Skip to content

chore(COD-7131): upgrade packages 1/n#272

Draft
jeremydubreil wants to merge 1 commit into
mainfrom
update-packages
Draft

chore(COD-7131): upgrade packages 1/n#272
jeremydubreil wants to merge 1 commit into
mainfrom
update-packages

Conversation

@jeremydubreil

Copy link
Copy Markdown
Contributor

No description provided.

@lacework-code-security

Copy link
Copy Markdown

Lacework Code Security

When a Pull Request in a repository is submitted, the Lacework FortiCNAPP runs scans on both the source and target branches and compares the results to identify any issues / vulnerabilities which will be introduced by the source branch.
See summary in Lacework FortiCNAPP

3rd Party Vulnerabilities - Found 1 package(s) which introduces 1 new CVE(s) - Severity: 🛑 High

Expand Details

The Lacework FortiCNAPP’s Software Composition Analysis (SCA) tool identified the following vulnerabilities introduced through the 3rd-party packages / dependencies included in the source branch.

Package Location Vulnerabilities (CVEs) Fix Version
Direct Transitive
@actions/artifact@2.3.2 package.json#L7
./
- 🛑 High: 1 Unknown
Expand Details
Vulnerability ID Severity Dependency
Direct / Transitive
Fix Version
CVE-2026-44665 🛑 High fast-xml-builder@1.1.4
Transitive
1.1.7

For more information on adding exceptions for any of the finding above, please refer to the Leveraging the codesec.yaml file for exceptions guide

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant