Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Snyk] Snyk check for week of 1/22/25 #187

Closed
exalate-issue-sync bot opened this issue Jan 20, 2025 · 5 comments
Closed

[Snyk] Snyk check for week of 1/22/25 #187

exalate-issue-sync bot opened this issue Jan 20, 2025 · 5 comments
Assignees

Comments

@exalate-issue-sync
Copy link

exalate-issue-sync bot commented Jan 20, 2025

Snyk check:

Per the snyk spreadsheet (https://docs.google.com/spreadsheets/d/1SNMOyGS4JAKgXQ0RhhzoX7M2ib1vm14dD0LxWNpssP4/edit?gid=0#gid=0 ) check snyk alerts for all projects and create tickets to address ALL alerts.

Steps to create tickets for alerts:

https://github.com/fecgov/fecfile-web-api/wiki/Snyk-security-scanning

QA Notes

null

DEV Notes

null

Design

null

See full ticket and images here: FECFILE-1958

Pull Request: https://fecgov.atlassian.net/browse/FECFILE-1972

@exalate-issue-sync exalate-issue-sync bot changed the title [Snyk] Snyk check for week of [Snyk] Snyk check for week of 1/22/25 Jan 22, 2025
Copy link
Author

Sasha Dresden commented: 2 New API Vulnerability
1 New Validation Vulnerability
1 New APP Vulnerability

API
django 5.1.4 introduced 2 Vulnerabilities both of which can be resolved by updating to django 5.1.5

Validation

Glob 7.2.3 has dependent vulnerability from: [email protected]
Recommendation is to update Glob to at least version 9 as everything before that is deprecated. Latest version of glob is 11.0.1

APP
@angular-devkit/build-angular uses "vite": "5.4.6". We need to use @5.4.12 or we could update to the next version of angular which addresses this vulnerability.

Copy link
Author

Sasha Dresden commented: [https://fecgov.atlassian.net/browse/FECFILE-1955|https://fecgov.atlassian.net/browse/FECFILE-1955|smart-link] will address the API issue.

[https://fecgov.atlassian.net/browse/FECFILE-1942|https://fecgov.atlassian.net/browse/FECFILE-1942|smart-link] will address the Validation issue;

New ticket required for APP issue. [https://fecgov.atlassian.net/browse/FECFILE-1972|https://fecgov.atlassian.net/browse/FECFILE-1972|smart-link]

Copy link
Author

Todd Lees commented: All follow up tickets accounted for and put in sprints

Copy link
Author

Shelly Wise commented: No QA review needed on this ticket per DEV.

Moved to Stage Ready.

Copy link
Author

Automation for Jira commented: Sprint accepted by Paul Clark during sprint review on the date of this comment.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant