Scan rule · RSC-SEC-078
Shipped library with a known vulnerability
SecuritySeverity: HighCWE-1395OWASP A06-2021
Detects front-end libraries and their version in the served bundle and in recovered source maps (retire.js signatures) and matches the version against OSV or the bundled retire.js database. Reports only on a confidently detected version.
Scan tier
External scan (anonymous)Source code from source maps
How to fix it
Raise the affected library to the patched version and set up a recurring update run.