Skip to content

Update README.md

9d4d4f1
Select commit
Loading
Failed to load commit list.
Merged

Update README.md #8

Update README.md
9d4d4f1
Select commit
Loading
Failed to load commit list.
Veracode-Workflow-App-Preprod / Veracode Software Composition Analysis failed Oct 28, 2025 in 1m 10s

Veracode Software Composition Analysis

Veracode SCA agent scanning engine ready
Searching for supported projects (this may take a minute)...
[Rake Native Collector]Scanning /home/runner/work/veracode/veracode
[Yarn]         Scanning /home/runner/work/veracode/veracode
[Gem]          Scanning /home/runner/work/veracode/veracode
Processing results...
Processing results complete

Summary Report
Scan ID                                               f3bf3fcd-1636-49bc-81fc-e3de127b6837
Scan Date & Time                                      Oct 28 2025 01:59PM UTC
Account type                                          ENTERPRISE
Scan engine                                           3.8.108 (latest 3.8.108)
Analysis time                                         43 seconds
User                                                  runner
Project                                               /home/runner/work/veracode/veracode
Package Manager(s)                                    Yarn, Gem, Rake Native Collector

Open-Source Libraries
Total Libraries                                       1529
Direct Libraries                                      198
Transitive Libraries                                  1354
Vulnerable Libraries                                  44

Security
With Vulnerable Methods                               0
Critical Risk Vulnerabilities                         6
High Risk Vulnerabilities                             40
Medium Risk Vulnerabilities                           36
Low Risk Vulnerabilities                              3

Vulnerabilities - Public Data
CVE-2024-48910                                        Critical Risk     Prototype Pollution                                  dompurify 2.2.7
CVE-2025-6545                                         Critical Risk     Signature Spoofing                                   pbkdf2 3.1.2
CVE-2024-48910                                        Critical Risk     Prototype Pollution                                  dompurify 2.3.6
CVE-2024-48949                                        Critical Risk     Improper Verification Of Cryptographic Signature     elliptic 6.5.4
CVE-2024-42461                                        Critical Risk     ECDSA Signature Malleability                         elliptic 6.5.4
CVE-2025-27610                                        High Risk         Path Traversal                                       rack 2.2.9
CVE-2025-46727                                        High Risk         Denial Of Service (DoS)                              rack 2.2.9
CVE-2024-21538                                        High Risk         Regular Expression Denial Of Service (ReDoS)         cross-spawn 6.0.5
CVE-2025-24928                                        High Risk         Stack-based Buffer Overflow                          nokogiri 1.16.6
CVE-2024-56171                                        High Risk         Use After Free                                       nokogiri 1.16.6
CVE-2024-45801                                        High Risk         Cross Site Scripting(XSS)                            dompurify 2.2.7
CVE-2024-7254                                         High Risk         Stack Overflow                                       google-protobuf 3.25.3
CVE-2024-47220                                        High Risk         HTTP Request Smuggling (HRS)                         webrick 1.8.1
CVE-2023-45133                                        High Risk         Arbitrary Code Execution                             @babel/traverse 7.18.8
CVE-2025-6547                                         High Risk         Signature Spoofing                                   pbkdf2 3.1.2
CVE-2022-25858                                        High Risk         Regular Expression Denial Of Service (ReDoS)         terser 5.14.1
CVE-2022-25883                                        High Risk         Regular Expression Denial Of Service (ReDoS)         semver 6.3.0
CVE-2021-3807                                         High Risk         Regular Expression Denial Of Service (ReDoS)         ansi-regex 4.1.0
CVE-2022-25883                                        High Risk         Regular Expression Denial Of Service (ReDoS)         semver 5.7.1
CVE-2024-4068                                         High Risk         Memory Exhaustion                                    braces 3.0.2
CVE-2025-58754                                        High Risk         Denial Of Service (DoS)                              axios 1.6.0
CVE-2024-39338                                        High Risk         Server-Side Request Forgery (SSRF)                   axios 1.6.0
CVE-2025-27152                                        High Risk         Server-Side Request Forgery (SSRF)                   axios 1.6.0
CVE-2024-45801                                        High Risk         Cross Site Scripting(XSS)                            dompurify 2.3.6
CVE-2024-21529                                        High Risk         Prototype Pollution                                  dset 3.1.2
CVE-2021-3803                                         High Risk         Regular Expression Denial Of Service (ReDoS)         nth-check 1.0.2
CVE-2024-41128                                        High Risk         Regular Expression Denial Of Service (ReDoS)         actionpack 7.0.8.4
CVE-2024-47887                                        High Risk         Regular Expression Denial Of Service (ReDoS)         actionpack 7.0.8.4
CVE-2022-37599                                        High Risk         Regular Expression Denial Of Service (ReDoS)         loader-utils 2.0.0
CVE-2022-37603                                        High Risk         Regular Expression Denial Of Service (ReDoS)         loader-utils 2.0.0
CVE-2022-46175                                        High Risk         Prototype Pollution                                  json5 2.2.0
CVE-2024-47889                                        High Risk         Regular Expression Denial Of Service (ReDoS)         actionmailer 7.0.8.4
CVE-2024-21529                                        High Risk         Prototype Pollution                                  dset 3.1.3
CVE-2023-45133                                        High Risk         Arbitrary Code Execution                             @babel/traverse 7.21.4
CVE-2024-43380                                        High Risk         Denial Of Service (DoS)                              fugit 1.9.0
CVE-2024-4068                                         High Risk         Memory Exhaustion                                    braces 2.3.2
CVE-2024-47888                                        High Risk         Regular Expression Denial Of Service (ReDoS)         actiontext 7.0.8.4
CVE-2025-43857                                        High Risk         Denial Of Service (DoS)                              net-imap 0.4.12
CVE-2025-7783                                         High Risk         HTTP Parameter Pollution                             form-data 4.0.0
CVE-2024-41946                                        High Risk         Denial Of Service (DoS)                              rexml 3.3.2
CVE-2024-41123                                        High Risk         Denial Of Service (DoS)                              rexml 3.3.2
CVE-2024-49761                                        High Risk         Regular Expression Denial Of Service (ReDoS)         rexml 3.3.2
CVE-2025-27111                                        Medium Risk       Log Injection                                        rack 2.2.9
CVE-2025-25184                                        Medium Risk       Log Injection                                        rack 2.2.9
CVE-2025-32441                                        Medium Risk       Session Fixation                                     rack 2.2.9
CVE-2024-11831                                        Medium Risk       Cross-site Scripting (XSS)                           serialize-javascript 5.0.1
CVE-2025-26791                                        Medium Risk       Mutation Cross-site Scripting (mXSS)                 dompurify 2.2.7
CVE-2024-53987                                        Medium Risk       Cross Site Scripting                                 rails-html-sanitizer 1.6.0
CVE-2024-53985                                        Medium Risk       Cross-site Scripting (XSS)                           rails-html-sanitizer 1.6.0
CVE-2024-53988                                        Medium Risk       Cross Site Scripting                                 rails-html-sanitizer 1.6.0
CVE-2024-53989                                        Medium Risk       Cross-site Scripting (XSS)                           rails-html-sanitizer 1.6.0
CVE-2024-53986                                        Medium Risk       Cross Site Scripting                                 rails-html-sanitizer 1.6.0
CVE-2024-11831                                        Medium Risk       Cross-site Scripting (XSS)                           serialize-javascript 4.0.0
CVE-2022-21670                                        Medium Risk       Regular Expression Denial Of Service (ReDoS)         markdown-it 10.0.0
CVE-2025-6442                                         Medium Risk       HTTP Request Smuggling (HRS)                         webrick 1.8.1
CVE-2024-45614                                        Medium Risk       HTTP Header Injection                                puma 6.4.2
CVE-2024-4067                                         Medium Risk       Regular Expression Denial Of Service (ReDoS)         micromatch 3.1.10
CVE-2024-57965                                        Medium Risk       Cross-Site Scripting (XSS)                           axios 1.6.0
CVE-2024-4067                                         Medium Risk       Regular Expression Denial Of Service (ReDoS)         micromatch 4.0.5
CVE-2025-26791                                        Medium Risk       Mutation Cross-site Scripting (mXSS)                 dompurify 2.3.6
CVE-2024-54133                                        Medium Risk       Cross-Site Scripting (XSS)                           actionpack 7.0.8.4
CVE-2025-27221                                        Medium Risk       Authentication Credential Leakage                    uri 0.13.0
CVE-2025-55193                                        Medium Risk       Improper Neutralization                              activerecord 7.0.8.4
CVE-2024-6783                                         Medium Risk       Cross Site Scripting (XSS)                           vue-template-compiler 2.6.12
CVE-2024-6783                                         Medium Risk       Cross Site Scripting (XSS)                           vue-template-compiler 2.7.16
CVE-2024-42459                                        Medium Risk       Signature Malleability                               elliptic 6.5.4
CVE-2024-42460                                        Medium Risk       ECDSA Signature Malleability                         elliptic 6.5.4
CVE-2023-44270                                        Medium Risk       Improper Input Validation                            postcss 7.0.39
CVE-2024-7246                                         Medium Risk       Information Disclosure                               grpc 1.62.0
CVE-2024-55565                                        Medium Risk       Mishandling Non-integer Values                       nanoid 3.3.7
CVE-2025-25186                                        Medium Risk       Denial Of Service                                    net-imap 0.4.12
CVE-2024-6783                                         Medium Risk       Cross Site Scripting (XSS)                           vue 2.7.16
CVE-2024-6783                                         Medium Risk       Cross Site Scripting (XSS)                           vue 2.6.12
CVE-2024-43398                                        Medium Risk       Denial Of Service (DoS)                              rexml 3.3.2
CVE-2025-54314                                        Low Risk          Command Injection                                    thor 1.3.1
CVE-2025-5889                                         Low Risk          Regular Expression Denial Of Service (ReDoS)         brace-expansion 1.1.11
CVE-2024-48948                                        Low Risk          Improper Verification Of Cryptographic Signature     elliptic 6.5.4

Vulnerabilities - Premium Data
NO-CVE                                                Critical Risk     Information Disclosure                               elliptic 6.5.4
NO-CVE                                                High Risk         Command Injection                                    activestorage 7.0.8.4
NO-CVE                                                High Risk         Prototype Pollution                                  axios 1.6.0
NO-CVE                                                High Risk         Prototype Pollution                                  unset-value 1.0.0
NO-CVE                                                Medium Risk       Prototype Pollution                                  @sentry/browser 6.19.7
NO-CVE                                                Medium Risk       Regular Expression Denial Of Service (ReDoS)         axios 1.6.0
NO-CVE                                                Medium Risk       Memory Leak                                          inflight 1.0.6
NO-CVE                                                Medium Risk       Cross-site Scripting (XSS)                           vuex-router-sync 4.1.3

Licenses
Unique Library Licenses                               19
Unique Libraries Using GPL                            2
Unique Libraries With High Risk License               5
Unique Libraries With Medium Risk License             4
Unique Libraries With Low Risk License                1520
Unique Libraries With Multiple Licenses               32
Unique Libraries With Unassessable License            0
Unique Libraries With Unrecognizable License          4

Issues
Issue ID     Issue Type          Severity    Description                                                         Library Name & Version In Use
461531081    Vulnerability       3.1         CVE-2024-48948: Improper Verification Of Cryptographic Signature    elliptic 6.5.4
461531082    Vulnerability       3.1         CVE-2025-5889: Regular Expression Denial Of Service (ReDoS)         brace-expansion 1.1.11
461531083    Vulnerability       2.8         CVE-2025-54314: Command Injection                                   thor 1.3.1
461531084    Vulnerability       6.1         NO-CVE: Cross-site Scripting (XSS)                                  vuex-router-sync 4.1.3
461532035    Vulnerability       5.3         CVE-2022-21670: Regular Expression Denial Of Service (ReDoS)        markdown-it 10.0.0
461532036    Vulnerability       6.2         NO-CVE: Memory Leak                                                 inflight 1.0.6
461532037    Vulnerability       5.3         CVE-2023-44270: Improper Input Validation                           postcss 7.0.39
461532038    Vulnerability       5.3         NO-CVE: Regular Expression Denial Of Service (ReDoS)                axios 1.6.0
461532039    Vulnerability       5.3         CVE-2024-4067: Regular Expression Denial Of Service (ReDoS)         micromatch 3.1.10
461532040    Vulnerability       5.3         CVE-2024-4067: Regular Expression Denial Of Service (ReDoS)         micromatch 4.0.5
461532041    Vulnerability       4.8         CVE-2024-6783: Cross Site Scripting (XSS)                           vue-template-compiler 2.7.16
461532042    Vulnerability       4.8         CVE-2024-6783: Cross Site Scripting (XSS)                           vue 2.7.16
461532043    Vulnerability       4.8         CVE-2024-6783: Cross Site Scripting (XSS)                           vue-template-compiler 2.6.12
461532044    Vulnerability       4.8         CVE-2024-6783: Cross Site Scripting (XSS)                           vue 2.6.12
461532045    Vulnerability       5.3         CVE-2024-42459: Signature Malleability                              elliptic 6.5.4
461532046    Vulnerability       5.3         CVE-2024-42460: ECDSA Signature Malleability                        elliptic 6.5.4
461532047    Vulnerability       5.3         CVE-2024-7246: Information Disclosure                               grpc 1.62.0
461532048    Vulnerability       5.9         CVE-2024-43398: Denial Of Service (DoS)                             rexml 3.3.2
461532049    Vulnerability       5.4         CVE-2024-45614: HTTP Header Injection                               puma 6.4.2
461532050    Vulnerability       5.6         NO-CVE: Prototype Pollution                                         @sentry/browser 6.19.7
461532051    Vulnerability       6.1         CVE-2024-53986: Cross Site Scripting                                rails-html-sanitizer 1.6.0
461532052    Vulnerability       6.1         CVE-2024-53987: Cross Site Scripting                                rails-html-sanitizer 1.6.0
461532053    Vulnerability       6.1         CVE-2024-53988: Cross Site Scripting                                rails-html-sanitizer 1.6.0
461532054    Vulnerability       6.1         CVE-2024-53985: Cross-site Scripting (XSS)                          rails-html-sanitizer 1.6.0
461532055    Vulnerability       6.1         CVE-2024-53989: Cross-site Scripting (XSS)                          rails-html-sanitizer 1.6.0
461532056    Vulnerability       6.1         CVE-2024-54133: Cross-Site Scripting (XSS)                          actionpack 7.0.8.4
461532057    Vulnerability       4.3         CVE-2024-55565: Mishandling Non-integer Values                      nanoid 3.3.7
461532058    Vulnerability       6.1         CVE-2024-57965: Cross-Site Scripting (XSS)                          axios 1.6.0
461532059    Vulnerability       5.4         CVE-2024-11831: Cross-site Scripting (XSS)                          serialize-javascript 4.0.0
461532060    Vulnerability       5.4         CVE-2024-11831: Cross-site Scripting (XSS)                          serialize-javascript 5.0.1
461532061    Vulnerability       6.5         CVE-2025-25186: Denial Of Service                                   net-imap 0.4.12
461532062    Vulnerability       6.5         CVE-2025-25184: Log Injection                                       rack 2.2.9
461532063    Vulnerability       4.5         CVE-2025-26791: Mutation Cross-site Scripting (mXSS)                dompurify 2.2.7
461532064    Vulnerability       4.5         CVE-2025-26791: Mutation Cross-site Scripting (mXSS)                dompurify 2.3.6
461532065    Vulnerability       5.3         CVE-2025-27221: Authentication Credential Leakage                   uri 0.13.0
461532066    Vulnerability       5.3         CVE-2025-27111: Log Injection                                       rack 2.2.9
461532067    Vulnerability       4.2         CVE-2025-32441: Session Fixation                                    rack 2.2.9
461532068    Vulnerability       5.9         CVE-2025-6442: HTTP Request Smuggling (HRS)                         webrick 1.8.1
461532069    Vulnerability       5.8         CVE-2025-55193: Improper Neutralization                             activerecord 7.0.8.4
461532070    Vulnerability       7.5         CVE-2021-3803: Regular Expression Denial Of Service (ReDoS)         nth-check 1.0.2
461532071    Vulnerability       7.5         CVE-2021-3807: Regular Expression Denial Of Service (ReDoS)         ansi-regex 4.1.0
461532072    Vulnerability       7.5         CVE-2022-25858: Regular Expression Denial Of Service (ReDoS)        terser 5.14.1
461532073    Vulnerability       7.5         CVE-2022-37599: Regular Expression Denial Of Service (ReDoS)        loader-utils 2.0.0
461532074    Vulnerability       7.5         CVE-2022-37603: Regular Expression Denial Of Service (ReDoS)        loader-utils 2.0.0
461532075    Vulnerability       7.3         NO-CVE: Prototype Pollution                                         unset-value 1.0.0
461532076    Vulnerability       8.8         CVE-2022-46175: Prototype Pollution                                 json5 2.2.0
461532077    Vulnerability       7.5         CVE-2022-25883: Regular Expression Denial Of Service (ReDoS)        semver 5.7.1
461532078    Vulnerability       7.5         CVE-2022-25883: Regular Expression Denial Of Service (ReDoS)        semver 6.3.0
461532079    Vulnerability       8.8         CVE-2023-45133: Arbitrary Code Execution                            @babel/traverse 7.18.8
461532080    Vulnerability       8.8         CVE-2023-45133: Arbitrary Code Execution                            @babel/traverse 7.21.4
461532081    Vulnerability       7.5         NO-CVE: Prototype Pollution                                         axios 1.6.0
461532082    Vulnerability       7.5         CVE-2024-4068: Memory Exhaustion                                    braces 2.3.2
461532083    Vulnerability       7.5         CVE-2024-4068: Memory Exhaustion                                    braces 3.0.2
461532084    Vulnerability       7.5         CVE-2024-41123: Denial Of Service (DoS)                             rexml 3.3.2
461532085    Vulnerability       7.5         CVE-2024-41946: Denial Of Service (DoS)                             rexml 3.3.2
461532086    Vulnerability       7.5         CVE-2024-39338: Server-Side Request Forgery (SSRF)                  axios 1.6.0
461532087    Vulnerability       7.5         CVE-2024-43380: Denial Of Service (DoS)                             fugit 1.9.0
461532088    Vulnerability       8.2         CVE-2024-21529: Prototype Pollution                                 dset 3.1.2
461532089    Vulnerability       8.2         CVE-2024-21529: Prototype Pollution                                 dset 3.1.3
461532090    Vulnerability       7.3         CVE-2024-45801: Cross Site Scripting(XSS)                           dompurify 2.2.7
461532091    Vulnerability       7.3         CVE-2024-45801: Cross Site Scripting(XSS)                           dompurify 2.3.6
461532092    Vulnerability       7.5         CVE-2024-7254: Stack Overflow                                       google-protobuf 3.25.3
461532093    Vulnerability       7.5         CVE-2024-47220: HTTP Request Smuggling (HRS)                        webrick 1.8.1
461532094    Vulnerability       7.5         CVE-2024-41128: Regular Expression Denial Of Service (ReDoS)        actionpack 7.0.8.4
461532095    Vulnerability       7.5         CVE-2024-47887: Regular Expression Denial Of Service (ReDoS)        actionpack 7.0.8.4
461532096    Vulnerability       7.5         CVE-2024-47888: Regular Expression Denial Of Service (ReDoS)        actiontext 7.0.8.4
461532097    Vulnerability       7.5         CVE-2024-47889: Regular Expression Denial Of Service (ReDoS)        actionmailer 7.0.8.4
461532098    Vulnerability       7.5         CVE-2024-49761: Regular Expression Denial Of Service (ReDoS)        rexml 3.3.2
461532099    Vulnerability       7.5         CVE-2024-21538: Regular Expression Denial Of Service (ReDoS)        cross-spawn 6.0.5
461532100    Vulnerability       7.8         CVE-2025-24928: Stack-based Buffer Overflow                         nokogiri 1.16.6
461532101    Vulnerability       7.8         CVE-2024-56171: Use After Free                                      nokogiri 1.16.6
461532102    Vulnerability       8.2         CVE-2025-27152: Server-Side Request Forgery (SSRF)                  axios 1.6.0
461532103    Vulnerability       7.5         CVE-2025-27610: Path Traversal                                      rack 2.2.9
461532104    Vulnerability       7.5         CVE-2025-43857: Denial Of Service (DoS)                             net-imap 0.4.12
461532105    Vulnerability       7.5         CVE-2025-46727: Denial Of Service (DoS)                             rack 2.2.9
461532106    Vulnerability       8.1         CVE-2025-6547: Signature Spoofing                                   pbkdf2 3.1.2
461532107    Vulnerability       7.4         CVE-2025-7783: HTTP Parameter Pollution                             form-data 4.0.0
461532108    Vulnerability       8.1         NO-CVE: Command Injection                                           activestorage 7.0.8.4
461532109    Vulnerability       7.5         CVE-2025-58754: Denial Of Service (DoS)                             axios 1.6.0
461532110    Vulnerability       9.1         CVE-2024-42461: ECDSA Signature Malleability                        elliptic 6.5.4
461532111    Vulnerability       9.1         CVE-2024-48949: Improper Verification Of Cryptographic Signature    elliptic 6.5.4
461532112    Vulnerability       9.1         CVE-2024-48910: Prototype Pollution                                 dompurify 2.2.7
461532113    Vulnerability       9.1         CVE-2024-48910: Prototype Pollution                                 dompurify 2.3.6
461532114    Vulnerability       9.1         NO-CVE: Information Disclosure                                      elliptic 6.5.4
461532115    Vulnerability       9.8         CVE-2025-6545: Signature Spoofing                                   pbkdf2 3.1.2
461532116    Outdated Library    3.0         Latest version at scan: 1.0.0.beta3                                 administrate 0.20.1
461532117    Outdated Library    3.0         Latest version at scan: 1.76.0                                      grpc 1.62.0
461532118    Outdated Library    3.0         Latest version at scan: 2.14.1                                      jbuilder 2.11.5
461532119    Outdated Library    3.0         Latest version at scan: 3.1.2                                       jwt 2.8.1
461532120    Outdated Library    3.0         Latest version at scan: 3.9.0                                       listen 3.8.0
461532121    Outdated Library    3.0         Latest version at scan: 0.5.1                                       net-smtp 0.3.4
461532122    Outdated Library    3.0         Latest version at scan: 9.21.0                                      newrelic_rpm 9.6.0
461532123    Outdated Library    3.0         Latest version at scan: 2.1.4                                       omniauth 2.1.2
461532124    Outdated Library    3.0         Latest version at scan: 8.1.0                                       rails 7.0.8.4
461532125    Outdated Library    3.0         Latest version at scan: 5.4.1                                       redis 5.0.6
461532126    Outdated Library    3.0         Latest version at scan: 3.2.0                                       responders 3.1.1
461532127    Outdated Library    3.0         Latest version at scan: 1.81.6                                      rubocop 1.50.2
461532128    Outdated Library    3.0         Latest version at scan: 6.0.0                                       sentry-ruby 5.18.2
461532129    Outdated Library    3.0         Latest version at scan: 8.0.8                                       sidekiq 7.3.0
461532130    Outdated Library    3.0         Latest version at scan: 4.4.0                                       spring 4.1.1
461532131    Outdated Library    3.0         Latest version at scan: 8.5.6                                       postcss 8.4.38
461532132    Outdated Library    3.0         Latest version at scan: 7.11.0                                      wavesurfer.js 6.1.0
461532133    Outdated Library    3.0         Latest version at scan: 6.0.1                                       webpack-cli 3.3.12
461532134    Outdated Library    3.0         Latest version at scan: 5.102.1                                     webpack 4.46.0
461532135    Outdated Library    3.0         Latest version at scan: 1.8.3                                       active_record_query_trace 1.8
461532136    Outdated Library    3.0         Latest version at scan: 2.2.0                                       activerecord-import 1.4.1
461532137    Outdated Library    3.0         Latest version at scan: 12.0.0                                      acts-as-taggable-on 9.0.1
461532138    Outdated Library    3.0         Latest version at scan: 1.0.6                                       administrate-field-active_storage 1.0.3
461532139    Outdated Library    3.0         Latest version at scan: 0.10.0                                      administrate-field-belongs_to_search 0.9.0
461532140    Outdated Library    3.0         Latest version at scan: 5.8.0                                       audited 5.4.1
461532141    Outdated Library    3.0         Latest version at scan: 1.201.0                                     aws-sdk-s3 1.122.0
461532142    Outdated Library    3.0         Latest version at scan: 1.18.6                                      bootsnap 1.16.0
461532143    Outdated Library    3.0         Latest version at scan: 7.1.0                                       brakeman 5.4.1
461532144    Outdated Library    3.0         Latest version at scan: 6.2.0                                       browser 5.3.1
461532145    Outdated Library    3.0         Latest version at scan: 8.1.0                                       bullet 7.0.7
461532146    Outdated Library    3.0         Latest version at scan: 12.0.0                                      byebug 11.1.3
461532147    Outdated Library    3.0         Latest version at scan: 2.4.1                                       commonmarker 0.23.10
461532148    Outdated Library    3.0         Latest version at scan: 1.19.0                                      cypress-on-rails 1.16.0
461532149    Outdated Library    3.0         Latest version at scan: 2.1.0                                       database_cleaner 2.0.2
461532150    Outdated Library    3.0         Latest version at scan: 1.23.3                                      ddtrace 1.23.2
461532151    Outdated Library    3.0         Latest version at scan: 1.11.0                                      debug 1.8.0
461532152    Outdated Library    3.0         Latest version at scan: 2.2.1                                       devise-secure_password 2.0.1
461532153    Outdated Library    3.0         Latest version at scan: 1.2.5                                       devise_token_auth 1.2.3
461532154    Outdated Library    3.0         Latest version at scan: 3.1.8                                       dotenv-rails 3.1.2
461532155    Outdated Library    3.0         Latest version at scan: 5.4.2                                       down 5.4.0
461532156    Outdated Library    3.0         Latest version at scan: 4.8.0                                       elastic-apm 4.6.2
461532157    Outdated Library    3.0         Latest version at scan: 0.2.0                                       email_reply_trimmer 0.1.13
461532158    Outdated Library    3.0         Latest version at scan: 6.5.1                                       factory_bot_rails 6.4.3
461532159    Outdated Library    3.0         Latest version at scan: 3.5.2                                       faker 3.2.0
461532160    Outdated Library    3.0         Latest version at scan: 2.0.1                                       fcm 1.0.8
461532161    Outdated Library    3.0         Latest version at scan: 0.90.0                                      foreman 0.87.2
461532162    Outdated Library    3.0         Latest version at scan: 1.8.6                                       geocoder 1.8.1
461532163    Outdated Library    3.0         Latest version at scan: 1.11.0                                      google-cloud-dialogflow-v2 0.23.0
461532164    Outdated Library    3.0         Latest version at scan: 1.57.0                                      google-cloud-storage 1.44.0
461532165    Outdated Library    3.0         Latest version at scan: 1.7.0                                       google-cloud-translate-v3 0.6.0
461532166    Outdated Library    3.0         Latest version at scan: 6.7.0                                       groupdate 6.2.1
461532167    Outdated Library    3.0         Latest version at scan: 1.3.1                                       hairtrigger 1.0.0
461532168    Outdated Library    3.0         Latest version at scan: 0.4.0                                       html2text 0.3.1
461532169    Outdated Library    3.0         Latest version at scan: 1.14.0                                      image_processing 1.12.2
461532170    Outdated Library    3.0         Latest version at scan: 0.1.9                                       json_refs 0.1.8
461532171    Outdated Library    3.0         Latest version at scan: 2.4.0                                       json_schemer 0.2.24
461532172    Outdated Library    3.0         Latest version at scan: 3.6.0                                       koala 3.4.0
461532173    Outdated Library    3.0         Latest version at scan: 1.10.0                                      letter_opener 1.8.1
461532174    Outdated Library    3.0         Latest version at scan: 2.3.0                                       line-bot-api 1.28.0
461532175    Outdated Library    3.0         Latest version at scan: 5.8.7                                       liquid 5.4.0
461532176    Outdated Library    3.0         Latest version at scan: 0.8.5                                       meta_request 0.8.2
461532177    Outdated Library    3.0         Latest version at scan: 0.52.0                                      mock_redis 0.36.0
461532178    Outdated Library    3.0         Latest version at scan: 0.6.0                                       neighbor 0.2.3
461532179    Outdated Library    3.0         Latest version at scan: 1.2.1                                       omniauth-google-oauth2 1.1.2
461532180    Outdated Library    3.0         Latest version at scan: 1.6.2                                       pg 1.5.3
461532181    Outdated Library    3.0         Latest version at scan: 2.3.7                                       pg_search 2.3.6
461532182    Outdated Library    3.0         Latest version at scan: 0.3.2                                       pgvector 0.1.1
461532183    Outdated Library    3.0         Latest version at scan: 0.3.11                                      pry-rails 0.3.9
461532184    Outdated Library    3.0         Latest version at scan: 7.1.0                                       puma 6.4.2
461532185    Outdated Library    3.0         Latest version at scan: 2.5.2                                       pundit 2.3.0
461532186    Outdated Library    3.0         Latest version at scan: 6.8.0                                       rack-attack 6.7.0
461532187    Outdated Library    3.0         Latest version at scan: 3.0.0                                       rack-cors 2.0.0
461532188    Outdated Library    3.0         Latest version at scan: 4.0.1                                       rack-mini-profiler 3.2.0
461532189    Outdated Library    3.0         Latest version at scan: 0.7.0                                       rack-timeout 0.6.3
461532190    Outdated Library    3.0         Latest version at scan: 1.11.0                                      redis-namespace 1.10.0
461532191    Outdated Library    3.0         Latest version at scan: 3.0.0                                       reverse_markdown 2.1.1
461532192    Outdated Library    3.0         Latest version at scan: 8.0.2                                       rspec-rails 6.1.3
461532193    Outdated Library    3.0         Latest version at scan: 1.26.1                                      rubocop-performance 1.17.1
461532194    Outdated Library    3.0         Latest version at scan: 2.33.4                                      rubocop-rails 2.19.1
461532195    Outdated Library    3.0         Latest version at scan: 3.7.0                                       rubocop-rspec 2.21.0
461532196    Outdated Library    3.0         Latest version at scan: 5.7.1                                       scout_apm 5.3.3
461532197    Outdated Library    3.0         Latest version at scan: 6.0.0                                       sentry-rails 5.18.2
461532198    Outdated Library    3.0         Latest version at scan: 6.0.0                                       sentry-sidekiq 5.18.2
461532199    Outdated Library    3.0         Latest version at scan: 6.5.0                                       shoulda-matchers 5.3.0
461532200    Outdated Library    3.0         Latest version at scan: 2.3.1                                       sidekiq-cron 1.12.0
461532201    Outdated Library    3.0         Latest version at scan: 0.22.0                                      simplecov 0.17.1
461532202    Outdated Library    3.0         Latest version at scan: 3.0.0                                       slack-ruby-client 2.2.0
461532203    Outdated Library    3.0         Latest version at scan: 0.8.0                                       squasher 0.7.2
461532204    Outdated Library    3.0         Latest version at scan: 0.2.27                                      stackprof 0.2.25
461532205    Outdated Library    3.0         Latest version at scan: 17.1.0.pre.beta.2                           stripe 8.5.0
461532206    Outdated Library    3.0         Latest version at scan: 1.4.23                                      telephone_number 1.4.20
461532207    Outdated Library    3.0         Latest version at scan: 1.4.4                                       test-prof 1.2.1
461532208    Outdated Library    3.0         Latest version at scan: 7.8.2                                       twilio-ruby 5.77.0
461532209    Outdated Library    3.0         Latest version at scan: 1.2025.2                                    tzinfo-data 1.2023.3
461532210    Outdated Library    3.0         Latest version at scan: 4.2.1                                       uglifier 4.2.0
461532211    Outdated Library    3.0         Latest version at scan: 7.0.13                                      valid_email2 4.0.6
461532212    Outdated Library    3.0         Latest version at scan: 3.0.2                                       web-push 3.0.1
461532213    Outdated Library    3.0         Latest version at scan: 3.25.1                                      webmock 3.23.1
461532214    Outdated Library    3.0         Latest version at scan: 6.0.0.rc.6                                  webpacker 5.4.4
461532215    Outdated Library    3.0         Latest version at scan: 3.0.0                                       wisper 2.0.0
461532216    Outdated Library    3.0         Latest version at scan: 1.5.0                                       working_hours 1.4.1
461532217    Outdated Library    3.0         Latest version at scan: 1.1.1-next                                  @chatwoot/prosemirror-schema 1.0.11
461532218    Outdated Library    3.0         Latest version at scan: 0.0.41                                      @chatwoot/utils 0.0.25
461532219    Outdated Library    3.0         Latest version at scan: 1.3.0                                       @hcaptcha/vue-hcaptcha 0.3.2
461532220    Outdated Library    3.0         Latest version at scan: 4.0.0                                       @june-so/analytics-next 2.0.0
461532221    Outdated Library    3.0         Latest version at scan: 3.0.0                                       @radix-ui/colors 1.0.1
461532222    Outdated Library    3.0         Latest version at scan: 8.1.0-beta1                                 @rails/actioncable 6.1.3
461532223    Outdated Library    3.0         Latest version at scan: 7.1.502                                     @rails/ujs 7.0.8
461532224    Outdated Library    3.0         Latest version at scan: 6.0.0-rc.6                                  @rails/webpacker 5.4.4
461532225    Outdated Library    3.0         Latest version at scan: 0.5.4                                       @scmmishra/pico-search 0.5.1
461532226    Outdated Library    3.0         Latest version at scan: 7.120.4                                     @sentry/tracing 6.19.7
461532227    Outdated Library    3.0         Latest version at scan: 10.21.0-alpha.1                             @sentry/vue 6.19.7
461532228    Outdated Library    3.0         Latest version at scan: 3.0.0                                       @sindresorhus/slugify 1.1.0
461532229    Outdated Library    3.0         Latest version at scan: 0.5.19                                      @tailwindcss/typography 0.5.9
461532230    Outdated Library    3.0         Latest version at scan: 14.0.0-alpha.1                              @vueuse/core 10.10.0
461532231    Outdated Library    3.0         Latest version at scan: 10.4.21                                     autoprefixer 10.4.19
461532232    Outdated Library    3.0         Latest version at scan: 1.13.0                                      axios 1.6.0
461532233    Outdated Library    3.0         Latest version at scan: 7.0.0-beta.3                                babel-plugin-syntax-jsx 6.18.0
461532234    Outdated Library    3.0         Latest version at scan: 4.0.1                                       babel-plugin-transform-vue-jsx 3.7.0
461532235    Outdated Library    3.0         Latest version at scan: 4.5.1                                       chart.js 2.9.4
461532236    Outdated Library    3.0         Latest version at scan: 1.1.0                                       company-email-validator 1.0.8
461532237    Outdated Library    3.0         Latest version at scan: 4.0.0-alpha.0                               core-js 3.11.0
461532238    Outdated Library    3.0         Latest version at scan: 3.2.0                                       date-fns-tz 1.3.8
461532239    Outdated Library    3.0         Latest version at scan: 4.1.0                                       date-fns 2.21.1
461532240    Outdated Library    3.0         Latest version at scan: 3.3.0                                       dompurify 2.2.7
461532241    Outdated Library    3.0         Latest version at scan: 11.11.1                                     highlight.js 10.4.1
461532242    Outdated Library    3.0         Latest version at scan: 8.0.3                                       idb 7.1.1
461532243    Outdated Library    3.0         Latest version at scan: 8.0.13                                      ionicons 2.0.1
461532244    Outdated Library    3.0         Latest version at scan: 1.2.1                                       lamejs 1.2.0
461532245    Outdated Library    3.0         Latest version at scan: 1.12.25                                     libphonenumber-js 1.10.44
461532246    Outdated Library    3.0         Latest version at scan: 14.1.0                                      markdown-it 13.0.2
461532247    Outdated Library    3.0         Latest version at scan: 8.2.0                                       postcss-loader 4.3.0
461532248    Outdated Library    3.0         Latest version at scan: 7.7.3                                       semver 7.5.3
461532249    Outdated Library    3.0         Latest version at scan: 4.1.16                                      tailwindcss 3.3.3
461532250    Outdated Library    3.0         Latest version at scan: 3.0.0                                       tinykeys 2.1.0
461532251    Outdated Library    3.0         Latest version at scan: 5.3.0-beta.1                                turbolinks 5.2.0
461532252    Outdated Library    3.0         Latest version at scan: 4.1.1                                       url-loader 2.3.0
461532253    Outdated Library    3.0         Latest version at scan: 10.1.0                                      urlpattern-polyfill 6.0.2
461532254    Outdated Library    3.0         Latest version at scan: 4.0.0-beta.17                               v-tooltip 2.1.3
461532255    Outdated Library    3.0         Latest version at scan: 4.8.0                                       videojs-record 4.5.0
461532256    Outdated Library    3.0         Latest version at scan: 5.3.2                                       vue-chartjs 3.5.1
461532257    Outdated Library    3.0         Latest version at scan: 2.2.2                                       vue-clickaway 2.1.0
461532258    Outdated Library    3.0         Latest version at scan: 3.0.2                                       vue-color 2.8.1
461532259    Outdated Library    3.0         Latest version at scan: 5.3.0                                       vue-dompurify-html 2.5.2
461532260    Outdated Library    3.0         Latest version at scan: 2.27.1                                      vue-easytable 2.5.5
461532261    Outdated Library    3.0         Latest version at scan: 12.0.0-alpha.3                              vue-i18n 8.24.3
461532262    Outdated Library    3.0         Latest version at scan: 0.2.1                                       vue-letter 0.1.3
461532263    Outdated Library    3.0         Latest version at scan: 17.4.2                                      vue-loader 15.10.2
461532264    Outdated Library    3.0         Latest version at scan: 3.4.0                                       vue-multiselect 2.1.9
461532265    Outdated Library    3.0         Latest version at scan: 4.6.3                                       vue-router 3.5.4
461532266    Outdated Library    3.0         Latest version at scan: 3.1.17                                      vue-upload-component 2.8.22
461532267    Outdated Library    3.0         Latest version at scan: 4.0.0-beta.2                                vue2-datepicker 3.9.1
461532268    Outdated Library    3.0         Latest version at scan: 3.6.0-alpha.2                               vue 2.7.16
461532269    Outdated Library    3.0         Latest version at scan: 4.1.0                                       vuedraggable 2.24.3
461532270    Outdated Library    3.0         Latest version at scan: 6.0.0-rc.1                                  vuex-router-sync 4.1.3
461532271    Outdated Library    3.0         Latest version at scan: 4.1.0                                       vuex 2.1.3
461532272    License             9.0         Library has High-Risk License                                       sidekiq 7.3.0
461532273    License             9.0         Library has High-Risk License                                       brakeman 5.4.1
461532274    License             9.0         Library has High-Risk License                                       lamejs 1.2.0


Full Report Details                                   https://sca.analysiscenter.veracode.com/teams/PaainkEg/scans/101628690

Veracode SCA scan faced a problem. Please contact your Veracode administrator for more information.