Package
gitlab-rails-ce-assets-19.4
Component
npm
Latest update
7.5
CVSS V3
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Justification
Impact
The flagged component is the editor's bundled 'npm' VS Code extension manifest (/srv/gitlab/public/assets/webpack/gitlab-web-ide-vscode-workbench-0.0.1-dev-20260106142046/vscode/extensions/npm/package.json). This is VS Code's built-in npm-scripts extension, a small JavaScript extension that provides task detection and script-running support for package.json - it declares its own unrelated version number and contains none of the actual 'npm' CLI/library code, so the vulnerable code is not shipped.
Status