fix: update vulnerable dependency yaml #44
Labels
No labels
source:analyste
source:defenseur
source:human
source:medic
status:approved
status:blocked
status:in-progress
status:needs-fix
status:ready
status:review
status:triage
type:bug
type:feature
type:infra
type:refactor
type:schema
type:security
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference: maximus/Simpl-Resultat#44
Loading…
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Vulnerability detected by defenseur-simpl
The following MEDIUM severity vulnerability was flagged:
Analyse
Faux positif —
yamlest une dépendance optionnelle devite(pour le support des fichiers.yamlen config). Le package n'est pas installé dansnode_modulesetnpm auditne le signale pas.Le scan a probablement détecté la vulnérabilité dans le
package-lock.jsonqui liste les optional dependencies même non installées.Risque réel : aucun. Fermé sans changement.
Source: defenseur-simpl security scan