Skip to content

Wiz: Upgrade multiple dependencies (resolves 20 findings)#8

Open
ghost wants to merge 5 commits intomainfrom
wiz-remediation-2025-03-02-d2c87305de95
Open

Wiz: Upgrade multiple dependencies (resolves 20 findings)#8
ghost wants to merge 5 commits intomainfrom
wiz-remediation-2025-03-02-d2c87305de95

Conversation

@ghost
Copy link

@ghost ghost commented Mar 2, 2025

Wiz Remediation Pull Request Banner

Wiz has created this PR to fix 20 findings detected in this project

Changes were made to the following file(s):

  • /examples/image-resize/package.json
  • /examples/strapi/strapi/package.json
  • /packages/create-remix/templates/arc/package.json
  • /packages/remix-dev/package.json
  • /packages/remix-server-runtime/package.json

Vulnerabilities:

Component Findings Locations
@strapi/plugin-users-permissions
4.0.3 → 4.24.2
Critical CVE-2023-38507
High GHSA-xv3q-jrmm-4fxv
High CVE-2023-22621
High CVE-2023-22893
High CVE-2024-34065
High CVE-2023-39345
/examples/strapi/strapi/package.json
@strapi/strapi
4.0.3 → 4.13.1
High CVE-2023-34093
High CVE-2021-46440
High CVE-2023-39345
High CVE-2022-30618
High CVE-2022-31367
Medium CVE-2023-22894
/examples/strapi/strapi/package.json
aws-sdk
2.796.0 → 2.814.0
Critical CVE-2020-28472 /packages/create-remix/templates/arc/package.json
cookie
0.4.2 → 0.7.0
Medium CVE-2024-47764 /packages/remix-server-runtime/package.json
esbuild
0.13.14 → 0.25.0
Medium GHSA-67mh-4wv8-2f99 /packages/remix-dev/package.json
sharp
0.29.3 → 0.32.6
High GHSA-54xq-cgqr-rpm3
High CVE-2023-4863
Medium CVE-2022-29256
/examples/image-resize/package.json
sqlite3
5.0.2 → 5.1.5
Critical CVE-2022-43441
High CVE-2022-21227
/examples/strapi/strapi/package.json

To detect these findings earlier in the dev lifecycle, try using Wiz Code VS Code Extension.

@ghost ghost added the Wiz-remediation label Mar 2, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

0 participants