Total Findings
49
All detected issues
KEV Findings
1
Known exploited
High EPSS
1
Likely to be exploited
Auto-merge ready
0
Remediation candidates
Affected pkgs
1
with remediation paths
KEV catalog
CISA's Known Exploited Vulnerabilities catalog. Documented active exploitation in the wild; the strongest 'this is happening now' signal.
Click for more →
1
actively exploited CVEs
Highest EPSS
Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity.
Click for more →
49.0%
CVE-2023-5217
Active vetos
3
lens blocks on candidates
Findings
49 findings
critical–low
Trust 30/100
EPSS 49.0% ↑
⚠ ownership transferred
REVIEW
Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk.
Click for more →
Electron protocol handler browser vulnerable to Command Injection
Electron affected by libvpx's heap buffer overflow in vp8 encoding
Electron: Renderer command-line switch injection via undocumented commandLineSwitches webPreference
Electron: Use-after-free in offscreen child window paint callback
Electron vulnerable to remote command execution
Context isolation bypass via leaked cross-context objects in Electron
High severity vulnerability that affects electron
Context isolation bypass via contextBridge in Electron
Electron: Use-after-free in WebContents fullscreen, pointer-lock, and keyboard-lock permission callbacks
Electron: Context isolation bypass via Function.prototype.bind hijack
Electron: Custom protocol with supportFetchAPI but not corsEnabled allows cross-origin reads
Electron: Sandboxed iframe can bypass the allow-popups restriction via the OpenURL navigation path
Electron: Use-after-free in PowerMonitor on Windows and macOS
Context isolation bypass via Promise in Electron
Arbitrary file read via window-open IPC in Electron
Electron's sandboxed renderers can obtain thumbnails of arbitrary files through the nativeImage API
Electron: nodeIntegrationInWorker not correctly scoped in shared renderer processes
AutoUpdater module fails to validate certain nested components of the bundle
Electron: Extension tab APIs operate across session boundaries
Electron: AppleScript injection in app.moveToApplicationsFolder on macOS
Electron: Parent process code-sign check is spoofable
ASAR Integrity bypass via filetype confusion in electron
Electron vulnerable to out-of-package code execution when launched with arbitrary cwd
Electron has ASAR Integrity Bypass via resource modification
Electron: shell.openPath path validation bypass via embedded null byte
Electron: Named window.open targets not scoped to the opener's browsing context
Electron context isolation bypass via nested unserializable return value
Electron: HTTP Response Header Injection in custom protocol handlers and webRequest
Electron: Permission Check Handler Receives Main Frame Origin Instead of Requesting Iframe Origin
Electron: HTTP redirect followed into local file loader
Electron: Service worker can spoof executeJavaScript IPC replies
Electron: Use-after-free in download save dialog callback
Electron: DevTools JavaScript Injection via Unsanitized Dock State Parameter
Electron: contextBridge object copy honors prototype setters
IPC messages delivered to the wrong frame in Electron
Exfiltration of hashed SMB credentials on Windows via file:// redirect
Electron: Incorrect origin passed to permission request handler for iframe requests
Electron: Out-of-bounds read in second-instance IPC on macOS and Linux
Electron: window.open features string controls some window options considered privileged
Electron vulnerable to Heap Buffer Overflow in NativeImage
Electron: Registry key path injection in app.setAsDefaultProtocolClient on Windows
Electron: Unquoted executable path in app.setLoginItemSettings on Windows
Electron: Off-screen rendering trusts GPU-supplied geometry over shared-memory size
Renderers can obtain access to random bluetooth device without permission in Electron
Electron: USB device selection not validated against filtered device list
Electron: Cross-origin iframe can position native autofill popup
Electron: Crash in clipboard.readImage() on malformed clipboard image data
Compromised child renderer processes could obtain IPC access without nodeIntegrationInSubFrames being enabled
0.4.1 → 39.8.10
major
Max CVSS 9.8 · 49 findings
Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency.
Click for more →
CISA KEV
CISA's Known Exploited Vulnerabilities catalog. Documented active exploitation in the wild; the strongest 'this is happening now' signal.
Click for more →
Max EPSS 49.0%
· 98th percentile
Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity.
Click for more →
fix_kind.major
Veto: the available fix requires a major version bump (1.x → 2.x), which implies potential breaking changes outside the auto-merge envelope.
Click for more →
trust.new_maintainer
Veto: a new publishing identity was added between your current version and the upgrade target. A well-documented supply chain attack vector.
Click for more →
trust.ownership_transferred
Veto: the package's primary maintainer changed during the upgrade window. Combined with new-maintainer, this is the highest-risk trust combination.
Click for more →
- major version bump requires human review (never auto-merge)
- trust veto: new maintainer added
- trust veto: package ownership transferred between versions
GHSA-4w88-rjj3-x7wp: Chromium Remote Code Execution in electron
Upgrade electron from 0.4.1 to 1.6.14 or later
View advisory
root →
matcha →
electron
Blast radius
Paths from project root to electron - which dependencies pulled this package in?
Package status
516 packages scanned.
- 1 Review-required candidate Arguss flagged these for a human decision - nothing merges until you review them.
-
- @types/node 26.1.2 direct
- ansi-styles 6.2.3 direct
- ava 8.0.1 direct
- c8 12.0.0 direct
- color-convert 3.1.3 direct
- execa 10.0.1 direct
- execa 9.6.1 direct
- log-update 8.0.0 direct
- matcha 0.7.0 direct
- typescript 6.0.3 direct
- xo 4.0.0 direct
- yoctodelay 2.0.0 direct
- @babel/code-frame 7.29.7
- @babel/helper-validator-identifier 7.29.7
- @bcoe/v8-coverage 1.0.2
- @cto.af/wtf8 0.0.5
- @emnapi/core 1.10.0
- @emnapi/runtime 1.10.0
- @emnapi/wasi-threads 1.2.1
- @es-joy/jsdoccomment 0.91.0
- @es-joy/resolve.exports 1.2.0
- @eslint-community/eslint-plugin-eslint-comments 4.7.2
- @eslint-community/eslint-utils 4.10.1
- @eslint-community/regexpp 4.12.2
- @eslint/compat 2.1.0
- @eslint/config-array 0.23.5
- @eslint/config-helpers 0.7.0
- @eslint/core 0.17.0
- @eslint/core 1.2.1
- @eslint/css 1.4.0
- @eslint/css-tree 4.0.5
- @eslint/json 2.0.1
- @eslint/markdown 8.0.3
- @eslint/object-schema 3.0.5
- @eslint/plugin-kit 0.4.1
- @eslint/plugin-kit 0.7.2
- @html-eslint/core 0.63.0
- @html-eslint/eslint-plugin 0.63.0
- @html-eslint/parser 0.63.0
- @html-eslint/template-parser 0.63.0
- @html-eslint/template-syntax-parser 0.63.0
- @html-eslint/types 0.63.0
- @humanfs/core 0.19.2
- @humanfs/node 0.16.8
- @humanfs/types 0.15.0
- @humanwhocodes/module-importer 1.0.1
- @humanwhocodes/momoa 3.3.10
- @humanwhocodes/retry 0.4.3
- @isaacs/fs-minipass 4.0.1
- @istanbuljs/schema 0.1.6
- @jridgewell/resolve-uri 3.1.2
- @jridgewell/sourcemap-codec 1.5.5
- @jridgewell/trace-mapping 0.3.31
- @mapbox/node-pre-gyp 2.0.3
- @napi-rs/wasm-runtime 1.1.6
- @nodelib/fs.scandir 2.1.5
- @nodelib/fs.stat 2.0.5
- @nodelib/fs.walk 1.2.8
- @pkgr/core 0.3.6
- @rollup/pluginutils 5.4.0
- @rviscomi/capo.js 2.2.0
- @sec-ant/readable-stream 0.4.1
- @sindresorhus/base62 1.0.0
- @sindresorhus/merge-streams 4.0.0
- @sindresorhus/tsconfig 8.1.0
- @stylistic/eslint-plugin 5.10.0
- @tybys/wasm-util 0.10.3
- @types/css-tree 2.3.11
- @types/debug 4.1.13
- @types/eslint 9.6.1
- @types/esrecurse 4.3.1
- @types/estree 1.0.9
- @types/hast 3.0.5
- @types/istanbul-lib-coverage 2.0.6
- @types/json-schema 7.0.15
- @types/katex 0.16.8
- @types/mdast 4.0.4
- @types/ms 2.1.0
- @types/unist 3.0.3
- @typescript-eslint/eslint-plugin 8.66.0
- @typescript-eslint/parser 8.66.0
- @typescript-eslint/project-service 8.66.0
- @typescript-eslint/scope-manager 8.66.0
- @typescript-eslint/tsconfig-utils 8.66.0
- @typescript-eslint/type-utils 8.66.0
- @typescript-eslint/types 8.66.0
- @typescript-eslint/typescript-estree 8.66.0
- @typescript-eslint/utils 8.66.0
- @typescript-eslint/visitor-keys 8.66.0
- @unrs/resolver-binding-android-arm-eabi 1.12.2
- @unrs/resolver-binding-android-arm64 1.12.2
- @unrs/resolver-binding-darwin-arm64 1.12.2
- @unrs/resolver-binding-darwin-x64 1.12.2
- @unrs/resolver-binding-freebsd-x64 1.12.2
- @unrs/resolver-binding-linux-arm-gnueabihf 1.12.2
- @unrs/resolver-binding-linux-arm-musleabihf 1.12.2
- @unrs/resolver-binding-linux-arm64-gnu 1.12.2
- @unrs/resolver-binding-linux-arm64-musl 1.12.2
- @unrs/resolver-binding-linux-loong64-gnu 1.12.2
- @unrs/resolver-binding-linux-loong64-musl 1.12.2
- @unrs/resolver-binding-linux-ppc64-gnu 1.12.2
- @unrs/resolver-binding-linux-riscv64-gnu 1.12.2
- @unrs/resolver-binding-linux-riscv64-musl 1.12.2
- @unrs/resolver-binding-linux-s390x-gnu 1.12.2
- @unrs/resolver-binding-linux-x64-gnu 1.12.2
- @unrs/resolver-binding-linux-x64-musl 1.12.2
- @unrs/resolver-binding-openharmony-arm64 1.12.2
- @unrs/resolver-binding-wasm32-wasi 1.12.2
- @unrs/resolver-binding-win32-arm64-msvc 1.12.2
- @unrs/resolver-binding-win32-ia32-msvc 1.12.2
- @unrs/resolver-binding-win32-x64-msvc 1.12.2
- @vercel/nft 1.10.2
- @vscode/l10n 0.0.18
- abbrev 3.0.1
- acorn 8.18.0
- acorn-import-attributes 1.9.5
- acorn-jsx 5.3.2
- acorn-walk 8.3.5
- agent-base 7.1.4
- ajv 6.15.0
- ansi-escapes 7.3.0
- ansi-regex 6.2.2
- are-docs-informative 0.0.2
- argparse 1.0.10
- argparse 2.0.1
- array-find-index 1.0.2
- arrgv 1.0.2
- arrify 3.0.0
- async-sema 3.1.1
- balanced-match 4.0.4
- baseline-browser-mapping 2.11.12
- bindings 1.5.0
- blueimp-md5 2.19.0
- brace-expansion 5.0.9
- braces 3.0.3
- browserslist 4.28.7
- builtin-modules 5.3.0
- bundle-name 4.1.0
- callsites 3.1.0
- callsites 4.2.0
- caniuse-lite 1.0.30001806
- cbor2 2.3.0
- ccount 2.0.1
- chalk 5.6.2
- change-case 5.4.4
- character-entities 2.0.2
- chownr 3.0.0
- chunkd 2.0.1
- ci-info 4.4.0
- ci-parallel-vars 1.0.1
- cli-cursor 5.0.0
- cli-truncate 6.1.1
- cliui 9.0.1
- code-excerpt 4.0.0
- color-name 2.1.1
- commander 8.3.0
- comment-parser 1.4.7
- common-path-prefix 3.0.0
- concordance 5.0.4
- confusing-browser-globals 1.0.11
- consola 3.4.2
- convert-hrtime 5.0.0
- convert-source-map 2.0.0
- convert-to-spaces 2.0.1
- core-js-compat 3.50.0
- cosmiconfig 9.0.2
- cross-spawn 7.0.6
- css-tree 3.2.1
- currently-unhandled 0.4.1
- date-time 3.1.0
- debug 4.4.3
- decode-named-character-reference 1.3.0
- deep-is 0.1.4
- default-browser 5.5.0
- default-browser-id 5.0.1
- define-lazy-prop 3.0.0
- dequal 2.0.3
- detect-indent 7.0.2
- detect-libc 2.1.2
- devlop 1.1.0
- drip 1.1.0
- electron-to-chromium 1.5.401
- emittery 2.0.0
- emoji-regex 10.6.0
- enhanced-resolve 5.24.5
- env-editor 1.3.0
- env-paths 2.2.1
- environment 1.1.0
- error-ex 1.3.4
- es-html-parser 0.3.1
- escalade 3.2.0
- escape-string-regexp 2.0.0
- escape-string-regexp 4.0.0
- escape-string-regexp 5.0.0
- eslint 10.8.0
- eslint-compat-utils 0.5.1
- eslint-config-prettier 10.1.8
- eslint-config-xo 0.57.0
- eslint-formatter-pretty 7.1.0
- eslint-import-context 0.1.9
- eslint-import-resolver-typescript 4.4.5
- eslint-node-test 0.2.0
- eslint-plugin-ava 17.0.1
- eslint-plugin-es-x 7.8.0
- eslint-plugin-import-x 4.17.1
- eslint-plugin-jsdoc 63.3.3
- eslint-plugin-n 18.2.2
- eslint-plugin-prettier 5.5.6
- eslint-plugin-regexp 3.1.1
- eslint-plugin-unicorn 71.1.0
- eslint-rule-docs 1.1.235
- eslint-scope 9.1.2
- eslint-visitor-keys 3.4.3
- eslint-visitor-keys 4.2.1
- eslint-visitor-keys 5.0.1
- espree 10.4.0
- espree 11.2.0
- esprima 4.0.1
- espurify 3.2.0
- esquery 1.7.0
- esrecurse 4.3.0
- estraverse 5.3.0
- estree-walker 2.0.2
- esutils 2.0.3
- fast-deep-equal 3.1.3
- fast-diff 1.3.0
- fast-glob 3.3.3
- fast-json-stable-stringify 2.1.0
- fast-levenshtein 2.0.6
- fastq 1.20.1
- fault 2.0.1
- fdir 6.5.0
- figures 6.1.0
- file-entry-cache 8.0.0
- file-uri-to-path 1.0.0
- fill-range 7.1.1
- find-cache-directory 6.0.0
- find-up 5.0.0
- find-up-simple 1.0.1
- flat-cache 4.0.1
- flatted 3.4.4
- foreground-child 3.3.1
- format 0.2.2
- function-timeout 1.0.2
- get-caller-file 2.0.5
- get-east-asian-width 1.6.0
- get-stdin 10.0.0
- get-stream 9.0.1
- get-tsconfig 4.14.1
- github-slugger 2.0.0
- glob 13.0.6
- glob-parent 5.1.2
- glob-parent 6.0.2
- globals 15.15.0
- globals 17.9.0
- globby 16.2.2
- globrex 0.1.2
- graceful-fs 4.2.11
- has-flag 4.0.0
- has-flag 5.0.1
- html-entities 2.6.0
- html-escaper 2.0.2
- html-standard 0.0.13
- https-proxy-agent 7.0.6
- human-signals 8.0.1
- identifier-regex 1.1.0
- ignore 5.3.2
- ignore 7.0.6
- ignore-by-default 2.1.0
- import-fresh 3.3.1
- imurmurhash 0.1.4
- indent-string 5.0.0
- irregular-plurals 3.5.0
- irregular-plurals 4.2.0
- is-arrayish 0.2.1
- is-builtin-module 5.0.0
- is-bun-module 2.0.0
- is-docker 3.0.0
- is-extglob 2.1.1
- is-fullwidth-code-point 5.1.0
- is-glob 4.0.3
- is-identifier 1.1.0
- is-in-ssh 1.0.0
- is-inside-container 1.0.0
- is-number 7.0.0
- is-path-inside 4.0.0
- is-plain-obj 4.1.0
- is-plain-object 5.0.0
- is-promise 4.0.0
- is-stream 4.0.1
- is-unicode-supported 2.1.0
- is-wsl 3.1.1
- isexe 2.0.0
- istanbul-lib-coverage 3.2.2
- istanbul-lib-report 3.0.1
- istanbul-reports 3.2.0
- jiti 2.7.0
- js-string-escape 1.0.1
- js-tokens 4.0.0
- js-yaml 3.15.1
- js-yaml 4.3.1
- jsdoc-type-pratt-parser 7.3.0
- jsdoc-type-pratt-parser 8.0.0
- jsesc 3.1.0
- json-buffer 3.0.1
- json-parse-even-better-errors 2.3.1
- json-schema-traverse 0.4.1
- json-stable-stringify-without-jsonify 1.0.1
- katex 0.16.47
- keyv 4.5.4
- levn 0.4.1
- line-column-path 4.0.0
- lines-and-columns 1.2.4
- load-json-file 7.0.1
- locate-path 6.0.0
- lodash 4.18.1
- log-symbols 7.0.1
- longest-streak 3.1.0
- lru-cache 11.5.2
- make-asynchronous 1.1.0
- make-dir 4.0.0
- markdown-table 3.0.4
- matcher 6.0.0
- md5-hex 3.0.1
- mdast-util-find-and-replace 3.0.2
- mdast-util-from-markdown 2.0.3
- mdast-util-frontmatter 2.0.1
- mdast-util-gfm 3.1.0
- mdast-util-gfm-autolink-literal 2.0.1
- mdast-util-gfm-footnote 2.1.0
- mdast-util-gfm-strikethrough 2.0.0
- mdast-util-gfm-table 2.0.0
- mdast-util-gfm-task-list-item 2.0.0
- mdast-util-math 3.0.0
- mdast-util-phrasing 4.1.0
- mdast-util-to-markdown 2.1.2
- mdast-util-to-string 4.0.0
- mdn-data 2.27.1
- mdn-data 2.29.0
- memoize 11.0.0
- meow 14.1.0
- merge2 1.4.1
- micro-spelling-correcter 1.1.1
- micromark 4.0.2
- micromark-core-commonmark 2.0.3
- micromark-extension-frontmatter 2.0.0
- micromark-extension-gfm 3.0.0
- micromark-extension-gfm-autolink-literal 2.1.0
- micromark-extension-gfm-footnote 2.1.0
- micromark-extension-gfm-strikethrough 2.1.0
- micromark-extension-gfm-table 2.1.1
- micromark-extension-gfm-tagfilter 2.0.0
- micromark-extension-gfm-task-list-item 2.1.0
- micromark-extension-math 3.1.0
- micromark-factory-destination 2.0.1
- micromark-factory-label 2.0.1
- micromark-factory-space 2.0.1
- micromark-factory-title 2.0.1
- micromark-factory-whitespace 2.0.1
- micromark-util-character 2.1.1
- micromark-util-chunked 2.0.1
- micromark-util-classify-character 2.0.1
- micromark-util-combine-extensions 2.0.1
- micromark-util-decode-numeric-character-reference 2.0.2
- micromark-util-decode-string 2.0.1
- micromark-util-encode 2.0.1
- micromark-util-html-tag-name 2.0.1
- micromark-util-normalize-identifier 2.0.1
- micromark-util-resolve-all 2.0.1
- micromark-util-sanitize-uri 2.0.1
- micromark-util-subtokenize 2.1.0
- micromark-util-symbol 2.0.1
- micromark-util-types 2.0.2
- micromatch 4.0.8
- mimic-function 5.0.1
- minimatch 10.2.6
- minipass 7.1.3
- minizlib 3.1.0
- ms 2.1.3
- napi-postinstall 0.3.4
- natural-compare 1.4.0
- node-fetch 2.7.0
- node-gyp-build 4.8.4
- node-releases 2.0.52
- nopt 8.1.0
- npm-run-path 6.0.0
- object-deep-merge 2.0.1
- onetime 7.0.0
- open 11.0.0
- open-editor 6.0.0
- optionator 0.9.4
- p-event 6.0.1
- p-limit 3.1.0
- p-locate 5.0.0
- p-map 7.0.6
- p-timeout 6.1.4
- package-config 5.0.0
- parent-module 1.0.1
- parse-imports-exports 0.2.4
- parse-json 5.2.0
- parse-ms 4.0.0
- parse-statements 1.0.11
- path-exists 4.0.0
- path-exists 5.0.0
- path-key 3.1.1
- path-key 4.0.0
- path-scurry 2.0.2
- picocolors 1.1.1
- picomatch 2.3.2
- picomatch 4.0.5
- pkg-dir 8.0.0
- plur 5.1.0
- plur 6.0.0
- pluralize 8.0.0
- powershell-utils 0.1.0
- prelude-ls 1.2.1
- prettier 3.9.6
- prettier-linter-helpers 1.0.1
- pretty-ms 9.3.0
- punycode 2.3.1
- queue-microtask 1.2.3
- quote-js-string 0.1.0
- refa 0.12.1
- regexp-ast-analysis 0.7.1
- regjsparser 0.13.2
- reserved-identifiers 1.2.0
- resolve-cwd 3.0.0
- resolve-from 4.0.0
- resolve-from 5.0.0
- resolve-pkg-maps 1.0.0
- restore-cursor 5.1.0
- reusify 1.1.0
- run-applescript 7.1.0
- run-parallel 1.2.0
- scslre 0.3.0
- semver 7.8.5
- serialize-error 7.0.1
- shebang-command 2.0.0
- shebang-regex 3.0.0
- signal-exit 4.1.0
- slash 5.1.0
- slice-ansi 9.0.0
- source-map-js 1.2.1
- spdx-exceptions 2.5.0
- spdx-expression-parse 5.0.0
- spdx-license-ids 3.0.23
- sprintf-js 1.0.3
- stable-hash-x 0.2.0
- stack-utils 2.0.6
- string-width 7.2.0
- string-width 8.2.2
- strip-ansi 7.2.0
- strip-final-newline 4.0.0
- strip-indent 4.1.1
- super-regex 1.1.0
- supertap 3.0.1
- supports-color 10.2.2
- supports-color 7.2.0
- supports-hyperlinks 4.5.0
- synckit 0.11.13
- tagged-tag 1.0.0
- tapable 2.3.3
- tar 7.5.22
- tea-concat 0.1.0
- temp-dir 3.0.0
- test-exclude 8.0.0
- time-span 5.1.0
- time-zone 1.0.0
- tinyglobby 0.2.17
- to-regex-range 5.0.1
- to-valid-identifier 1.0.0
- tr46 0.0.3
- ts-api-utils 2.5.0
- tslib 2.8.1
- type-check 0.4.0
- type-fest 0.13.1
- type-fest 4.41.0
- type-fest 5.8.0
- typescript-eslint 8.66.0
- undici-types 8.3.0
- unicorn-magic 0.3.0
- unicorn-magic 0.4.0
- unist-util-is 6.0.1
- unist-util-remove-position 5.0.0
- unist-util-stringify-position 4.0.0
- unist-util-visit 5.1.0
- unist-util-visit-parents 6.0.2
- unrs-resolver 1.12.2
- update-browserslist-db 1.2.3
- uri-js 4.4.1
- v8-argv 0.1.0
- v8-to-istanbul 9.3.0
- vscode-css-languageservice 6.3.10
- vscode-languageserver-textdocument 1.0.12
- vscode-languageserver-types 3.17.5
- vscode-uri 3.1.0
- web-worker 1.5.0
- webidl-conversions 3.0.1
- well-known-symbols 2.0.0
- whatwg-url 5.0.0
- which 2.0.2
- which-command 0.1.0
- word-wrap 1.2.5
- wrap-ansi 10.0.0
- wrap-ansi 9.0.2
- write-file-atomic 7.0.1
- wsl-utils 0.3.1
- y18n 5.0.8
- yallist 5.0.0
- yargs 18.1.0
- yargs-parser 21.1.1
- yargs-parser 22.0.0
- yocto-queue 0.1.0
- yoctocolors 2.2.0
- zwitch 2.0.4
Review auto-merge candidates and open PRs in a guided flow.
Glossary
What the labels and signals mean.
Glossary
What the labels and signals mean.
- Trust Save
- A package upgrade Arguss would have blocked despite the new version being available, because trust signals, like ownership transfer or a new maintainer, fired during the upgrade window. The name reflects what the agent did for the user: saved them from a potentially malicious update that a version-only auto-PR tool would have merged.
- AUTO-MERGE
- Verdict tier indicating the fix passes all three lenses cleanly. After you confirm action from a Scan assessment, Arguss opens a pull request for the upgrade; it does not merge PRs on GitHub. The envelope is conservative on purpose: patch or minor version bump, trust signals unchanged, blast radius bounded, real tests pass.
- REVIEW
- Verdict tier requiring a human decision. At least one veto fired during fix-confidence evaluation, trust signals shifted, the pipeline can't verify post-upgrade behavior, or the upgrade is a major version bump. The agent surfaces the reasons; the developer decides.
- DECLINE
- Verdict tier indicating no remediation is recommended. Typically applies when no fix version exists for the finding, or when multiple critical vetoes make even human review unproductive.
fix_kind.major- Veto signal that fires when the available fix requires a major version bump (1.x → 2.x). Major bumps imply potential breaking changes and fall outside the auto-merge envelope by default, even when the upgrade is the only available fix.
trust.new_maintainer- Veto signal that fires when a package added a new maintainer during the upgrade window, meaning between the user's current version and the proposed upgrade. New publishing identities are a well-documented attack vector for typosquats and supply chain takeovers.
trust.ownership_transferred- Veto signal that fires when a package's primary maintainer changed during the upgrade window. Combined with
trust.new_maintainer, this is the highest-risk trust combination, typical of the xz-utils style attacks and historical npm credential theft incidents. pipeline.test_reality- Veto signal that fires when Arguss can't verify tests will run on the upgraded code. Four conditions must hold: a test script exists in
package.json, it isn't a no-op, real test files exist, and a workflow actually invokes them. If any fail, the fix cannot qualify for AUTO_MERGE because there's no way to verify the upgrade didn't break the user's project. - CVSS
- Common Vulnerability Scoring System. A numeric score (0.0–10.0) representing how damaging a vulnerability could be if exploited. Sourced from NIST's National Vulnerability Database via OSV.dev. Severity, not urgency.
- EPSS
- Exploit Prediction Scoring System. A daily-updated probability (0.0–1.0, displayed as percent) that a CVE will be exploited in the next 30 days. Sourced from FIRST.org. Probability, not severity.
- KEV
- CISA's Known Exploited Vulnerabilities catalog. A federal list of CVEs with documented active exploitation in the wild. Federal agencies have a binding patching deadline; for everyone else, presence on KEV is the strongest "this is being used right now" signal available. Sourced directly from CISA.
- Project Risk Score (PRS)
- A weighted blend of the three lens subscores (40% vulnerability, 30% trust, 30% pipeline) producing an overall 0–100 indicator of the project's dependency health. Useful for at-a-glance triage; the per-finding fix-confidence verdicts are what drive automated decisions.
Dependency graph
Full-project map of transitive dependencies. Severity colors reflect vulnerabilities; trust rings apply only to direct dependencies analyzed by OpenSSF Scorecard (higher = riskier).