-
-
Notifications
You must be signed in to change notification settings - Fork 184
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Critical Vulnerability due to Resolve Package -- monorepo-symlink-test #310
Comments
Hey! please refer to this: #309 |
Because it's a private package that just coincidentally has the same name as the malicious one, it is a false positive - so whatever tool is flagging this repo is broken, and you should strongly reconsider using a tool that is this naive about npm package names. Duplicate of #303. Duplicate of #291. Duplicate of #288. Duplicate of #304. Duplicate of #305. Duplicate of #306. Duplicate of #309. |
Package causing vulnerability can be found below:
https://github.com/browserify/resolve/blob/main/test/resolver/multirepo/package.json
This is causing deployments to fail security screening due to the following:
https://snyk.io/advisor/npm-package/monorepo-symlink-test
The text was updated successfully, but these errors were encountered: