-
-
Notifications
You must be signed in to change notification settings - Fork 185
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
monorepo-symlink-test security issue #319
Comments
Duplicate of #303. Duplicate of #291. Duplicate of #288. Duplicate of #304. Duplicate of #305. Duplicate of #306. Duplicate of #309. Duplicate of #310. Duplicate of #311. Duplicate of #312. Duplicate of #314. Duplicate of #317. Duplicate of #318. |
This package which is included in our project by a transitive dependency appears to include what the
monorepo-symlink-test
package which is identified as a malicious package in sca scanning tools such as AWS Inspector (9.8 - CRITICAL rating):https://security.snyk.io/vuln/SNYK-JS-MONOREPOSYMLINKTEST-5865510
and has been set as NPM Security Holding package:
https://www.npmjs.com/package/monorepo-symlink-test
Other related bugs:
Unitech/pm2#5669
The text was updated successfully, but these errors were encountered: