Dashboard › Code › Session s2f1860684df
s2f1860684df861e1Edit applied successfully.
#278 [open] shell-quote (critical) - shell-quote quote() does not escape newlines in object .op values Vulnerable: >= 1.1.0, <= 1.8.3 | Patched: 1.8.4 | Relationship: transitive #277 [open] hono (medium) - Hono: app.mount() strips mount prefix using undecoded path, causing incorrect routing for percent-encoded paths Vulnerable: < 4.12.21 | Patched: 4.12.21 | Relationship: transitive #276 [open] hono (medium) - Hono: IP Restriction bypasses static deny rules for non-canonical IPv6 Vulnerable: < 4.12.21 | Patched: 4.12.21 | Relationship: transitive #275 [open] hono (medium) - Hono: Cookie helper does not sanitize sameSite and priority, allowing Set-Cookie injection Vulnerable: < 4.12.21 | Patched: 4.12.21 | Relationship: transitive #274 [open] hono (medium) - Hono: JWT middleware accepts any Authorization scheme, not only Bearer Vulnerable: < 4.12.21 | Patched: 4.12.21 | Relationship: transitive #273 [fixed] react-router (medium) - React Router's same-origin redirect ...
Good. No security advisories, and there are 5 open dependabot alerts. Let me now explore the codebase to understand where these dependencies come from.
(no output)
No CI runs triggered. This might be because the branch was pushed from a worktree or the CI workflow has path filters. Let me check the CI workflow configuration: