A package you depend on has a known security hole (CVE-2021-44906). Fix: Update that package to its patched version.
Worth fixingGHSA-6chw-6frg-f759 Regular Expression Denial of Service in Acorn
yarn.lock
A package you depend on has a known security hole (GHSA-6chw-6frg-f759). Fix: Update that package to its patched version.
Worth fixingCVE-2020-7598 nodejs-minimist: prototype pollution allows adding or modifying properties of Object.prototype using a constructor or __proto__ payload
yarn.lock
A package you depend on has a known security hole (CVE-2020-7598). Fix: Update that package to its patched version.
Worth fixingCVE-2021-23343 nodejs-path-parse: ReDoS via splitDeviceRe, splitTailRe and splitPathRe
yarn.lock
A package you depend on has a known security hole (CVE-2021-23343). Fix: Update that package to its patched version.
About these results. Six open-source checks ran in parallel; every finding is tagged with the tool that produced it. The verdict follows a published rule. False positives and false negatives are normal — a clean scan does not mean the code is secure, and a red verdict does not mean the project is compromised.