Skip to content

Update dependency @vonage/server-sdk to v3 (main)#24

Open
mend-for-github-com[bot] wants to merge 1 commit intomainfrom
whitesource-remediate/main-vonage-server-sdk-3.x
Open

Update dependency @vonage/server-sdk to v3 (main)#24
mend-for-github-com[bot] wants to merge 1 commit intomainfrom
whitesource-remediate/main-vonage-server-sdk-3.x

Conversation

@mend-for-github-com
Copy link
Copy Markdown

@mend-for-github-com mend-for-github-com Bot commented Aug 5, 2025

This PR contains the following updates:

Package Type Update Change
@vonage/server-sdk (source) dependencies major ^2.10.8^3.0.0

By merging this PR, the below vulnerabilities will be automatically resolved:

Severity CVSS Score Vulnerability Reachability
Critical Critical 9.8 CVE-2021-3918

Unreachable

High High 8.7 CVE-2025-7783

Reachable

High High 7.5 CVE-2025-65945

Reachable

Medium Medium 6.5 CVE-2023-26136

Reachable

Medium Medium 6.4 CVE-2022-23540

Reachable

Medium Medium 5.9 CVE-2022-23539

Reachable

Medium Medium 5.6 CVE-2020-15366

Unreachable

Medium Medium 5.3 CVE-2022-25883

Unreachable

Medium Medium 5.0 CVE-2022-23541

Reachable


Release Notes

Vonage/vonage-node-sdk (@​vonage/server-sdk)

v3.0.0

Compare Source

Bug Fixes
  • add top level package-lock (a845782)
  • auth: add signed requests and req updates (887a776)
Features
  • numbers: Add Numbers module code (a78e9f0)
  • numbers: add numbers module) (82805e4)
  • sms: add sms module (4479d03)

v2.11.3

Compare Source

v2.11.2

Compare Source

  • Corrected issue where downloading a voice recording transcript would throw an exception

v2.11.1

Compare Source

v2.11.0

Compare Source

2.11.0

  • Added support for the Messages API v1.0

v2.10.11: 2.10.11

Compare Source

2.10.11

Fixed
  • callback argument missing (#​597)
  • Repair signatures, fix up tests, remove legacy querystring

v2.10.10

Compare Source

v2.10.9

Compare Source

  • Remove extraneous log output.

  • If you want to rebase/retry this PR, check this box

@mend-for-github-com mend-for-github-com Bot added the security fix Security fix generated by Mend label Aug 5, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

security fix Security fix generated by Mend

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants