feast-dev / feast-dev/feast

Mend scan shows some javascript vulnerabilities in feast pacakge

Open
#5,349 0 comments 2 reactions 0 assignees View on GitHub
kind/feature
Dominant language
Python
Stars
7.3k
Forks
1.4k
Avg merge
3d 16h
Merged PRs (30d)
15

Description

The feast shows javascript vulnerabilities from mend.
These are coming from ui package. I think this ui should be optional dependency in feast and shouldn't be included without extra install

This is what under ui dir.
```
/site-packages/feast/ui
README.md __init__.py build package.json public src yarn.lock
```
E.g report include below vulnerabilities.

CVE-2024-52798
CVE-2022-3517
CVE-2024-21538
CVE-2021-3803
CVE-2024-21536
CVE-2022-37603
CVE-2022-46175
CVE-2024-6484
CVE-2025-27789
CVE-2025-27789
CVE-2025-27789
CVE-2025-27789
CVE-2019-8331
CVE-2018-20677
CVE-2018-20676
CVE-2018-14042
CVE-2016-10735
CVE-2024-11831
CVE-2024-11831
CVE-2023-44270
CVE-2023-44270
CVE-2022-25883
CVE-2024-47764
CVE-2023-26115
CVE-2024-53382
CVE-2024-53382
CVE-2025-32997
CVE-2025-32996
CVE-2018-14040

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.