-
Notifications
You must be signed in to change notification settings - Fork 1.4k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[Snyk] Fix for 2 vulnerabilities #7152
base: develop
Are you sure you want to change the base?
Conversation
…ties The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-JS-SERIALIZEJAVASCRIPT-6147607 - https://snyk.io/vuln/SNYK-JS-DOMPURIFY-8722251
|
Build Error! No Linked Issue found. Please link an issue or mention it in the body using #<issue_id> |
Build Error! No Linked Issue found. Please link an issue or mention it in the body using #<issue_id> |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
👍 Looks good to me! Reviewed everything up to ac35e4f in 1 minute and 2 seconds
More details
- Looked at
22
lines of code in1
files - Skipped
1
files when reviewing. - Skipped posting
4
drafted comments based on config settings.
1. frontend/package.json:71
- Draft comment:
Upgrade dompurify from 3.1.3 to 3.2.4 to address XSS vulnerability. Ensure compatibility with existing usage. - Reason this comment was not posted:
Comment did not seem useful. Confidence is useful =50%
<= threshold50%
This comment is about upgrading a dependency to address a security vulnerability. However, it also asks to ensure compatibility, which violates the rule against asking the PR author to ensure things. The part about ensuring compatibility should be removed.
2. frontend/package.json:130
- Draft comment:
Upgrade webpack from 5.94.0 to 5.98.0 as part of security fixes. Verify plugin compatibility after update. - Reason this comment was not posted:
Comment did not seem useful. Confidence is useful =0%
<= threshold50%
This comment is related to a dependency change, specifically an upgrade of webpack. The comment also asks the PR author to verify plugin compatibility, which is against the rules of asking for confirmation or verification. Therefore, this comment should be removed.
3. frontend/package.json:71
- Draft comment:
Upgrade DomPurify to 3.2.4 to address the XSS vulnerability (SNYK-JS-DOMPURIFY-8722251). Verify that any custom sanitization options remain compatible. - Reason this comment was not posted:
Confidence changes required:0%
<= threshold50%
None
4. frontend/package.json:130
- Draft comment:
Upgrade webpack to 5.98.0 to fix the serialize-javascript vulnerability (SNYK-JS-SERIALIZEJAVASCRIPT-6147607). Please double-check webpack config compatibility. - Reason this comment was not posted:
Confidence changes required:0%
<= threshold50%
None
Workflow ID: wflow_BOrFwsLPl5aBYOME
You can customize Ellipsis with 👍 / 👎 feedback, review rules, user-specific overrides, quiet
mode, and more.
Snyk has created this PR to fix 2 vulnerabilities in the yarn dependencies of this project.
Snyk changed the following file(s):
frontend/package.json
frontend/yarn.lock
Note for zero-installs users
If you are using the Yarn feature zero-installs that was introduced in Yarn V2, note that this PR does not update the
.yarn/cache/
directory meaning this code cannot be pulled and immediately developed on as one would expect for a zero-install project - you will need to runyarn
to update the contents of the./yarn/cache
directory.If you are not using zero-install you can ignore this as your flow should likely be unchanged.
Vulnerabilities that will be fixed with an upgrade:
SNYK-JS-SERIALIZEJAVASCRIPT-6147607
SNYK-JS-DOMPURIFY-8722251
Important
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.
For more information:
🧐 View latest project report
📜 Customise PR templates
🛠 Adjust project settings
📚 Read about Snyk's upgrade logic
Learn how to fix vulnerabilities with free interactive lessons:
🦉 Cross-site Scripting (XSS)
Important
Upgrade
dompurify
andwebpack
infrontend/package.json
to fix XSS vulnerabilities.dompurify
from3.1.3
to3.2.4
infrontend/package.json
andfrontend/yarn.lock
.webpack
from5.94.0
to5.98.0
infrontend/package.json
andfrontend/yarn.lock
.dompurify
andwebpack
.This description was created by
for ac35e4f. It will automatically update as commits are pushed.