-
zizmor reported unpinned-uses · zizmor 1.28.0
The code has a known weakness, though this scan does not show that anyone can exploit it here.
Policy reason: zizmor-known-workflow-rule · Execution scope: automation
Source: .github/workflows/publish.yml:30
-
zizmor reported cache-poisoning · zizmor 1.28.0
The code has a known weakness, though this scan does not show that anyone can exploit it here.
Policy reason: zizmor-known-workflow-rule · Execution scope: automation
Source: .github/workflows/publish.yml:30
-
JavaScript analysis reported javascript.xray.data-exfiltration · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
This technical signal is not part of the shipped runtime behavior.
Policy reason: javascript-xray-inert-content · Execution scope: test-documentation-data
Source: server/persona-map.test.js:17
-
zizmor reported unpinned-uses · zizmor 1.28.0
The code has a known weakness, though this scan does not show that anyone can exploit it here.
Policy reason: zizmor-known-workflow-rule · Execution scope: automation
Source: .github/workflows/publish.yml:15
-
Dependency advisory GHSA-8xcm-r25x-g524:pkg:0e0e3ef7b07665812bdc5021 applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason: osv-structured-advisory · Execution scope: unknown
Source: server/package-lock.json
-
Dependency advisory GHSA-h67p-54hq-rp68:pkg:0199d54d4e55594b20539f39 applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason: osv-structured-advisory · Execution scope: unknown
Source: package-lock.json
-
Dependency advisory GHSA-g8m3-5g58-fq7m:pkg:d10a1af9c865101c9cc1b09a applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason: osv-structured-advisory · Execution scope: unknown
Source: server/package-lock.json
-
Dependency advisory GHSA-5p4m-2wfm-xmqj:pkg:a2732cf17ea59b7c9ad7dcba applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason: osv-structured-advisory · Execution scope: unknown
Source: package-lock.json
-
JavaScript analysis reported javascript.xray.shady-link · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
This technical signal is not part of the shipped runtime behavior.
Policy reason: javascript-xray-inert-content · Execution scope: test-documentation-data
Source: server/websocket-router.test.js:22
-
Dependency advisory GHSA-p88m-4jfj-68fv:pkg:efcee449c87d39d4db94186e applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason: osv-structured-advisory · Execution scope: unknown
Source: server/package-lock.json
-
Dependency advisory GHSA-m8rv-5g2x-5cg5:pkg:dfdc5c12308ee863a661f110 applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason: osv-structured-advisory · Execution scope: unknown
Source: server/package-lock.json
-
Dependency advisory GHSA-rgw5-rvv9-x895:pkg:d9de591f6b7272d0d17e4e9f applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason: osv-structured-advisory · Execution scope: unknown
Source: package-lock.json
-
zizmor reported unpinned-uses · zizmor 1.28.0
The code has a known weakness, though this scan does not show that anyone can exploit it here.
Policy reason: zizmor-known-workflow-rule · Execution scope: automation
Source: .github/workflows/publish.yml:18
-
JavaScript analysis reported javascript.xray.data-exfiltration · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
This technical signal is not part of the shipped runtime behavior.
Policy reason: javascript-xray-inert-content · Execution scope: test-documentation-data
Source: server/lang-map.test.js:17
-
Dependency advisory GHSA-v3r7-h72x-cjcm:pkg:78c671fc46b87817fdf1de6e applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason: osv-structured-advisory · Execution scope: unknown
Source: server/package-lock.json
-
Dependency advisory GHSA-52cp-r559-cp3m:pkg:cf5cb3ae8e56cb4261cd5e98 applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason: osv-structured-advisory · Execution scope: unknown
Source: package-lock.json
-
Dependency advisory GHSA-35p6-xmwp-9g52:pkg:7cd7d8f74690ab75b37c197f applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason: osv-structured-advisory · Execution scope: unknown
Source: server/package-lock.json
-
Dependency advisory GHSA-3jxr-9vmj-r5cp:pkg:46968ba7f775ec580db4bbb2 applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason: osv-structured-advisory · Execution scope: unknown
Source: package-lock.json
-
Dependency advisory GHSA-vxpw-j846-p89q:pkg:9fd432fe695c0d4b2a2a02dc applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason: osv-structured-advisory · Execution scope: unknown
Source: server/package-lock.json
-
Dependency advisory GHSA-mh99-v99m-4gvg:pkg:4ccc458e17e9edf57fcb5743 applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason: osv-structured-advisory · Execution scope: unknown
Source: package-lock.json
-
JavaScript analysis reported javascript.xray.data-exfiltration · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
This technical signal is not part of the shipped runtime behavior.
Policy reason: javascript-xray-inert-content · Execution scope: test-documentation-data
Source: server/plugin-i18n.test.js:17
-
zizmor reported cache-poisoning · zizmor 1.28.0
The code has a known weakness, though this scan does not show that anyone can exploit it here.
Policy reason: zizmor-known-workflow-rule · Execution scope: automation
Source: .github/workflows/publish.yml:18