Mend scan shows some javascript vulnerabilities in feast pacakge
- Dominant language
- Python
- Stars
- 7.3k
- Forks
- 1.4k
- Avg merge
- 3d 16h
- Merged PRs (30d)
- 15
Description
The feast shows javascript vulnerabilities from mend.
These are coming from ui package. I think this ui should be optional dependency in feast and shouldn't be included without extra install
This is what under ui dir.
```
/site-packages/feast/ui
README.md __init__.py build package.json public src yarn.lock
```
E.g report include below vulnerabilities.
CVE-2024-52798
CVE-2022-3517
CVE-2024-21538
CVE-2021-3803
CVE-2024-21536
CVE-2022-37603
CVE-2022-46175
CVE-2024-6484
CVE-2025-27789
CVE-2025-27789
CVE-2025-27789
CVE-2025-27789
CVE-2019-8331
CVE-2018-20677
CVE-2018-20676
CVE-2018-14042
CVE-2016-10735
CVE-2024-11831
CVE-2024-11831
CVE-2023-44270
CVE-2023-44270
CVE-2022-25883
CVE-2024-47764
CVE-2023-26115
CVE-2024-53382
CVE-2024-53382
CVE-2025-32997
CVE-2025-32996
CVE-2018-14040
Contributor guide
Assessment
This issue has not been assessed yet.