Skip to content

Package advisories

npm

94advisory rows79advisories79packagesRSSas of the 2026-09-07 snapshot

An advisory is the GHSA entry a Dependabot alert links to; GitHub-reviewed only. One row is one change to one package: 26 fixed-in version changed, 68 package added later.

No rate: 35,259 advisories were compared across every ecosystem together, and the analysis carries no count of how many were npm, so nothing here divides one number by the other.

Kind of change

68 counted rows in this one change · showing 1 to 50 · newest advisory first

One change, in full: Package added to advisory: 56 packages named as affected in npm. The same change, 68 rows across 54 advisories. Back to npm

Changes to GitHub-reviewed advisories naming a package in npm. Each row gives the kind of change and the advisory it happened to. Where the same change was made to several advisories or packages at once, one row stands for all of them, says how many, and opens to every one. Then the ecosystem and package, what the advisory said beside what it says now, GitHub's severity level, and the date the advisory was published.
Package, The package the change names, or where one row stands for the same change across several packages, how many.Kind of changeAdvisory, The advisory id, or where one row stands for the same change made to several advisories, how many it stands for. An advisory id links to GitHub, and a CVE id is shown beside it where the advisory names one.What changedSeverity, GitHub's severity level for the advisory as it stands today: low, moderate, high or critical. Where one row stands for advisories at more than one level, it says how many levels, never one of them.Advisory published, The date the advisory was published. Every lag on this source is measured from it, and it is a third clock beside the CVE catalog's publication date and the date CISA added an entry to KEV. Two kinds of change also carry a date of their own: a withdrawal states its own timestamp, and a changed fix version is dated by reading back through the dated saves of the advisory file until the one where the version first reached the value it has today. A package added and a severity changed leave no commit of their own to date, so for those the date of the change is not recorded at all. That is absence, never same-day.
@remix-run/routerPackage added to advisoryGHSA-2j2x-hqr9-3h42CVE-2026-40181not named as affected when the advisory was published, now names @remix-run/routermoderate2026-06-03
flowise-componentsPackage added to advisoryGHSA-fvcw-9w9r-pxc7CVE-2026-31829not named as affected when the advisory was published, now names flowise-componentshigh2026-03-11
@azure/mcpPackage added to advisoryGHSA-hhfx-wfvq-7g9cCVE-2026-26118not named as affected when the advisory was published, now names @azure/mcphigh2026-03-10
@react-native-community/cli-server-apiPackage added to advisoryGHSA-399j-vxmf-hjvrCVE-2025-11953not named as affected when the advisory was published, now names @react-native-community/cli-server-apicritical2025-11-03
@nubosoftware/node-staticPackage added to advisoryGHSA-27w5-gj5q-82fvCVE-2025-11149not named as affected when the advisory was published, now names @nubosoftware/node-statichigh2025-09-30
@node-saml/passport-samlPackage added to advisoryGHSA-4mxg-3p6v-xgq3CVE-2025-54419not named as affected when the advisory was published, now names @node-saml/passport-samlcritical2025-07-28
passport-samlPackage added to advisoryGHSA-4mxg-3p6v-xgq3CVE-2025-54419not named as affected when the advisory was published, now names passport-samlcritical2025-07-28
got-fetchPackage added to advisoryGHSA-f29h-pxvx-f335CVE-2025-54313not named as affected when the advisory was published, now names got-fetchhigh2025-07-19
@directus/apiPackage added to advisoryGHSA-56p6-qw3c-fq2gCVE-2025-30351not named as affected when the advisory was published, now names @directus/apilow2025-03-26
@directus/typesPackage added to advisoryGHSA-56p6-qw3c-fq2gCVE-2025-30351not named as affected when the advisory was published, now names @directus/typeslow2025-03-26
@directus/appPackage added to advisoryGHSA-pmf4-v838-29hgCVE-2025-24353not named as affected when the advisory was published, now names @directus/appmoderate2025-01-23
@directus/apiPackage added to advisoryGHSA-849r-qrwj-8rv4CVE-2024-54151not named as affected when the advisory was published, now names @directus/apihigh2024-12-09
@ckeditor/ckeditor5-clipboardPackage added to advisoryGHSA-rgg8-g5x8-wr9vCVE-2024-45613not named as affected when the advisory was published, now names @ckeditor/ckeditor5-clipboardmoderate2024-09-25
@lunary/backendPackage added to advisoryGHSA-v6x6-4v4x-2fx9CVE-2024-6862not named as affected when the advisory was published, now names @lunary/backendmoderate2024-09-13
ckeditor4Package added to advisoryGHSA-7r32-vfj5-c2jvCVE-2024-43407not named as affected when the advisory was published, now names ckeditor4moderate2024-08-21
bootstrap-sassPackage added to advisoryGHSA-9mvj-f7w8-pvh2CVE-2024-6484not named as affected when the advisory was published, now names bootstrap-sassmoderate2024-07-11
@airvertco/frappejsPackage added to advisoryGHSA-gc7m-596h-x57rCVE-2024-38992not named as affected when the advisory was published, now names @airvertco/frappejshigh2024-07-01
tarPackage added to advisoryGHSA-f5x3-32g6-xq36CVE-2024-28863not named as affected when the advisory was published, now names tarmoderate2024-03-22
remark-images-downloadPackage added to advisoryGHSA-mf74-qq7w-6j7vnot named as affected when the advisory was published, now names remark-images-downloadmoderate2024-02-03
babel-traversePackage added to advisoryGHSA-67hx-6x53-jw92CVE-2023-45133not named as affected when the advisory was published, now names babel-traversecritical2023-10-16
froala-editorPackage added to advisoryGHSA-hvpq-7vcc-5hj5CVE-2023-41592not named as affected when the advisory was published, now names froala-editormoderate2023-09-15
electronPackage added to advisoryGHSA-j7hp-h8jx-5pprCVE-2023-4863not named as affected when the advisory was published, now names electronhigh2023-09-12
@cypress/requestPackage added to advisoryGHSA-p8p7-x288-28g6CVE-2023-28155not named as affected when the advisory was published, now names @cypress/requestmoderate2023-03-16
hoekPackage added to advisoryGHSA-c429-5p7v-vgjpCVE-2020-36604not named as affected when the advisory was published, now names hoekhigh2022-09-25
converse.jsPackage added to advisoryGHSA-mv4h-qm24-x4ghCVE-2018-6591not named as affected when the advisory was published, now names converse.jsmoderate2022-05-14
@uppy/companionPackage added to advisoryGHSA-x8rq-rc7x-5fg5CVE-2022-0086not named as affected when the advisory was published, now names @uppy/companionhigh2022-01-06
lodash-esPackage added to advisoryGHSA-29mw-wpgm-hmr9CVE-2020-28500not named as affected when the advisory was published, now names lodash-esmoderate2022-01-06
lodash.trimPackage added to advisoryGHSA-29mw-wpgm-hmr9CVE-2020-28500not named as affected when the advisory was published, now names lodash.trimmoderate2022-01-06
lodash.trimendPackage added to advisoryGHSA-29mw-wpgm-hmr9CVE-2020-28500not named as affected when the advisory was published, now names lodash.trimendmoderate2022-01-06
strapi-adminPackage added to advisoryGHSA-23fp-fmrv-f5pxCVE-2020-8123not named as affected when the advisory was published, now names strapi-adminmoderate2021-12-10
swagger-ui-reactPackage added to advisoryGHSA-qrmm-w75w-3wpxnot named as affected when the advisory was published, now names swagger-ui-reactmoderate2021-12-09
org.webjars.npm:json-pointerPackage added to advisoryGHSA-282f-qqgm-c34qCVE-2021-23807not named as affected when the advisory was published, now names org.webjars.npm:json-pointermoderate2021-11-08
@tarojs/helperPackage added to advisoryGHSA-468q-v4jj-485hCVE-2021-3804not named as affected when the advisory was published, now names @tarojs/helperhigh2021-09-20
@openzeppelin/contracts-upgradeablePackage added to advisoryGHSA-5vp3-v4hc-gx76CVE-2021-41264not named as affected when the advisory was published, now names @openzeppelin/contracts-upgradeablecritical2021-09-15
degeneratorPackage added to advisoryGHSA-9j49-mfvp-vmhmCVE-2021-23406not named as affected when the advisory was published, now names degeneratorhigh2021-09-02
@xmldom/xmldomPackage added to advisoryGHSA-5fg8-2547-mr8qCVE-2021-32796not named as affected when the advisory was published, now names @xmldom/xmldommoderate2021-08-03
@shopify/koa-shopify-authPackage added to advisoryGHSA-jqh7-w5pr-cr56CVE-2020-8176not named as affected when the advisory was published, now names @shopify/koa-shopify-authmoderate2021-05-17
lodash-esPackage added to advisoryGHSA-35jh-r3h4-6jhmCVE-2021-23337not named as affected when the advisory was published, now names lodash-eshigh2021-05-06
lodash-templatePackage added to advisoryGHSA-35jh-r3h4-6jhmCVE-2021-23337not named as affected when the advisory was published, now names lodash-templatehigh2021-05-06
lodash.templatePackage added to advisoryGHSA-35jh-r3h4-6jhmCVE-2021-23337not named as affected when the advisory was published, now names lodash.templatehigh2021-05-06
@scullyio/ng-libPackage added to advisoryGHSA-r96p-v3cr-gfv8CVE-2020-28470not named as affected when the advisory was published, now names @scullyio/ng-libhigh2021-04-13
gitingPackage added to advisoryGHSA-53xj-v576-3ch2CVE-2019-10802not named as affected when the advisory was published, now names gitingcritical2021-04-13
@hapi/pezPackage added to advisoryGHSA-g9cg-h3jm-cwrcnot named as affected when the advisory was published, now names @hapi/pezhigh2020-09-03
pezPackage added to advisoryGHSA-g64q-3vg8-8f93not named as affected when the advisory was published, now names pezhigh2020-09-03
contentPackage added to advisoryGHSA-5854-jvxx-2cg9not named as affected when the advisory was published, now names contenthigh2020-09-03
@hapi/contentPackage added to advisoryGHSA-3wqh-h42r-x8fqnot named as affected when the advisory was published, now names @hapi/contenthigh2020-09-03
ag-gridPackage added to advisoryGHSA-7p6w-x2gr-rrf8not named as affected when the advisory was published, now names ag-gridhigh2020-09-02
lodash-esPackage added to advisoryGHSA-p6mc-m468-83gwCVE-2020-8203not named as affected when the advisory was published, now names lodash-eshigh2020-07-15
lodash.pickPackage added to advisoryGHSA-p6mc-m468-83gwCVE-2020-8203not named as affected when the advisory was published, now names lodash.pickhigh2020-07-15
lodash.setPackage added to advisoryGHSA-p6mc-m468-83gwCVE-2020-8203not named as affected when the advisory was published, now names lodash.sethigh2020-07-15

Every change counted from this source is on this page, so an advisory with no row here had no change of that kind. No finding here is not an all clear. It means this check found nothing in the history it can see, not that nothing happened.

A grouped row is the same change, repeated: where one change was made to many packages or advisories, the advisory column says how many it stands for and opens to every one. The change is identical; it was not necessarily made in one act.

A fixed-in version is compared within one release branch: an advisory listing a fix for 4.1.x and another for 4.2.x states two, and taking the highest version across the package would report a newly added branch as though an existing branch's fix had changed.

10 more advisories that name a package in npm had the severity changed, or the whole advisory withdrawn. None of it is counted in any figure above. Open to read it.

A severity level and a withdrawal belong to the whole advisory. The advisory database records neither against a package, so neither can be attributed to an ecosystem. These 10 rows are here for one reason: the same advisory also names a package in npm in the table above. The other 3,170 of the 3,180 cannot be placed in an ecosystem at all.

Severity changes and withdrawals recorded against advisories that also name a package in npm. These rows name no ecosystem of their own and are not counted in this page's ecosystem figures.
Kind of changeAdvisoryWhat changedSeverityAdvisory published
Advisory withdrawnGHSA-pj86-cfqh-vqx6CVE-2024-51999withdrawn 2025-12-02low2025-12-01
Advisory severity changedGHSA-xffm-g5w8-qvg7stated at publication HIGH, now states LOWA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.low2025-07-18
Advisory withdrawnGHSA-v6x6-4v4x-2fx9CVE-2024-6862withdrawn 2025-06-20moderate2024-09-13
Advisory withdrawnGHSA-9mvj-f7w8-pvh2CVE-2024-6484withdrawn 2025-09-11moderate2024-07-11
Advisory severity changedGHSA-gc7m-596h-x57rCVE-2024-38992stated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.high2024-07-01
Advisory severity changedGHSA-j7hp-h8jx-5pprCVE-2023-4863stated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.high2023-09-12
Advisory severity changedGHSA-4cpg-3vgw-4877CVE-2022-22912stated at publication HIGH, now states CRITICALNo CVSS vector was stated in the first observed version.critical2022-02-18
Advisory severity changedGHSA-53xj-v576-3ch2CVE-2019-10802stated at publication HIGH, now states CRITICALThe severity label changed while the stated CVSS vectors stayed the same.critical2021-04-13
Advisory severity changedGHSA-cqp5-m4pq-gfgpCVE-2018-3723stated at publication LOW, now states HIGHNo CVSS vector was stated in the first observed version.high2018-07-26
Advisory severity changedGHSA-rch9-xh7r-mqgwCVE-2018-3717stated at publication HIGH, now states MODERATENo CVSS vector was stated in the first observed version.moderate2018-07-26

Data sources and quality

Every figure on this page counts rows keyed to a GitHub advisory, naming an ecosystem and a package; none counts CVE records or is added to the record counts elsewhere on this site. Rows, advisories and packages are three different numbers, never added; that the advisory and package counts match here is a coincidence, one advisory naming one package each time.

Not checked: GitHub-reviewed advisories only. An advisory GitHub never reviewed, and an ecosystem it does not review, produce no row at all, so an ecosystem missing from these figures is not evidence that its advisories held.

How advisories are compared, in full →

Advisory data from the GitHub Advisory Database, used under CC-BY-4.0. Not affiliated with or endorsed by GitHub.

Shipped snapshot computed 2026-09-07 from catalog commit ed5547afbae2. Real findings, not live ones: records amended since are not reflected. A later fix version is evidence that the record changed, not evidence that the first fix was incomplete.