Skip to content

Update dependency @crowdin/crowdin-api-client to v1.33.2 - #4

Open
dev-mend-for-github-com[bot] wants to merge 1 commit into
masterfrom
whitesource-remediate/crowdin-crowdin-api-client-1.x-lockfile
Open

Update dependency @crowdin/crowdin-api-client to v1.33.2#4
dev-mend-for-github-com[bot] wants to merge 1 commit into
masterfrom
whitesource-remediate/crowdin-crowdin-api-client-1.x-lockfile

Update dependency @crowdin/crowdin-api-client to v1.33.2

a01cb81
Select commit
Loading
Failed to load commit list.
Dev - Mend for GitHub.com / Mend Security Check failed Sep 10, 2026 in 6m 9s

Security Report

You have successfully remediated 18 vulnerabilities, but introduced 17 new vulnerabilities in this branch.

❌ New vulnerabilities:

Vulnerability Severity CVSS Score Vulnerable Library Direct Library Suggested Fix Issue
CVE-941441-362681

Path to dependency file: /website/package.json

Path to vulnerable library: /website/package.json

Dependency Hierarchy:

-> core-2.4.0.tgz (Root Library)

   -> shelljs-0.8.5.tgz

     -> glob-7.2.3.tgz

       -> ❌ once-1.4.0.tgz (Vulnerable Library)

Critical 9.8 Transitive once-1.4.0.tgz core-2.4.0.tgz None
CVE-666308-417910

Path to dependency file: /website/package.json

Path to vulnerable library: /website/package.json

Dependency Hierarchy:

-> core-2.4.0.tgz (Root Library)

   -> babel-plugin-dynamic-import-node-2.3.3.tgz

     -> object.assign-4.1.5.tgz

       -> ❌ has-symbols-1.1.0.tgz (Vulnerable Library)

Critical 9.8 Transitive has-symbols-1.1.0.tgz core-2.4.0.tgz None
CVE-2026-39834

Path to dependency file: /v2/go.mod

Path to vulnerable library: /home/wss-scanner/go/pkg/mod/cache/download/golang.org/x/crypto/@⁠v/v0.23.0.mod

Dependency Hierarchy:

-> github.com/Go-git/go-git/v5-v5.11.0 (Root Library)

   -> ❌ golang.org/x/crypto-v0.23.0 (Vulnerable Library)

Critical 9.1 Transitive golang.org/x/crypto-v0.23.0 github.com/Go-git/go-git/v5-v5.11.0 Transitive v0.52.0 None
CVE-2026-39831

Path to dependency file: /v2/go.mod

Path to vulnerable library: /home/wss-scanner/go/pkg/mod/cache/download/golang.org/x/crypto/@⁠v/v0.23.0.mod

Dependency Hierarchy:

-> github.com/Go-git/go-git/v5-v5.11.0 (Root Library)

   -> ❌ golang.org/x/crypto-v0.23.0 (Vulnerable Library)

Critical 9.1 Transitive golang.org/x/crypto-v0.23.0 github.com/Go-git/go-git/v5-v5.11.0 Transitive v0.52.0 None
CVE-2026-44728

Path to dependency file: /website/package.json

Path to vulnerable library: /website/package.json

Dependency Hierarchy:

-> core-2.4.0.tgz (Root Library)

   -> preset-env-7.24.7.tgz

     -> ❌ plugin-transform-modules-systemjs-7.24.7.tgz (Vulnerable Library)

High 8.2 Transitive plugin-transform-modules-systemjs-7.24.7.tgz core-2.4.0.tgz Transitive 7.29.4 None
CVE-2026-44973

Path to dependency file: /v2/go.mod

Path to vulnerable library: /home/wss-scanner/go/pkg/mod/cache/download/github.com/go-git/go-billy/v5/@⁠v/v5.5.0.mod

Dependency Hierarchy:

-> github.com/Go-git/go-git/v5-v5.11.0 (Root Library)

   -> ❌ github.com/go-git/go-Billy/v5-v5.5.0 (Vulnerable Library)

High 8.1 Transitive github.com/go-git/go-Billy/v5-v5.5.0 github.com/Go-git/go-git/v5-v5.11.0 None
CVE-2026-46599

Path to dependency file: /v2/go.mod

Path to vulnerable library: /home/wss-scanner/go/pkg/mod/cache/download/golang.org/x/image/@⁠v/v0.12.0.mod

Dependency Hierarchy:

-> github.com/leaanthony/winicon-v1.0.0 (Root Library)

   -> ❌ golang.org/x/image-v0.12.0 (Vulnerable Library)

High 7.5 Transitive golang.org/x/image-v0.12.0 github.com/leaanthony/winicon-v1.0.0 Transitive golang.org/x/image - v0.41.0 None
CVE-2026-46599

Path to dependency file: /v2/go.mod

Path to vulnerable library: /home/wss-scanner/go/pkg/mod/cache/download/golang.org/x/image/@⁠v/v0.12.0.mod

Dependency Hierarchy:

-> github.com/tc-hib/winres-v0.2.1 (Root Library)

   -> ❌ golang.org/x/image-v0.12.0 (Vulnerable Library)

High 7.5 Transitive golang.org/x/image-v0.12.0 github.com/tc-hib/winres-v0.2.1 Transitive golang.org/x/image - v0.41.0 None
CVE-2026-46597

Path to dependency file: /v2/go.mod

Path to vulnerable library: /home/wss-scanner/go/pkg/mod/cache/download/golang.org/x/crypto/@⁠v/v0.23.0.mod

Dependency Hierarchy:

-> github.com/Go-git/go-git/v5-v5.11.0 (Root Library)

   -> ❌ golang.org/x/crypto-v0.23.0 (Vulnerable Library)

High 7.5 Transitive golang.org/x/crypto-v0.23.0 github.com/Go-git/go-git/v5-v5.11.0 Transitive v0.52.0 None
CVE-2026-44740

Path to dependency file: /v2/go.mod

Path to vulnerable library: /home/wss-scanner/go/pkg/mod/cache/download/github.com/go-git/go-billy/v5/@⁠v/v5.5.0.mod

Dependency Hierarchy:

-> github.com/Go-git/go-git/v5-v5.11.0 (Root Library)

   -> ❌ github.com/go-git/go-Billy/v5-v5.5.0 (Vulnerable Library)

Medium 6.5 Transitive github.com/go-git/go-Billy/v5-v5.5.0 github.com/Go-git/go-git/v5-v5.11.0 None
CVE-2026-1229

Path to dependency file: /v2/go.mod

Path to vulnerable library: /home/wss-scanner/go/pkg/mod/cache/download/github.com/cloudflare/circl/@⁠v/v1.3.7.mod

Dependency Hierarchy:

-> github.com/Go-git/go-git/v5-v5.11.0 (Root Library)

   -> github.com/ProtonMail/go-crypto-v0.0.0-20230828082145-3c4c8a2d2371

     -> ❌ github.com/Cloudflare/circl-v1.3.7 (Vulnerable Library)

Medium 6.5 Transitive github.com/Cloudflare/circl-v1.3.7 github.com/Go-git/go-git/v5-v5.11.0 None
CVE-2025-27789

Path to dependency file: /website/package.json

Path to vulnerable library: /website/package.json

Dependency Hierarchy:

-> core-2.4.0.tgz (Root Library)

   -> ❌ runtime-corejs3-7.24.7.tgz (Vulnerable Library)

Medium 6.2 Transitive runtime-corejs3-7.24.7.tgz core-2.4.0.tgz Transitive 7.26.10 None
CVE-2025-27789

Path to dependency file: /website/package.json

Path to vulnerable library: /website/package.json

Dependency Hierarchy:

-> core-2.4.0.tgz (Root Library)

   -> core-7.24.7.tgz

     -> ❌ helpers-7.24.7.tgz (Vulnerable Library)

Medium 6.2 Transitive helpers-7.24.7.tgz core-2.4.0.tgz Transitive 7.26.10 None
CVE-2025-27789

Path to dependency file: /website/package.json

Path to vulnerable library: /website/package.json

Dependency Hierarchy:

-> core-2.4.0.tgz (Root Library)

   -> ❌ runtime-7.24.7.tgz (Vulnerable Library)

Medium 6.2 Transitive runtime-7.24.7.tgz core-2.4.0.tgz Transitive 7.26.10 None
CVE-2026-46598

Path to dependency file: /v2/go.mod

Path to vulnerable library: /home/wss-scanner/go/pkg/mod/cache/download/golang.org/x/crypto/@⁠v/v0.23.0.mod

Dependency Hierarchy:

-> github.com/Go-git/go-git/v5-v5.11.0 (Root Library)

   -> ❌ golang.org/x/crypto-v0.23.0 (Vulnerable Library)

Medium 5.3 Transitive golang.org/x/crypto-v0.23.0 github.com/Go-git/go-git/v5-v5.11.0 Transitive v0.52.0 None
CVE-2026-33809

Path to dependency file: /v2/go.mod

Path to vulnerable library: /home/wss-scanner/go/pkg/mod/cache/download/golang.org/x/image/@⁠v/v0.12.0.mod

Dependency Hierarchy:

-> github.com/leaanthony/winicon-v1.0.0 (Root Library)

   -> ❌ golang.org/x/image-v0.12.0 (Vulnerable Library)

Medium 5.3 Transitive golang.org/x/image-v0.12.0 github.com/leaanthony/winicon-v1.0.0 Transitive v0.38.0 None
CVE-2026-33809

Path to dependency file: /v2/go.mod

Path to vulnerable library: /home/wss-scanner/go/pkg/mod/cache/download/golang.org/x/image/@⁠v/v0.12.0.mod

Dependency Hierarchy:

-> github.com/tc-hib/winres-v0.2.1 (Root Library)

   -> ❌ golang.org/x/image-v0.12.0 (Vulnerable Library)

Medium 5.3 Transitive golang.org/x/image-v0.12.0 github.com/tc-hib/winres-v0.2.1 Transitive v0.38.0 None

✔️ Remediated vulnerabilities:

Vulnerability Vulnerable Library
CVE-2026-42039 axios-1.7.2.tgz
CVE-2026-42033 axios-1.7.2.tgz
CVE-2026-25639 axios-1.7.2.tgz
CVE-2026-44487 axios-1.7.2.tgz
CVE-2026-44496 axios-1.7.2.tgz
CVE-2025-7783 form-data-4.0.0.tgz
CVE-2026-44488 axios-1.7.2.tgz
CVE-2026-42264 axios-1.7.2.tgz
CVE-2024-39338 axios-1.7.2.tgz
CVE-2026-42037 axios-1.7.2.tgz
CVE-2025-58754 axios-1.7.2.tgz
CVE-2025-62718 axios-1.7.2.tgz
CVE-2026-42043 axios-1.7.2.tgz
CVE-2026-39865 axios-1.7.2.tgz
CVE-2026-40175 axios-1.7.2.tgz
CVE-2025-27152 axios-1.7.2.tgz
CVE-2026-67316 axios-1.7.2.tgz
CVE-2026-44486 axios-1.7.2.tgz

Base branch total remaining vulnerabilities: 132
Base branch commit: null


Total libraries scanned: 1270

Scan token: d330c6e2dc9f412cb7c03b542a30808d