {"repobilityId": "3e3e7c29f5745cfa", "scanner": "scanner-primary", "fingerprint": "df43818ec803dac6", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-48779"]}}, {"ruleId": "scanner-f4def1fa4a4e776c", "level": "error", "message": {"text": "DS-0002: Image user should not be 'root' \u2014 .migration-backup/Dockerfile"}, "properties": {"repobilityId": "0f534db5ba09df2f", "scanner": "scanner-primary", "fingerprint": "f4def1fa4a4e776c", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "misconfig"]}}, {"ruleId": "scanner-ed0f059f269da3b5", "level": "note", "message": {"text": "DS-0026: No HEALTHCHECK defined \u2014 .migration-backup/Dockerfile"}, "properties": {"repobilityId": "885c805a482d1b66", "scanner": "scanner-primary", "fingerprint": "ed0f059f269da3b5", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "misconfig"]}}, {"ruleId": "scanner-3a3527e70129fb18", "level": "error", "message": {"text": "DS-0002: Image user should not be 'root' \u2014 Dockerfile"}, "properties": {"repobilityId": "691787f6b20605df", "scanner": "scanner-primary", "fingerprint": "3a3527e70129fb18", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "misconfig"]}}, {"ruleId": "scanner-72ff79e0f8219b60", "level": "warning", "message": {"text": "DS-0013: 'RUN cd ...' to change directory \u2014 Dockerfile"}, "properties": {"repobilityId": "975852f52ce6eb22", "scanner": "scanner-primary", "fingerprint": "72ff79e0f8219b60", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "misconfig"]}}, {"ruleId": "scanner-3c4041c454cda88e", "level": "note", "message": {"text": "DS-0026: No HEALTHCHECK defined \u2014 Dockerfile"}, "properties": {"repobilityId": "da995bb2cfa21f65", "scanner": "scanner-primary", "fingerprint": "3c4041c454cda88e", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "misconfig"]}}, {"ruleId": "scanner-f12fd58d443fd86f", "level": "error", "message": {"text": "DS-0002: Image user should not be 'root' \u2014 Dockerfile.api"}, "properties": {"repobilityId": "042869c5b0490692", "scanner": "scanner-primary", "fingerprint": "f12fd58d443fd86f", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "misconfig"]}}, {"ruleId": "scanner-7440a4d260cc223a", "level": "note", "message": {"text": "DS-0026: No HEALTHCHECK defined \u2014 Dockerfile.api"}, "properties": {"repobilityId": "f3bdf92f4db43b74", "scanner": "scanner-primary", "fingerprint": "7440a4d260cc223a", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "misconfig"]}}, {"ruleId": "scanner-8ea271d955e28e4a", "level": "error", "message": {"text": "DS-0029: 'apt-get' missing '--no-install-recommends' \u2014 Dockerfile.api"}, "properties": {"repobilityId": "304b64987c52c9c6", "scanner": "scanner-primary", "fingerprint": "8ea271d955e28e4a", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "misconfig"]}}, {"ruleId": "scanner-5d012ea0e358b226", "level": "error", "message": {"text": "DS-0002: Image user should not be 'root' \u2014 Dockerfile.manager"}, "properties": {"repobilityId": "3068f03035faf07f", "scanner": "scanner-primary", "fingerprint": "5d012ea0e358b226", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "misconfig"]}}, {"ruleId": "scanner-379e564e599d0fbf", "level": "note", "message": {"text": "DS-0026: No HEALTHCHECK defined \u2014 Dockerfile.manager"}, "properties": {"repobilityId": "e297bb38f10e11c7", "scanner": "scanner-primary", "fingerprint": "379e564e599d0fbf", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "misconfig"]}}, {"ruleId": "scanner-fa25f052682e3e23", "level": "error", "message": {"text": "Secret leak: Asymmetric Private Key \u2014 .migration-backup/server/certs/qz-private-key.pem"}, "properties": {"repobilityId": "8a8c2e1d78f5af16", "scanner": "scanner-primary", "fingerprint": "fa25f052682e3e23", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "secret"]}}, {"ruleId": "scanner-2165df432f868b6b", "level": "error", "message": {"text": "Secret leak: Asymmetric Private Key \u2014 artifacts/api-server/server/certs/qz-private-key.pem"}, "properties": {"repobilityId": "ff552ad162262b20", "scanner": "scanner-primary", "fingerprint": "2165df432f868b6b", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "secret"]}}, {"ruleId": "scanner-2c5a37784607d195", "level": "error", "message": {"text": "Secret leak: Asymmetric Private Key \u2014 artifacts/api-server/src/certs/qz-private-key.pem"}, "properties": {"repobilityId": "b44459a2642607a8", "scanner": "scanner-primary", "fingerprint": "2c5a37784607d195", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "secret"]}}, {"ruleId": "scanner-b23183c45ac454b1", "level": "error", "message": {"text": "Secret leak: Asymmetric Private Key \u2014 server/certs/qz-private-key.pem"}, "properties": {"repobilityId": "ec4eba4e4339d416", "scanner": "scanner-primary", "fingerprint": "b23183c45ac454b1", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "secret"]}}, {"ruleId": "scanner-d63da3583b14afc0", "level": "warning", "message": {"text": "Dockerfile runs as root: Dockerfile"}, "properties": {"repobilityId": "a2ed1bd120e507db", "scanner": "scanner-primary", "fingerprint": "d63da3583b14afc0", "layer": "hardware", "severity": "medium", "confidence": 1.0, "tags": ["security", "container"]}}, {"ruleId": "scanner-25de52372c63f233", "level": "note", "message": {"text": "Docker base image is tag-pinned but not digest-pinned: node:24-slim"}, "properties": {"repobilityId": "7b9258013695f0b5", "scanner": "scanner-primary", "fingerprint": "25de52372c63f233", "layer": "hardware", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "docker", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "Dockerfile"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-48e5a2876fc80d5c", "level": "warning", "message": {"text": "Insecure pattern 'local_storage_auth_token' in artifacts/pregasquad-manager/src/main.tsx:35"}, "properties": {"repobilityId": "8c6fc7eaf4c2d6b7", "scanner": "scanner-primary", "fingerprint": "48e5a2876fc80d5c", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "local_storage_auth_token"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "artifacts/pregasquad-manager/src/main.tsx"}, "region": {"startLine": 35}}}]}, {"ruleId": "scanner-025da1ad06f81388", "level": "warning", "message": {"text": "Insecure pattern 'local_storage_auth_token' in artifacts/pregasquad-manager/src/components/layout/FirstLogin.tsx:96"}, "properties": {"repobilityId": "5747afee7f83c41d", "scanner": "scanner-primary", "fingerprint": "025da1ad06f81388", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "local_storage_auth_token"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "artifacts/pregasquad-manager/src/components/layout/FirstLogin.tsx"}, "region": {"startLine": 96}}}]}, {"ruleId": "scanner-69ae226a68090585", "level": "warning", "message": {"text": "Insecure pattern 'dangerous_innerhtml' in artifacts/pregasquad-manager/src/components/ui/chart.tsx:81"}, "properties": {"repobilityId": "8cf923fafd4ec56c", "scanner": "scanner-primary", "fingerprint": "69ae226a68090585", "layer": "security", "severity": "medium", "confidence": 0.65, "tags": ["owasp", "dangerous_innerhtml"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "artifacts/pregasquad-manager/src/components/ui/chart.tsx"}, "region": {"startLine": 81}}}]}, {"ruleId": "scanner-8be6a5fc36902a6f", "level": "warning", "message": {"text": "Insecure pattern 'dangerous_innerhtml' in artifacts/mockup-sandbox/src/components/ui/chart.tsx:79"}, "properties": {"repobilityId": "ac72f3f576911974", "scanner": "scanner-primary", "fingerprint": "8be6a5fc36902a6f", "layer": "security", "severity": "medium", "confidence": 0.65, "tags": ["owasp", "dangerous_innerhtml"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "artifacts/mockup-sandbox/src/components/ui/chart.tsx"}, "region": {"startLine": 79}}}]}, {"ruleId": "scanner-e5f9a03d756818c5", "level": "warning", "message": {"text": "Insecure pattern 'cors_wildcard' in artifacts/api-server/src/app.ts:8"}, "properties": {"repobilityId": "9661a72d8c5f8b98", "scanner": "scanner-primary", "fingerprint": "e5f9a03d756818c5", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "cors_wildcard"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "artifacts/api-server/src/app.ts"}, "region": {"startLine": 8}}}]}, {"ruleId": "scanner-5b201e37e7306271", "level": "warning", "message": {"text": "Insecure pattern 'cors_wildcard' in artifacts/api-server/src/routes/routes.ts:542"}, "properties": {"repobilityId": "05acd331321e2c18", "scanner": "scanner-primary", "fingerprint": "5b201e37e7306271", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "cors_wildcard"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "artifacts/api-server/src/routes/routes.ts"}, "region": {"startLine": 542}}}]}, {"ruleId": "scanner-cb639d9a10a47b23", "level": "note", "message": {"text": "package.json defines install-time lifecycle scripts"}, "properties": {"repobilityId": "4d02a5c7daed0bc5", "scanner": "scanner-primary", "fingerprint": "cb639d9a10a47b23", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "npm", "install-scripts"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-d2bbeabe4013d568", "level": "note", "message": {"text": "Very large file: artifacts/pregasquad-manager/src/pages/AdminSettings.tsx (2186 lines)"}, "properties": {"repobilityId": "723dc3fee276d8eb", "scanner": "scanner-primary", "fingerprint": "d2bbeabe4013d568", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-dfae44774be69d50", "level": "note", "message": {"text": "Very large file: artifacts/pregasquad-manager/src/pages/Salaries.tsx (2447 lines)"}, "properties": {"repobilityId": "e6cbb84d1c8d91e9", "scanner": "scanner-primary", "fingerprint": "dfae44774be69d50", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-57f10e7c21b381ff", "level": "note", "message": {"text": "Very large file: artifacts/pregasquad-manager/src/pages/WhatsApp.tsx (3431 lines)"}, "properties": {"repobilityId": "095bc5c593ee56c7", "scanner": "scanner-primary", "fingerprint": "57f10e7c21b381ff", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-f1651c68f64e43c7", "level": "note", "message": {"text": "Very large file: artifacts/pregasquad-manager/src/pages/Website.tsx (1157 lines)"}, "properties": {"repobilityId": "e98045e8bbe6c55e", "scanner": "scanner-primary", "fingerprint": "f1651c68f64e43c7", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-83b8a5eb5a17efb5", "level": "note", "message": {"text": "Very large file: artifacts/pregasquad-manager/src/pages/Clients.tsx (1370 lines)"}, "properties": {"repobilityId": "1be902e83a66f5ce", "scanner": "scanner-primary", "fingerprint": "83b8a5eb5a17efb5", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-0bef888905140f39", "level": "note", "message": {"text": "Very large file: artifacts/pregasquad-manager/src/pages/Charges.tsx (1112 lines)"}, "properties": {"repobilityId": "bbbf8048e2d9c339", "scanner": "scanner-primary", "fingerprint": "0bef888905140f39", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-49c141f8db7fb738", "level": "note", "message": {"text": "Very large file: artifacts/pregasquad-manager/src/pages/Planning.tsx (4883 lines)"}, "properties": {"repobilityId": "c138a82a07370c5b", "scanner": "scanner-primary", "fingerprint": "49c141f8db7fb738", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-0bae98eab61865d8", "level": "note", "message": {"text": "Very large file: artifacts/pregasquad-manager/src/pages/Booking.tsx (1311 lines)"}, "properties": {"repobilityId": "2e772ee7a288d7a2", "scanner": "scanner-primary", "fingerprint": "0bae98eab61865d8", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-8143d7963cf091a0", "level": "note", "message": {"text": "Very large file: artifacts/pregasquad-manager/src/hooks/use-salon-data.ts (1527 lines)"}, "properties": {"repobilityId": "12f3ae9b1e1296cf", "scanner": "scanner-primary", "fingerprint": "8143d7963cf091a0", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-2191b9ce86040ede", "level": "note", "message": {"text": "Very large file: artifacts/api-server/src/storage.ts (1694 lines)"}, "properties": {"repobilityId": "a3b069d2d3aeacde", "scanner": "scanner-primary", "fingerprint": "2191b9ce86040ede", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-3b9e20e2012234e8", "level": "note", "message": {"text": "Very large file: artifacts/api-server/src/gemini.ts (1703 lines)"}, "properties": {"repobilityId": "4edbbf52324e7d63", "scanner": "scanner-primary", "fingerprint": "3b9e20e2012234e8", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-22ff002102036496", "level": "note", "message": {"text": "Very large file: artifacts/api-server/src/db.ts (2811 lines)"}, "properties": {"repobilityId": "0022b1ae82e7a510", "scanner": "scanner-primary", "fingerprint": "22ff002102036496", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-8ed40d7926ed8994", "level": "note", "message": {"text": "Very large file: artifacts/api-server/src/routes/routes.ts (7388 lines)"}, "properties": {"repobilityId": "dd536ef2b9676faf", "scanner": "scanner-primary", "fingerprint": "8ed40d7926ed8994", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-6893a6c8b0861585", "level": "warning", "message": {"text": "Very low test-to-source ratio"}, "properties": {"repobilityId": "54a7de3f06314bf0", "scanner": "scanner-primary", "fingerprint": "6893a6c8b0861585", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["tests", "coverage"]}}, {"ruleId": "scanner-141b30a41e03817b", "level": "note", "message": {"text": "No license file detected"}, "properties": {"repobilityId": "85570602a143230c", "scanner": "scanner-primary", "fingerprint": "141b30a41e03817b", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["license", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-faccb9061e9b52a0", "level": "note", "message": {"text": "No README detected"}, "properties": {"repobilityId": "e1125f40da1076e7", "scanner": "scanner-primary", "fingerprint": "faccb9061e9b52a0", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["docs", "readme", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-2cc1d1055f9af446", "level": "note", "message": {"text": "Node manifest has dependencies but no lockfile: scripts/package.json"}, "properties": {"repobilityId": "3a2a86cb93b8e276", "scanner": "scanner-primary", "fingerprint": "2cc1d1055f9af446", "layer": "dependencies", "severity": "low", "confidence": 1.0, "tags": ["dependency", "lockfile", "reproducibility", "generated-repo-pattern"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "scripts/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-c34cfbe6f531799c", "level": "note", "message": {"text": "Node manifest has dependencies but no lockfile: lib/api-spec/package.json"}, "properties": {"repobilityId": "eda4cc86db8e9149", "scanner": "scanner-primary", "fingerprint": "c34cfbe6f531799c", "layer": "dependencies", "severity": "low", "confidence": 1.0, "tags": ["dependency", "lockfile", "reproducibility", "generated-repo-pattern"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "lib/api-spec/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-fc09d08ad5b813b9", "level": "note", "message": {"text": "Node manifest has dependencies but no lockfile: lib/db/package.json"}, "properties": {"repobilityId": "892008a5a207d3f2", "scanner": "scanner-primary", "fingerprint": "fc09d08ad5b813b9", "layer": "dependencies", "severity": "low", "confidence": 1.0, "tags": ["dependency", "lockfile", "reproducibility", "generated-repo-pattern"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "lib/db/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-4876ea1389cf2faf", "level": "note", "message": {"text": "Node manifest has dependencies but no lockfile: lib/api-zod/package.json"}, "properties": {"repobilityId": "804558e2ccb62729", "scanner": "scanner-primary", "fingerprint": "4876ea1389cf2faf", "layer": "dependencies", "severity": "low", "confidence": 1.0, "tags": ["dependency", "lockfile", "reproducibility", "generated-repo-pattern"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "lib/api-zod/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-64d389a127f7f14c", "level": "note", "message": {"text": "Node manifest has dependencies but no lockfile: lib/api-client-react/package.json"}, "properties": {"repobilityId": "2f7f46cc532837f4", "scanner": "scanner-primary", "fingerprint": "64d389a127f7f14c", "layer": "dependencies", "severity": "low", "confidence": 1.0, "tags": ["dependency", "lockfile", "reproducibility", "generated-repo-pattern"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "lib/api-client-react/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-8d4d073a77500fa6", "level": "note", "message": {"text": "Node manifest has dependencies but no lockfile: artifacts/pregasquad-manager/package.json"}, "properties": {"repobilityId": "095572de09063a47", "scanner": "scanner-primary", "fingerprint": "8d4d073a77500fa6", "layer": "dependencies", "severity": "low", "confidence": 1.0, "tags": ["dependency", "lockfile", "reproducibility", "generated-repo-pattern"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "artifacts/pregasquad-manager/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-12ffb37512252714", "level": "note", "message": {"text": "Node manifest has dependencies but no lockfile: artifacts/api-server/package.json"}, "properties": {"repobilityId": "acfe01e5eaa91c63", "scanner": "scanner-primary", "fingerprint": "12ffb37512252714", "layer": "dependencies", "severity": "low", "confidence": 1.0, "tags": ["dependency", "lockfile", "reproducibility", "generated-repo-pattern"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "artifacts/api-server/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-3ab5d313dda8e5f9", "level": "note", "message": {"text": "Debug logging residue appears in source files"}, "properties": {"repobilityId": "4a53c57fe373b6bc", "scanner": "scanner-primary", "fingerprint": "3ab5d313dda8e5f9", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["debug", "cleanup", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-72b2a6250083a784", "level": "warning", "message": {"text": "Placeholder or mock-heavy implementation detected"}, "properties": {"repobilityId": "e5bcc073806d3bb0", "scanner": "scanner-primary", "fingerprint": "72b2a6250083a784", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["placeholder", "mock-data", "incomplete", "generated-repo-pattern"]}}, {"ruleId": "scanner-9d79c4077342a7d0", "level": "warning", "message": {"text": "Runtime service client appears to use placeholder configuration"}, "properties": {"repobilityId": "ad33a1cc5cb230ee", "scanner": "scanner-primary", "fingerprint": "9d79c4077342a7d0", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["placeholder", "runtime-config", "service-client", "generated-repo-pattern"]}}, {"ruleId": "scanner-2d0c7b7ab8f8aacf", "level": "warning", "message": {"text": "Critical user flow still appears backed by mock or placeholder data"}, "properties": {"repobilityId": "eb89147141d4c0bf", "scanner": "scanner-primary", "fingerprint": "2d0c7b7ab8f8aacf", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["placeholder", "mock-data", "critical-flow", "generated-repo-pattern"]}}, {"ruleId": "scanner-b9088664ace7f748", "level": "warning", "message": {"text": "Composite production-readiness gap"}, "properties": {"repobilityId": "fc35a1e3e99517c5", "scanner": "scanner-primary", "fingerprint": "b9088664ace7f748", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["production-readiness", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-672accf751fc6bfc", "level": "warning", "message": {"text": "Fire-and-forget `fetch()` has no rejection handler \u2014 artifacts/pregasquad-manager/src/App.tsx:312"}, "properties": {"repobilityId": "d1995d00dbf0e010", "scanner": "scanner-primary", "fingerprint": "672accf751fc6bfc", "layer": "quality", "severity": "medium", "confidence": 0.9, "tags": ["integrity", "fragile-runtime", "robustness", "unhandled-promise"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "artifacts/pregasquad-manager/src/App.tsx"}, "region": {"startLine": 312}}}]}, {"ruleId": "scanner-fde86c89f4bc2fb6", "level": "warning", "message": {"text": "Fire-and-forget `fetch()` has no rejection handler \u2014 artifacts/pregasquad-manager/src/lib/qzPrint.ts:52"}, "properties": {"repobilityId": "d6f574f06d248326", "scanner": "scanner-primary", "fingerprint": "fde86c89f4bc2fb6", "layer": "quality", "severity": "medium", "confidence": 0.9, "tags": ["integrity", "fragile-runtime", "robustness", "unhandled-promise"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "artifacts/pregasquad-manager/src/lib/qzPrint.ts"}, "region": {"startLine": 52}}}]}, {"ruleId": "scanner-4636dc5108a5af7c", "level": "warning", "message": {"text": "Fire-and-forget `fetch()` has no rejection handler \u2014 artifacts/pregasquad-manager/src/pages/WhatsApp.tsx:1016"}, "properties": {"repobilityId": "d5e3d9f747f599aa", "scanner": "scanner-primary", "fingerprint": "4636dc5108a5af7c", "layer": "quality", "severity": "medium", "confidence": 0.9, "tags": ["integrity", "fragile-runtime", "robustness", "unhandled-promise"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "artifacts/pregasquad-manager/src/pages/WhatsApp.tsx"}, "region": {"startLine": 1016}}}]}, {"ruleId": "scanner-7ff4f48319566139", "level": "warning", "message": {"text": "Fire-and-forget `fetch()` has no rejection handler \u2014 artifacts/pregasquad-manager/src/pages/Planning.tsx:757"}, "properties": {"repobilityId": "4f9ef5b2fa12a195", "scanner": "scanner-primary", "fingerprint": "7ff4f48319566139", "layer": "quality", "severity": "medium", "confidence": 0.9, "tags": ["integrity", "fragile-runtime", "robustness", "unhandled-promise"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "artifacts/pregasquad-manager/src/pages/Planning.tsx"}, "region": {"startLine": 757}}}]}, {"ruleId": "scanner-98809848c4b57e22", "level": "warning", "message": {"text": "Fire-and-forget `fetch()` has no rejection handler \u2014 artifacts/pregasquad-manager/src/pages/Booking.tsx:140"}, "properties": {"repobilityId": "a4bc9e3d3daea2eb", "scanner": "scanner-primary", "fingerprint": "98809848c4b57e22", "layer": "quality", "severity": "medium", "confidence": 0.9, "tags": ["integrity", "fragile-runtime", "robustness", "unhandled-promise"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "artifacts/pregasquad-manager/src/pages/Booking.tsx"}, "region": {"startLine": 140}}}]}, {"ruleId": "scanner-0d2ddca6e169fabc", "level": "warning", "message": {"text": "Fire-and-forget `fetch()` has no rejection handler \u2014 artifacts/pregasquad-manager/src/pages/Logs.tsx:109"}, "properties": {"repobilityId": "1509e460d3c2f1f5", "scanner": "scanner-primary", "fingerprint": "0d2ddca6e169fabc", "layer": "quality", "severity": "medium", "confidence": 0.9, "tags": ["integrity", "fragile-runtime", "robustness", "unhandled-promise"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "artifacts/pregasquad-manager/src/pages/Logs.tsx"}, "region": {"startLine": 109}}}]}, {"ruleId": "scanner-a9d48ab77a6ee2ea", "level": "warning", "message": {"text": "Fire-and-forget `fetch()` has no rejection handler \u2014 artifacts/pregasquad-manager/src/pages/Website1.tsx:88"}, "properties": {"repobilityId": "aa328aef0f1e84bb", "scanner": "scanner-primary", "fingerprint": "a9d48ab77a6ee2ea", "layer": "quality", "severity": "medium", "confidence": 0.9, "tags": ["integrity", "fragile-runtime", "robustness", "unhandled-promise"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "artifacts/pregasquad-manager/src/pages/Website1.tsx"}, "region": {"startLine": 88}}}]}, {"ruleId": "scanner-3f655669718d4e68", "level": "warning", "message": {"text": "Frontend route `/staff-portal/:token` has no Link/navigate to it \u2014 artifacts/pregasquad-manager/src/App.tsx"}, "properties": {"repobilityId": "147cf606060902e2", "scanner": "scanner-primary", "fingerprint": "3f655669718d4e68", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "orphan-page", "wiring"]}}, {"ruleId": "scanner-9169f714ff7b7b1d", "level": "note", "message": {"text": "Vulnerable dependency esbuild 0.27.7: GHSA-g7r4-m6w7-qqqr"}, "properties": {"repobilityId": "dbc426c2dd693105", "scanner": "scanner-primary", "fingerprint": "9169f714ff7b7b1d", "layer": "dependencies", "severity": "low", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-g7r4-m6w7-qqqr", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "artifacts/mockup-sandbox/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-857deb3a99c6ced1", "level": "error", "message": {"text": "Vulnerable dependency nanoid 3.3.12: GHSA-28wg-ghj8-5hjv"}, "properties": {"repobilityId": "1c539067ffbb7d02", "scanner": "scanner-primary", "fingerprint": "857deb3a99c6ced1", "layer": "dependencies", "severity": "high", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-28wg-ghj8-5hjv", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "artifacts/mockup-sandbox/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-9484bb7b5b522ccb", "level": "error", "message": {"text": "Vulnerable dependency nanoid 3.3.12: GHSA-2v37-7h3g-55p8"}, "properties": {"repobilityId": "e145d5e3a509b3d8", "scanner": "scanner-primary", "fingerprint": "9484bb7b5b522ccb", "layer": "dependencies", "severity": "high", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-2v37-7h3g-55p8", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "artifacts/mockup-sandbox/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-2979aecac39eb079", "level": "warning", "message": {"text": "Vulnerable dependency postcss 8.5.15: GHSA-fxqj-rqcc-2cmp"}, "properties": {"repobilityId": "ab38bf8006c871b9", "scanner": "scanner-primary", "fingerprint": "2979aecac39eb079", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-fxqj-rqcc-2cmp", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "artifacts/pregasquad-manager/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-a71a7d7d7dbd0d2f", "level": "warning", "message": {"text": "Vulnerable dependency postcss 8.5.15: GHSA-r28c-9q8g-f849"}, "properties": {"repobilityId": "70c61f72b039c17c", "scanner": "scanner-primary", "fingerprint": "a71a7d7d7dbd0d2f", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-r28c-9q8g-f849", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "artifacts/pregasquad-manager/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-6aa9fbcbb60bed0a", "level": "error", "message": {"text": "Vulnerable dependency vite 7.3.3: GHSA-fx2h-pf6j-xcff"}, "properties": {"repobilityId": "6bcffa62f84d5105", "scanner": "scanner-primary", "fingerprint": "6aa9fbcbb60bed0a", "layer": "dependencies", "severity": "high", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-fx2h-pf6j-xcff", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "artifacts/mockup-sandbox/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-803164d68cf1a938", "level": "warning", "message": {"text": "Vulnerable dependency vite 7.3.3: GHSA-v6wh-96g9-6wx3"}, "properties": {"repobilityId": "25538a476284b764", "scanner": "scanner-primary", "fingerprint": "803164d68cf1a938", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-v6wh-96g9-6wx3", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "artifacts/mockup-sandbox/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-bd723825e360c985", "level": "note", "message": {"text": "Vulnerable dependency esbuild 0.27.3: GHSA-g7r4-m6w7-qqqr"}, "properties": {"repobilityId": "8ca6a3c17eea45ad", "scanner": "scanner-primary", "fingerprint": "bd723825e360c985", "layer": "dependencies", "severity": "low", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-g7r4-m6w7-qqqr", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "artifacts/api-server/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-7cafadac43283f61", "level": "warning", "message": {"text": "Vulnerable dependency multer 2.1.1: GHSA-3p4h-7m6x-2hcm"}, "properties": {"repobilityId": "3d21a5ce152aca4d", "scanner": "scanner-primary", "fingerprint": "7cafadac43283f61", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-3p4h-7m6x-2hcm"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "artifacts/api-server/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-b30c11bb8470aae8", "level": "error", "message": {"text": "Vulnerable dependency multer 2.1.1: GHSA-72gw-mp4g-v24j"}, "properties": {"repobilityId": "5fd28b2ffad63174", "scanner": "scanner-primary", "fingerprint": "b30c11bb8470aae8", "layer": "dependencies", "severity": "high", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-72gw-mp4g-v24j"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "artifacts/api-server/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-4ca1329ae57c3c8c", "level": "warning", "message": {"text": "Vulnerable dependency mysql2 3.22.4: GHSA-rgwj-5xj2-c3m3"}, "properties": {"repobilityId": "72d4a45c4194aa41", "scanner": "scanner-primary", "fingerprint": "4ca1329ae57c3c8c", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-rgwj-5xj2-c3m3"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "artifacts/api-server/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-bd5046a49b16b8cb", "level": "error", "message": {"text": "Vulnerable dependency nanoid 5.1.11: GHSA-28wg-ghj8-5hjv"}, "properties": {"repobilityId": "30f5b304be413177", "scanner": "scanner-primary", "fingerprint": "bd5046a49b16b8cb", "layer": "dependencies", "severity": "high", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-28wg-ghj8-5hjv"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "artifacts/api-server/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-50a0ccef57d8b8f3", "level": "error", "message": {"text": "Vulnerable dependency ws 8.20.1: GHSA-96hv-2xvq-fx4p"}, "properties": {"repobilityId": "a1dc5bed811d8076", "scanner": "scanner-primary", "fingerprint": "50a0ccef57d8b8f3", "layer": "dependencies", "severity": "high", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-96hv-2xvq-fx4p"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "pnpm-lock.yaml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-9ce290f81268f4e5", "level": "note", "message": {"text": "Vulnerable dependency @babel/core 7.29.0: GHSA-4x5r-pxfx-6jf8"}, "properties": {"repobilityId": "048ec5a9afac1732", "scanner": "scanner-primary", "fingerprint": "9ce290f81268f4e5", "layer": "dependencies", "severity": "low", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-4x5r-pxfx-6jf8", "transitive", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "artifacts/mockup-sandbox/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-9614dd79a5c65dac", "level": "note", "message": {"text": "Dependency @google-cloud/storage is a major version behind"}, "properties": {"repobilityId": "b8513f4eac46fba9", "scanner": "scanner-primary", "fingerprint": "9614dd79a5c65dac", "layer": "dependencies", "severity": "low", "confidence": 0.9, "tags": ["dependency", "freshness", "outdated"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "artifacts/api-server/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-afd1fe5046bc0607", "level": "note", "message": {"text": "Dependency date-fns is a major version behind"}, "properties": {"repobilityId": "fe449132ff5b70a3", "scanner": "scanner-primary", "fingerprint": "afd1fe5046bc0607", "layer": "dependencies", "severity": "low", "confidence": 0.9, "tags": ["dependency", "freshness", "outdated"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "artifacts/api-server/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-747ce365c4150d64", "level": "note", "message": {"text": "Dependency nanoid is a major version behind"}, "properties": {"repobilityId": "33a1d5dee66478fe", "scanner": "scanner-primary", "fingerprint": "747ce365c4150d64", "layer": "dependencies", "severity": "low", "confidence": 0.9, "tags": ["dependency", "freshness", "outdated"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "artifacts/api-server/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-8401c240841914fc", "level": "note", "message": {"text": "Dependency pino-http is a major version behind"}, "properties": {"repobilityId": "6d3389b88ef4cf52", "scanner": "scanner-primary", "fingerprint": "8401c240841914fc", "layer": "dependencies", "severity": "low", "confidence": 0.9, "tags": ["dependency", "freshness", "outdated"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "artifacts/api-server/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-8261eac145992d6c", "level": "note", "message": {"text": "Dependency pino is a major version behind"}, "properties": {"repobilityId": "28212715182ae044", "scanner": "scanner-primary", "fingerprint": "8261eac145992d6c", "layer": "dependencies", "severity": "low", "confidence": 0.9, "tags": ["dependency", "freshness", "outdated"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "artifacts/api-server/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-28bcd8de999454c2", "level": "error", "message": {"text": "Dangling fetch: GET /api/export/${type} (artifacts/pregasquad-manager/src/pages/AdminSettings.tsx:531)"}, "properties": {"repobilityId": "f0d7c486e1b516a8", "scanner": "scanner-primary", "fingerprint": "28bcd8de999454c2", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "artifacts/pregasquad-manager/src/pages/AdminSettings.tsx"}, "region": {"startLine": 531}}}]}, {"ruleId": "scanner-a78ff2da1b49b4aa", "level": "error", "message": {"text": "Dangling fetch: GET /api/notifications/broadcast/last (artifacts/pregasquad-manager/src/pages/WhatsApp.tsx:1025)"}, "properties": {"repobilityId": "9885b494d9dbd3a2", "scanner": "scanner-primary", "fingerprint": "a78ff2da1b49b4aa", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "artifacts/pregasquad-manager/src/pages/WhatsApp.tsx"}, "region": {"startLine": 1025}}}]}, {"ruleId": "scanner-bf703dd27600eed2", "level": "error", "message": {"text": "Dangling fetch: PUT /api/appointments/${id} (artifacts/pregasquad-manager/src/pages/BookingHistory.tsx:92)"}, "properties": {"repobilityId": "757befd6774280c2", "scanner": "scanner-primary", "fingerprint": "bf703dd27600eed2", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "artifacts/pregasquad-manager/src/pages/BookingHistory.tsx"}, "region": {"startLine": 92}}}]}, {"ruleId": "scanner-ed48be944fb57876", "level": "error", "message": {"text": "Dangling fetch: POST /api/appointments (artifacts/pregasquad-manager/src/pages/BookingHistory.tsx:108)"}, "properties": {"repobilityId": "b359778b2e218bd9", "scanner": "scanner-primary", "fingerprint": "ed48be944fb57876", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "artifacts/pregasquad-manager/src/pages/BookingHistory.tsx"}, "region": {"startLine": 108}}}]}, {"ruleId": "scanner-bde11d5593469fad", "level": "error", "message": {"text": "Dangling fetch: DELETE /api/appointments/${id} (artifacts/pregasquad-manager/src/pages/BookingHistory.tsx:131)"}, "properties": {"repobilityId": "1564296e818ada53", "scanner": "scanner-primary", "fingerprint": "bde11d5593469fad", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "artifacts/pregasquad-manager/src/pages/BookingHistory.tsx"}, "region": {"startLine": 131}}}]}, {"ruleId": "scanner-926824cd381e9d40", "level": "error", "message": {"text": "Dangling fetch: POST /api/appointments (artifacts/pregasquad-manager/src/pages/Clients.tsx:264)"}, "properties": {"repobilityId": "cbf3b8afd227e348", "scanner": "scanner-primary", "fingerprint": "926824cd381e9d40", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "artifacts/pregasquad-manager/src/pages/Clients.tsx"}, "region": {"startLine": 264}}}]}, {"ruleId": "scanner-576dfb4153565f90", "level": "error", "message": {"text": "Dangling fetch: POST /api/appointments (artifacts/pregasquad-manager/src/pages/POS.tsx:195)"}, "properties": {"repobilityId": "5f4af0aa64aed4df", "scanner": "scanner-primary", "fingerprint": "576dfb4153565f90", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "artifacts/pregasquad-manager/src/pages/POS.tsx"}, "region": {"startLine": 195}}}]}, {"ruleId": "scanner-b05683ef40d20d3d", "level": "note", "message": {"text": "146 backend endpoints not called by scanned frontend"}, "properties": {"repobilityId": "3c8e96670c5e1f9f", "scanner": "scanner-primary", "fingerprint": "b05683ef40d20d3d", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}]}]}