Skip to content

Demo: exercise PR security-review integrations (do not merge) - #5

Open
bomly-guy wants to merge 1 commit into
mainfrom
demo/socket-pr-comment-trigger
Open

Demo: exercise PR security-review integrations (do not merge)#5
bomly-guy wants to merge 1 commit into
mainfrom
demo/socket-pr-comment-trigger

Conversation

@bomly-guy

Copy link
Copy Markdown
Member

Fixture-repo demo PR. Adds node-fetch@2.6.0 (known advisories CVE-2020-15168, CVE-2022-0235) to observe the PR-comment/check behavior of the security integrations connected to this repository (Bomly Guard workflow + the recently installed Socket GitHub App).

Do not merge — will be closed after the integration output is captured.

🤖 Generated with Claude Code

Demo change: introduces a dependency with known advisories
(CVE-2020-15168, CVE-2022-0235) to observe PR-comment behavior of
connected security integrations on this fixture repository. Not for merge.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@socket-security

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Addednode-fetch@​2.6.0958410085100

View full report

Comment thread package-lock.json
}
},
"node_modules/node-fetch": {
"version": "2.6.0",
@github-actions

github-actions Bot commented Aug 1, 2026

Copy link
Copy Markdown

Bomly Diff Summary

Compared c226b2c1f8bcbc40ab51d80febd28c044a96f818 to 0958062f1f11cdb2440154592035e58c45bf3db6.

Overview

Status Manifests Dependencies Findings Duration
❌ Failing findings +0 / ~1 / -0 1 added / 0 version changed / 0 detail changes / 0 removed 1 introduced / 0 persisted / 0 resolved 54.7s

Dependency Changes

Summary: 1 added, 0 version changed, 0 detail changes, 0 removed.

Added Dependencies

Change Package Version Direct? Scope Licenses
added node-fetch@2.6.0 2.6.0 Yes runtime MIT

Vulnerabilities

Summary: 2 introduced, 0 persisted, 0 resolved.

Introduced Vulnerabilities

Change Severity ID Package Fixed In Source Title
introduced HIGH GHSA-r683-j2x4-v87g node-fetch@2.6.0 2.6.7 grype node-fetch forwards secure headers to untrusted sites
introduced LOW GHSA-w7rc-rwvf-8q5r node-fetch@2.6.0 2.6.1 grype The size option isn't honored after following a redirect in node-fetch

License Changes

Summary: 1 added, 0 changed, 0 removed.

Added Licenses

Change Package Licenses
added node-fetch@2.6.0 MIT

Project Posture

✅ No project posture changes (--matchers +scorecard was not selected).

Policy Findings

Summary: 1 introduced, 0 persisted, 0 resolved.

Introduced Findings

Status Category Severity ID Package Fixed In Title
introduced vulnerability HIGH GHSA-r683-j2x4-v87g node-fetch@2.6.0 2.6.7 node-fetch forwards secure headers to untrusted sites

Legend: ✅ resolved · ❌ failing · ⚠️ warning

Remediation

✅ 1 fix suggestion for 1 of 1 vulnerable package.

Vulnerable package Status Recommended version Action Suggested action for Manifest Manager advice
node-fetch@2.6.0 Complete fix available 2.6.7 Direct bump pkg:npm/node-fetch@2.6.0 package-lock.json -

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants