Skip to content

auto-audit: unfixable npm vulnerabilities #9

@github-actions

Description

@github-actions

npm audit reports vulnerabilities with no upstream fix available (fixAvailable: false). These need manual triage - pinning, patching, swapping the dependency, or accepting the risk.

form-data - critical (vulnerable: <2.5.4)

qs - high (vulnerable: <=6.14.0)

request - critical (vulnerable: *)

tough-cookie - moderate (vulnerable: <4.1.3)

uuid - moderate (vulnerable: <11.1.1)


Last updated by run: https://github.com/surajkumar/auto-audit/actions/runs/27394650553

Metadata

Metadata

Assignees

No one assigned

    Labels

    auto-audit-unfixableVulnerabilities with no upstream fix available

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions