Skip to content

NPM Audit Report

Generation Date: 2.4.2026 - 15:15:03

Vulnerabilities

Vulnerabilities are known security weaknesses of dependencies and are categorized by severity:

  • Critical: Exploitable with severe impact, requiring immediate action.
  • High: Significant risk, should be addressed promptly.
  • Moderate: Requires specific conditions to exploit, but should still be remediated.
  • Low: Minor risk with limited impact.
PackageSeverityURLRangeEffectsFix Available
preacthighhttps://github.com/advisories/GHSA-36hm-qxxp-pg3m10.28.0 - 10.28.1-true
rolluphighhttps://github.com/advisories/GHSA-mw96-cpmx-2vgc4.0.0 - 4.58.0-true
esbuildmoderatehttps://github.com/advisories/GHSA-67mh-4wv8-2f99<=0.24.2vitevitepress@0.1.1
vitemoderate-0.11.0 - 6.1.6vitepressvitepress@0.1.1
vitepressmoderate-0.2.0 - 1.6.4-vitepress@0.1.1

Outdated Dependencies

Regular updates are a core requirement of the EU Cyber Resilience Act (CRA), which mandates timely delivery of security patches. Keeping dependencies current reduces the attack surface and ensures the project benefits from the latest improvements.

Update TypeCountRisk
Major (breaking changes possible)3Test thoroughly
Minor (new features)3Low risk
Patch (bug fixes)3Safe to update
Total outdated9

Major Updates

Major version changes may include breaking API changes. Review changelogs before updating.

PackageCurrentWantedLatest
echarts5.6.05.6.06.0.0
vue-i18n9.14.59.14.511.3.0
vuetify3.11.43.12.54.0.5

Minor Updates

Minor updates add new features in a backward-compatible manner.

PackageCurrentWantedLatest
@powersync/web1.35.01.37.11.37.1
@supabase/supabase-js2.89.02.101.12.101.1
maplibre-gl5.15.05.21.15.21.1

Patch Updates

Patch updates contain bug fixes and are generally safe to apply.

PackageCurrentWantedLatest
@turf/turf7.3.17.3.47.3.4
esbuild0.27.20.27.50.27.5
vite-plugin-vuetify2.1.22.1.32.1.3