Skip to content

Update dependency actions-toolkit to v2.1.0

acfe7bc
Select commit
Loading
Failed to load commit list.
Open

Update dependency actions-toolkit to v2.1.0 #13

Update dependency actions-toolkit to v2.1.0
acfe7bc
Select commit
Loading
Failed to load commit list.
Dev - Mend for GitHub.com / Mend Security Check failed Feb 26, 2026 in 2m 24s

Security Report

You have successfully remediated 15 vulnerabilities, but introduced 6 new vulnerabilities in this branch.

❌ New vulnerabilities:

Vulnerability Severity CVSS Score Vulnerable Library Direct Library Suggested Fix Issue Reachability
CVE-2025-25290

Path to dependency file: /nexmo-changelog/package.json

Path to vulnerable library: /nexmo-changelog/package.json

Dependency Hierarchy:

-> actions-toolkit-2.1.0.tgz (Root Library)

   -> rest-16.43.2.tgz

     -> ❌ request-5.6.3.tgz (Vulnerable Library)

Medium 5.3 Transitive request-5.6.3.tgz actions-toolkit-2.1.0.tgz Transitive 8.4.1 #7

Unreachable

CVE-2025-25289

Path to dependency file: /nexmo-changelog/package.json

Path to vulnerable library: /nexmo-changelog/package.json

Dependency Hierarchy:

-> actions-toolkit-2.1.0.tgz (Root Library)

   -> rest-16.43.2.tgz

     -> request-5.6.3.tgz

       -> ❌ request-error-2.1.0.tgz (Vulnerable Library)

Medium 5.3 Transitive request-error-2.1.0.tgz actions-toolkit-2.1.0.tgz Transitive 5.1.1 #7

Unreachable

CVE-2025-25289

Path to dependency file: /nexmo-changelog/package.json

Path to vulnerable library: /nexmo-changelog/package.json

Dependency Hierarchy:

-> actions-toolkit-2.1.0.tgz (Root Library)

   -> rest-16.43.2.tgz

     -> ❌ request-error-1.2.1.tgz (Vulnerable Library)

Medium 5.3 Transitive request-error-1.2.1.tgz actions-toolkit-2.1.0.tgz Transitive 5.1.1 #7

Unreachable

CVE-2025-25288

Path to dependency file: /nexmo-changelog/package.json

Path to vulnerable library: /nexmo-changelog/package.json

Dependency Hierarchy:

-> actions-toolkit-2.1.0.tgz (Root Library)

   -> rest-16.43.2.tgz

     -> ❌ plugin-paginate-rest-1.1.2.tgz (Vulnerable Library)

Medium 5.3 Transitive plugin-paginate-rest-1.1.2.tgz actions-toolkit-2.1.0.tgz Transitive 9.2.2 #7

Unreachable

CVE-2025-25285

Path to dependency file: /nexmo-changelog/package.json

Path to vulnerable library: /nexmo-changelog/package.json

Dependency Hierarchy:

-> actions-toolkit-2.1.0.tgz (Root Library)

   -> rest-16.43.2.tgz

     -> request-5.6.3.tgz

       -> ❌ endpoint-6.0.12.tgz (Vulnerable Library)

Medium 5.3 Transitive endpoint-6.0.12.tgz actions-toolkit-2.1.0.tgz Transitive @octokit/endpoint - 9.0.6,@octokit/endpoint - 10.1.3 #7

Unreachable

CVE-2024-21538

Path to dependency file: /nexmo-changelog/package.json

Path to vulnerable library: /nexmo-changelog/package.json

Dependency Hierarchy:

-> actions-toolkit-2.1.0.tgz (Root Library)

   -> execa-1.0.0.tgz

     -> ❌ cross-spawn-6.0.6.tgz (Vulnerable Library)

High 7.5 Transitive cross-spawn-6.0.6.tgz actions-toolkit-2.1.0.tgz Transitive https://github.com/moxystudio/node-cross-spawn.git - v7.0.5,https://github.com/moxystudio/node-cross-spawn.git - v6.0.6,org.webjars.npm:cross-spawn:6.0.6 #7

✔️ Remediated vulnerabilities:

Vulnerability Vulnerable Library
CVE-2025-25290 request-3.0.2.tgz
CVE-561003-132867 tmp-0.0.33.tgz
CVE-2022-37598 uglify-js-3.7.1.tgz
GHSA-7fhm-mqm4-2wp7 acorn-6.4.0.tgz
CVE-2025-54798 tmp-0.0.33.tgz
GHSA-7fhm-mqm4-2wp7 minimist-1.2.0.tgz
GHSA-6chw-6frg-f759 acorn-6.4.0.tgz
GHSA-7fhm-mqm4-2wp7 minimist-0.0.10.tgz
CVE-2020-15366 ajv-6.10.0.tgz
CVE-2025-25285 endpoint-5.1.1.tgz
CVE-2021-23337 lodash-4.17.19.tgz
GHSA-35jh-r3h4-6jhm lodash-4.17.19.tgz
CVE-2020-28500 lodash-4.17.19.tgz
CVE-2025-69873 ajv-6.10.0.tgz
GHSA-7fhm-mqm4-2wp7 minimist-0.0.8.tgz

Base branch total remaining vulnerabilities: 97
Base branch commit: 1fa94290fb5d5a75015c22faad5467200e4eff4a


Total libraries scanned: 646

Scan token: 2431fac1a94a4f2eb21373c96eb0fcbc