-
Notifications
You must be signed in to change notification settings - Fork 1.4k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[Snyk] Fix for 2 vulnerabilities #7117
base: develop
Are you sure you want to change the base?
Conversation
…ties The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-JS-SERIALIZEJAVASCRIPT-6147607 - https://snyk.io/vuln/SNYK-JS-DOMPURIFY-8722251
|
Build Error! No Linked Issue found. Please link an issue or mention it in the body using #<issue_id> |
1 similar comment
Build Error! No Linked Issue found. Please link an issue or mention it in the body using #<issue_id> |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
👍 Looks good to me! Reviewed everything up to da3eb2b in 39 seconds
More details
- Looked at
22
lines of code in1
files - Skipped
1
files when reviewing. - Skipped posting
4
drafted comments based on config settings.
1. frontend/package.json:71
- Draft comment:
Updated dompurify version. Ensure that no breaking changes (API or security behavior) were introduced in 3.2.4. Verify that related usage across the app is compatible. - Reason this comment was not posted:
Marked as duplicate.
2. frontend/package.json:130
- Draft comment:
Upgraded webpack to 5.98.0. Confirm that this upgrade does not introduce incompatibilities in the build setup. - Reason this comment was not posted:
Marked as duplicate.
3. frontend/package.json:70
- Draft comment:
Bump 'dompurify' from 3.1.3 to 3.2.4 to address XSS vulnerabilities (SNYK-JS-DOMPURIFY-8722251). Please verify that this update doesn't break any usages in the project. - Reason this comment was not posted:
Comment did not seem useful. Confidence is useful =0%
<= threshold50%
This comment is related to a dependency change, specifically a version bump for 'dompurify'. The comment asks the PR author to verify that the update doesn't break any usages, which violates the rule against asking for confirmation or verification. Therefore, this comment should not be approved.
4. frontend/package.json:129
- Draft comment:
Upgrade 'webpack' from 5.94.0 to 5.98.0 to patch potential vulnerabilities. Ensure that the custom webpack configuration remains compatible with this version. - Reason this comment was not posted:
Comment did not seem useful. Confidence is useful =0%
<= threshold50%
This comment is related to a dependency change, specifically upgrading 'webpack'. The comment suggests ensuring compatibility with custom configurations, which falls under asking the PR author to ensure behavior is intended or tested. This violates the rules.
Workflow ID: wflow_d8xyTzzsJC2Ksqpi
You can customize Ellipsis with 👍 / 👎 feedback, review rules, user-specific overrides, quiet
mode, and more.
Snyk has created this PR to fix 2 vulnerabilities in the yarn dependencies of this project.
Snyk changed the following file(s):
frontend/package.json
frontend/yarn.lock
Note for zero-installs users
If you are using the Yarn feature zero-installs that was introduced in Yarn V2, note that this PR does not update the
.yarn/cache/
directory meaning this code cannot be pulled and immediately developed on as one would expect for a zero-install project - you will need to runyarn
to update the contents of the./yarn/cache
directory.If you are not using zero-install you can ignore this as your flow should likely be unchanged.
Vulnerabilities that will be fixed with an upgrade:
SNYK-JS-SERIALIZEJAVASCRIPT-6147607
SNYK-JS-DOMPURIFY-8722251
Important
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.
For more information:data:image/s3,"s3://crabby-images/9e517/9e517fd4ee1bdbad69a969c8b4708f5ab0864b31" alt=""
🧐 View latest project report
📜 Customise PR templates
🛠 Adjust project settings
📚 Read about Snyk's upgrade logic
Learn how to fix vulnerabilities with free interactive lessons:
🦉 Cross-site Scripting (XSS)
Important
Upgrade
dompurify
andwebpack
infrontend/package.json
to fix XSS vulnerabilities.dompurify
from3.1.3
to3.2.4
infrontend/package.json
to fix XSS vulnerability.webpack
from5.94.0
to5.98.0
infrontend/package.json
to fix XSS vulnerability.frontend/package.json
andfrontend/yarn.lock
for dependency changes.yarn
to update.yarn/cache/
directory.This description was created by
for da3eb2b. It will automatically update as commits are pushed.