Skip to content

Add demo-nyc-neighborhood-finder - #29

Open
chriswhong wants to merge 5 commits into
mainfrom
cw/demo-nyc-neighborhood-finder
Open

Add demo-nyc-neighborhood-finder#29
chriswhong wants to merge 5 commits into
mainfrom
cw/demo-nyc-neighborhood-finder

Configure vite to load env from root directory

ec73837
Select commit
Loading
Failed to load commit list.
OX Security / ox-security/scan completed Sep 8, 2026 in 1m 13s

Scan complete: no blocking issues found

OX Security Logo

Successfully scanned changes introduced in a pull request into main from cw/demo-nyc-neighborhood-finder.

Internal scan identifier: 2a3d97f0-678a-41fe-80a9-f311037b8567.

Total issues Blocking issues Scan status
10 0 ✔️
Category Issues
Open Source Security 10

See all issues found during this scan in the OX Security Application.

Detailed information
Issue #1
Namevite@5.4.11 • 12 CVEs • KEV - Known Exploited • Public Exploit
StatusOld
EnforcementMonitor
SeverityCritical
CategoryOpen Source Security
Source toolsOX Open Source Security
RecommendationDevelopment dependencies are normally not critical to resolve right away, however, it is safer to use a library with less security issues.

• Current Dependency: vite@5.4.11
• Recommended Upgrade: vite@8.2.2
• vite@8.2.2 resolves 1 of 1 development vulnerabilities

Upgrading to vite@8.2.2 will resolve ALL known vulnerabilities in your current dependency.
1 aggregation
FileMatch
yarn.lockvite@5.4.11

Issue #2
Namelodash@4.17.21 • 3 CVEs • EPSS Low
StatusOld
EnforcementMonitor
SeverityHigh
CategoryOpen Source Security
Source toolsOX Open Source Security
RecommendationDevelopment dependencies are normally not critical to resolve right away, however, it is safer to use a library with less security issues.

• Current Dependency: lodash@4.17.21
• Recommended Upgrade: lodash@4.18.1
• lodash@4.18.1 resolves 1 of 1 development vulnerabilities

Upgrading to lodash@4.18.1 will resolve ALL known vulnerabilities in your current dependency.
1 aggregation
FileMatch
yarn.locklodash@4.17.21

Issue #3
Namejs-yaml@4.1.0 • 4 CVEs • Public Exploit • EPSS Low
StatusOld
EnforcementMonitor
SeverityHigh
CategoryOpen Source Security
Source toolsOX Open Source Security
RecommendationDevelopment dependencies are normally not critical to resolve right away, however, it is safer to use a library with less security issues.

• Current Dependency: js-yaml@4.1.0
• Recommended Upgrade: js-yaml@4.3.2
• js-yaml@4.3.2 resolves 1 of 1 development vulnerabilities

Upgrading to js-yaml@4.3.2 will resolve ALL known vulnerabilities in your current dependency.
1 aggregation
FileMatch
yarn.lockjs-yaml@4.1.0

Issue #4
Nameform-data@3.0.2 • 2 CVEs • EPSS Low
StatusOld
EnforcementMonitor
SeverityHigh
CategoryOpen Source Security
Source toolsOX Open Source Security
RecommendationDevelopment dependencies are normally not critical to resolve right away, however, it is safer to use a library with less security issues.

• Current Dependency: form-data@3.0.2
• Recommended Upgrade: form-data@3.0.5
• form-data@3.0.5 resolves 1 of 1 development vulnerabilities

Upgrading to form-data@3.0.5 will resolve ALL known vulnerabilities in your current dependency.
1 aggregation
FileMatch
yarn.lockform-data@3.0.2

Issue #5
Namerollup@4.30.1 • 1 CVE • Public Exploit • EPSS Low
StatusOld
EnforcementMonitor
SeverityHigh
CategoryOpen Source Security
Source toolsOX Open Source Security
RecommendationDevelopment dependencies are normally not critical to resolve right away, however, it is safer to use a library with less security issues.

• Current Dependency: rollup@4.30.1
• Recommended Upgrade: rollup@4.63.1
• rollup@4.63.1 resolves 1 of 1 development vulnerabilities

Upgrading to rollup@4.63.1 will resolve ALL known vulnerabilities in your current dependency.
1 aggregation
FileMatch
yarn.lockrollup@4.30.1

Issue #6
Namerollup@4.52.3 • 1 CVE • Public Exploit • EPSS Low
StatusOld
EnforcementMonitor
SeverityHigh
CategoryOpen Source Security
Source toolsOX Open Source Security
RecommendationDevelopment dependencies are normally not critical to resolve right away, however, it is safer to use a library with less security issues.

• Current Dependency: rollup@4.52.3
• Recommended Upgrade: rollup@4.63.1
• rollup@4.63.1 resolves 1 of 1 development vulnerabilities

Upgrading to rollup@4.63.1 will resolve ALL known vulnerabilities in your current dependency.
1 aggregation
FileMatch
yarn.lockrollup@4.52.3

Issue #7
Nameflatted@3.3.2 • 2 CVEs • Public Exploit • EPSS Low
StatusOld
EnforcementMonitor
SeverityHigh
CategoryOpen Source Security
Source toolsOX Open Source Security
RecommendationDevelopment dependencies are normally not critical to resolve right away, however, it is safer to use a library with less security issues.

• Current Dependency: flatted@3.3.2
• Recommended Upgrade: flatted@3.4.4
• flatted@3.4.4 resolves 1 of 1 development vulnerabilities

Upgrading to flatted@3.4.4 will resolve ALL known vulnerabilities in your current dependency.
1 aggregation
FileMatch
yarn.lockflatted@3.3.2

Issue #8
Namepostcss@8.4.49 • 4 CVEs • Public Exploit • EPSS Low
StatusOld
EnforcementMonitor
SeverityHigh
CategoryOpen Source Security
Source toolsOX Open Source Security
RecommendationDevelopment dependencies are normally not critical to resolve right away, however, it is safer to use a library with less security issues.

• Current Dependency: postcss@8.4.49
• Recommended Upgrade: postcss@8.5.26
• postcss@8.5.26 resolves 1 of 1 development vulnerabilities

Upgrading to postcss@8.5.26 will resolve ALL known vulnerabilities in your current dependency.
1 aggregation
FileMatch
yarn.lockpostcss@8.4.49

Issue #9
Namepostcss@8.5.6 • 4 CVEs • Public Exploit • EPSS Low
StatusOld
EnforcementMonitor
SeverityHigh
CategoryOpen Source Security
Source toolsOX Open Source Security
RecommendationDevelopment dependencies are normally not critical to resolve right away, however, it is safer to use a library with less security issues.

• Current Dependency: postcss@8.5.6
• Recommended Upgrade: postcss@8.5.26
• postcss@8.5.26 resolves 1 of 1 development vulnerabilities

Upgrading to postcss@8.5.26 will resolve ALL known vulnerabilities in your current dependency.
1 aggregation
FileMatch
yarn.lockpostcss@8.5.6

Issue #10
Namejs-yaml@4.1.1 • 3 CVEs • Public Exploit • EPSS Low
StatusOld
EnforcementMonitor
SeverityHigh
CategoryOpen Source Security
Source toolsOX Open Source Security
RecommendationDevelopment dependencies are normally not critical to resolve right away, however, it is safer to use a library with less security issues.

• Current Dependency: js-yaml@4.1.1
• Recommended Upgrade: js-yaml@4.3.2
• js-yaml@4.3.2 resolves 1 of 1 development vulnerabilities

Upgrading to js-yaml@4.3.2 will resolve ALL known vulnerabilities in your current dependency.
1 aggregation
FileMatch
yarn.lockjs-yaml@4.1.1

Annotations

Check warning on line 1 in yarn.lock

See this annotation in the file changed.

@ox-security ox-security / ox-security/scan

vite@5.4.11 • 12 CVEs • KEV - Known Exploited • Public Exploit

Development dependencies are normally not critical to resolve right away, however, it is safer to use a library with less security issues.

• Current Dependency: vite@5.4.11
• Recommended Upgrade: vite@8.2.2
• vite@8.2.2 resolves 1 of 1 development vulnerabilities

Upgrading to vite@8.2.2 will resolve ALL known vulnerabilities in your current dependency.

Check warning on line 1 in yarn.lock

See this annotation in the file changed.

@ox-security ox-security / ox-security/scan

lodash@4.17.21 • 3 CVEs • EPSS Low

Development dependencies are normally not critical to resolve right away, however, it is safer to use a library with less security issues.

• Current Dependency: lodash@4.17.21
• Recommended Upgrade: lodash@4.18.1
• lodash@4.18.1 resolves 1 of 1 development vulnerabilities

Upgrading to lodash@4.18.1 will resolve ALL known vulnerabilities in your current dependency.

Check warning on line 1 in yarn.lock

See this annotation in the file changed.

@ox-security ox-security / ox-security/scan

js-yaml@4.1.0 • 4 CVEs • Public Exploit • EPSS Low

Development dependencies are normally not critical to resolve right away, however, it is safer to use a library with less security issues.

• Current Dependency: js-yaml@4.1.0
• Recommended Upgrade: js-yaml@4.3.2
• js-yaml@4.3.2 resolves 1 of 1 development vulnerabilities

Upgrading to js-yaml@4.3.2 will resolve ALL known vulnerabilities in your current dependency.

Check warning on line 1 in yarn.lock

See this annotation in the file changed.

@ox-security ox-security / ox-security/scan

form-data@3.0.2 • 2 CVEs • EPSS Low

Development dependencies are normally not critical to resolve right away, however, it is safer to use a library with less security issues.

• Current Dependency: form-data@3.0.2
• Recommended Upgrade: form-data@3.0.5
• form-data@3.0.5 resolves 1 of 1 development vulnerabilities

Upgrading to form-data@3.0.5 will resolve ALL known vulnerabilities in your current dependency.

Check warning on line 1 in yarn.lock

See this annotation in the file changed.

@ox-security ox-security / ox-security/scan

rollup@4.30.1 • 1 CVE • Public Exploit • EPSS Low

Development dependencies are normally not critical to resolve right away, however, it is safer to use a library with less security issues.

• Current Dependency: rollup@4.30.1
• Recommended Upgrade: rollup@4.63.1
• rollup@4.63.1 resolves 1 of 1 development vulnerabilities

Upgrading to rollup@4.63.1 will resolve ALL known vulnerabilities in your current dependency.

Check warning on line 1 in yarn.lock

See this annotation in the file changed.

@ox-security ox-security / ox-security/scan

rollup@4.52.3 • 1 CVE • Public Exploit • EPSS Low

Development dependencies are normally not critical to resolve right away, however, it is safer to use a library with less security issues.

• Current Dependency: rollup@4.52.3
• Recommended Upgrade: rollup@4.63.1
• rollup@4.63.1 resolves 1 of 1 development vulnerabilities

Upgrading to rollup@4.63.1 will resolve ALL known vulnerabilities in your current dependency.

Check warning on line 1 in yarn.lock

See this annotation in the file changed.

@ox-security ox-security / ox-security/scan

flatted@3.3.2 • 2 CVEs • Public Exploit • EPSS Low

Development dependencies are normally not critical to resolve right away, however, it is safer to use a library with less security issues.

• Current Dependency: flatted@3.3.2
• Recommended Upgrade: flatted@3.4.4
• flatted@3.4.4 resolves 1 of 1 development vulnerabilities

Upgrading to flatted@3.4.4 will resolve ALL known vulnerabilities in your current dependency.

Check warning on line 1 in yarn.lock

See this annotation in the file changed.

@ox-security ox-security / ox-security/scan

postcss@8.4.49 • 4 CVEs • Public Exploit • EPSS Low

Development dependencies are normally not critical to resolve right away, however, it is safer to use a library with less security issues.

• Current Dependency: postcss@8.4.49
• Recommended Upgrade: postcss@8.5.26
• postcss@8.5.26 resolves 1 of 1 development vulnerabilities

Upgrading to postcss@8.5.26 will resolve ALL known vulnerabilities in your current dependency.

Check warning on line 1 in yarn.lock

See this annotation in the file changed.

@ox-security ox-security / ox-security/scan

postcss@8.5.6 • 4 CVEs • Public Exploit • EPSS Low

Development dependencies are normally not critical to resolve right away, however, it is safer to use a library with less security issues.

• Current Dependency: postcss@8.5.6
• Recommended Upgrade: postcss@8.5.26
• postcss@8.5.26 resolves 1 of 1 development vulnerabilities

Upgrading to postcss@8.5.26 will resolve ALL known vulnerabilities in your current dependency.

Check warning on line 1 in yarn.lock

See this annotation in the file changed.

@ox-security ox-security / ox-security/scan

js-yaml@4.1.1 • 3 CVEs • Public Exploit • EPSS Low

Development dependencies are normally not critical to resolve right away, however, it is safer to use a library with less security issues.

• Current Dependency: js-yaml@4.1.1
• Recommended Upgrade: js-yaml@4.3.2
• js-yaml@4.3.2 resolves 1 of 1 development vulnerabilities

Upgrading to js-yaml@4.3.2 will resolve ALL known vulnerabilities in your current dependency.