Skip to content

chore(deps): update dependency express to v4.18.3

2dbd7c8
Select commit
Loading
Failed to load commit list.
Open

chore(deps): update dependency express to v4.18.3 #63

chore(deps): update dependency express to v4.18.3
2dbd7c8
Select commit
Loading
Failed to load commit list.
Mend for GitHub.com / WhiteSource Security Check failed Apr 9, 2026 in 4m 38s

Security Report

You have successfully remediated 3 vulnerabilities, but introduced 16 new vulnerabilities in this branch.

❌ New vulnerabilities:

Vulnerability Severity CVSS Score Vulnerable Library Direct Library Suggested Fix Issue
CVE-2026-4867

Path to dependency file: /app-to-phone-kotlin/package.json

Path to vulnerable library: /app-to-phone-kotlin/package.json,/app-to-phone-swift/package.json,/app-to-app-swift/package.json,/phone-to-app-kotlin/package.json

Dependency Hierarchy:

-> express-4.21.0.tgz (Root Library)

   -> ❌ path-to-regexp-0.1.10.tgz (Vulnerable Library)

High 7.5 Transitive path-to-regexp-0.1.10.tgz express-4.21.0.tgz Transitive path-to-regexp - 0.1.13 None
CVE-2026-4867

Path to dependency file: /app-to-phone-kotlin/package.json

Path to vulnerable library: /app-to-phone-kotlin/package.json,/app-to-phone-swift/package.json,/app-to-app-swift/package.json,/phone-to-app-kotlin/package.json

Dependency Hierarchy:

-> express-4.21.1.tgz (Root Library)

   -> ❌ path-to-regexp-0.1.10.tgz (Vulnerable Library)

High 7.5 Transitive path-to-regexp-0.1.10.tgz express-4.21.1.tgz Transitive path-to-regexp - 0.1.13 None
CVE-2026-4867

Path to dependency file: /app-to-phone-kotlin/package.json

Path to vulnerable library: /app-to-phone-kotlin/package.json,/app-to-phone-swift/package.json,/app-to-app-swift/package.json,/phone-to-app-kotlin/package.json

Dependency Hierarchy:

-> express-4.20.0.tgz (Root Library)

   -> ❌ path-to-regexp-0.1.10.tgz (Vulnerable Library)

High 7.5 Transitive path-to-regexp-0.1.10.tgz express-4.20.0.tgz Transitive path-to-regexp - 0.1.13 None
CVE-2026-27904

Path to dependency file: /app-to-phone-js/package.json

Path to vulnerable library: /app-to-phone-js/package.json,/app-to-app-js/package.json,/phone-to-app-js/package.json

Dependency Hierarchy:

-> client-sdk-2.0.0.tgz (Root Library)

   -> typedoc-plugin-missing-exports-2.2.0.tgz

     -> typedoc-0.25.12.tgz

       -> ❌ minimatch-9.0.3.tgz (Vulnerable Library)

High 7.5 Transitive minimatch-9.0.3.tgz client-sdk-2.0.0.tgz Transitive 9.0.7 #72
CVE-2026-27903

Path to dependency file: /app-to-phone-js/package.json

Path to vulnerable library: /app-to-phone-js/package.json,/app-to-app-js/package.json,/phone-to-app-js/package.json

Dependency Hierarchy:

-> client-sdk-2.0.0.tgz (Root Library)

   -> typedoc-plugin-missing-exports-2.2.0.tgz

     -> typedoc-0.25.12.tgz

       -> ❌ minimatch-9.0.3.tgz (Vulnerable Library)

High 7.5 Transitive minimatch-9.0.3.tgz client-sdk-2.0.0.tgz Transitive https://github.com/isaacs/minimatch.git - v3.1.3,https://github.com/isaacs/minimatch.git - v4.2.5,https://github.com/isaacs/minimatch.git - v6.2.2,https://github.com/isaacs/minimatch.git - v10.2.3,https://github.com/isaacs/minimatch.git - v5.1.8,https://github.com/isaacs/minimatch.git - v9.0.7,https://github.com/isaacs/minimatch.git - v7.4.8,https://github.com/isaacs/minimatch.git - v8.0.6 #72
CVE-2026-26996

Path to dependency file: /app-to-phone-js/package.json

Path to vulnerable library: /app-to-phone-js/package.json,/app-to-app-js/package.json,/phone-to-app-js/package.json

Dependency Hierarchy:

-> client-sdk-2.0.0.tgz (Root Library)

   -> typedoc-plugin-missing-exports-2.2.0.tgz

     -> typedoc-0.25.12.tgz

       -> ❌ minimatch-9.0.3.tgz (Vulnerable Library)

High 7.5 Transitive minimatch-9.0.3.tgz client-sdk-2.0.0.tgz Transitive https://github.com/isaacs/minimatch.git - v10.2.1,https://github.com/isaacs/minimatch.git - v5.1.7,https://github.com/isaacs/minimatch.git - v4.2.4,https://github.com/isaacs/minimatch.git - v3.1.3,https://github.com/isaacs/minimatch.git - v8.0.5,https://github.com/isaacs/minimatch.git - v9.0.6,https://github.com/isaacs/minimatch.git - v6.2.1,https://github.com/isaacs/minimatch.git - v7.4.7 #72
CVE-2024-52798

Path to dependency file: /app-to-phone-kotlin/package.json

Path to vulnerable library: /app-to-phone-kotlin/package.json,/app-to-phone-swift/package.json,/app-to-app-swift/package.json,/phone-to-app-kotlin/package.json

Dependency Hierarchy:

-> express-4.21.0.tgz (Root Library)

   -> ❌ path-to-regexp-0.1.10.tgz (Vulnerable Library)

High 7.5 Transitive path-to-regexp-0.1.10.tgz express-4.21.0.tgz Transitive 0.1.12 None
CVE-2024-52798

Path to dependency file: /app-to-phone-kotlin/package.json

Path to vulnerable library: /app-to-phone-kotlin/package.json,/app-to-phone-swift/package.json,/app-to-app-swift/package.json,/phone-to-app-kotlin/package.json

Dependency Hierarchy:

-> express-4.21.1.tgz (Root Library)

   -> ❌ path-to-regexp-0.1.10.tgz (Vulnerable Library)

High 7.5 Transitive path-to-regexp-0.1.10.tgz express-4.21.1.tgz Transitive 0.1.12 None
CVE-2024-52798

Path to dependency file: /app-to-phone-kotlin/package.json

Path to vulnerable library: /app-to-phone-kotlin/package.json,/app-to-phone-swift/package.json,/app-to-app-swift/package.json,/phone-to-app-kotlin/package.json

Dependency Hierarchy:

-> express-4.20.0.tgz (Root Library)

   -> ❌ path-to-regexp-0.1.10.tgz (Vulnerable Library)

High 7.5 Transitive path-to-regexp-0.1.10.tgz express-4.20.0.tgz Transitive 0.1.12 None
CVE-2024-45590

Path to dependency file: /phone-to-app-swift/package.json

Path to vulnerable library: /phone-to-app-swift/package.json

Dependency Hierarchy:

-> express-4.18.3.tgz (Root Library)

   -> ❌ body-parser-1.20.2.tgz (Vulnerable Library)

High 7.5 Transitive body-parser-1.20.2.tgz express-4.18.3.tgz Transitive 1.20.3 None
CVE-2026-33750

Path to dependency file: /phone-to-app-js/package.json

Path to vulnerable library: /phone-to-app-js/package.json,/app-to-app-js/package.json,/app-to-phone-js/package.json

Dependency Hierarchy:

-> client-sdk-2.0.0.tgz (Root Library)

   -> typedoc-plugin-missing-exports-2.2.0.tgz

     -> typedoc-0.25.12.tgz

       -> minimatch-9.0.3.tgz

         -> ❌ brace-expansion-2.0.1.tgz (Vulnerable Library)

Medium 6.5 Transitive brace-expansion-2.0.1.tgz client-sdk-2.0.0.tgz Transitive https://github.com/juliangruber/brace-expansion.git - v2.0.3,https://github.com/juliangruber/brace-expansion.git - v3.0.2,https://github.com/juliangruber/brace-expansion.git - v5.0.5,https://github.com/juliangruber/brace-expansion.git - v1.1.13 #72
CVE-2024-29041

Path to dependency file: /phone-to-app-swift/package.json

Path to vulnerable library: /phone-to-app-swift/package.json

Dependency Hierarchy:

-> ❌ express-4.18.3.tgz (Vulnerable Library)

Medium 6.1 Direct express-4.18.3.tgz express-4.18.3.tgz 4.19.0 None
CVE-2024-47764

Path to dependency file: /app-to-app-swift/package.json

Path to vulnerable library: /app-to-app-swift/package.json,/phone-to-app-kotlin/package.json,/app-to-phone-swift/package.json

Dependency Hierarchy:

-> express-4.21.0.tgz (Root Library)

   -> ❌ cookie-0.6.0.tgz (Vulnerable Library)

Medium 5.3 Transitive cookie-0.6.0.tgz express-4.21.0.tgz Transitive 0.7.0 None
CVE-2024-47764

Path to dependency file: /app-to-app-swift/package.json

Path to vulnerable library: /app-to-app-swift/package.json,/phone-to-app-kotlin/package.json,/app-to-phone-swift/package.json

Dependency Hierarchy:

-> express-4.20.0.tgz (Root Library)

   -> ❌ cookie-0.6.0.tgz (Vulnerable Library)

Medium 5.3 Transitive cookie-0.6.0.tgz express-4.20.0.tgz Transitive 0.7.0 None
CVE-2024-43796

Path to dependency file: /phone-to-app-swift/package.json

Path to vulnerable library: /phone-to-app-swift/package.json

Dependency Hierarchy:

-> ❌ express-4.18.3.tgz (Vulnerable Library)

Medium 5.0 Direct express-4.18.3.tgz express-4.18.3.tgz 4.20.0 None
CVE-2025-5889

Path to dependency file: /phone-to-app-js/package.json

Path to vulnerable library: /phone-to-app-js/package.json,/app-to-app-js/package.json,/app-to-phone-js/package.json

Dependency Hierarchy:

-> client-sdk-2.0.0.tgz (Root Library)

   -> typedoc-plugin-missing-exports-2.2.0.tgz

     -> typedoc-0.25.12.tgz

       -> minimatch-9.0.3.tgz

         -> ❌ brace-expansion-2.0.1.tgz (Vulnerable Library)

Low 3.1 Transitive brace-expansion-2.0.1.tgz client-sdk-2.0.0.tgz Transitive 2.0.2 #72

✔️ Remediated vulnerabilities:

Vulnerability Vulnerable Library
CVE-2024-43796 express-4.18.2.tgz
CVE-2024-29041 express-4.18.2.tgz
CVE-2024-45590 body-parser-1.20.1.tgz

Base branch total remaining vulnerabilities: 25
Base branch commit: null


Total libraries scanned: 363

Scan token: 7d4e791d3aa747eb824e6faa57fe0cea