Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Vulnerability found in jest-editor-support #339

Closed
Bruswei opened this issue Nov 2, 2023 · 2 comments
Closed

Vulnerability found in jest-editor-support #339

Bruswei opened this issue Nov 2, 2023 · 2 comments

Comments

@Bruswei
Copy link

Bruswei commented Nov 2, 2023

Upon cloning the repository, I conducted a security check and identified a critical vulnerability linked to the repository. The specifics of the vulnerability are as follows:

Upgrade [email protected] to [email protected] to fix
 ✗ Incomplete List of Disallowed Inputs (new) [Critical Severity][https://security.snyk.io/vuln/SNYK-JS-BABELTRAVERSE-5962462] in @babel/[email protected]
   introduced by [email protected] > @babel/[email protected] and 10 other path(s)

This information was obtained through the snyk test command execution.

While not every vulnerability may pose an immediate risk to Visual Studio Code extensions, the nature of this particular issue warrants a closer examination. Could we assess whether this critical vulnerability presents a tangible risk to our extension's security posture?

@firsttris
Copy link
Owner

thx for reporting, i think we can update jest-editor-support to the latest version

@domsleee
Copy link
Collaborator

Thanks, closed by #347 👍

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants