Skip to content

Conversation

@ast-phoenix
Copy link

Updates checkmarx-ast-cli to 2.3.22

Auto-generated by [create-pull-request][2]

@cx-ben-alvo
Copy link
Collaborator

Logo
Checkmarx One – Scan Summary & Detailsd253a48b-b4c9-4a8e-9dae-d86392044a9a

New Issues (2)

Checkmarx found the following issues in this Pull Request

Severity Issue Source File / Package Checkmarx Insight
HIGH CVE-2025-48387 Npm-tar-fs-2.1.2
detailsRecommended version: 2.1.3
Description: The package tar-fs provides filesystem bindings for tar-stream. In versions prior to 1.16.5, 2.0.x prior to 2.1.3, and 3.0.x prior to 3.0.9, have...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: %2BnP7qoKv1qkLayvyQfwLCI%2F%2FIZiDHOFmA04T8%2FXsR2M%3D
Vulnerable Package
HIGH CVE-2025-48387 Npm-tar-fs-1.16.4
detailsRecommended version: 1.16.5
Description: The package tar-fs provides filesystem bindings for tar-stream. In versions prior to 1.16.5, 2.0.x prior to 2.1.3, and 3.0.x prior to 3.0.9, have...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: XWJjpF6kEIYobbdTGINA%2BzZ9gx6vqhU9WyUlj0nOusc%3D
Vulnerable Package
Policy Management Violations (1)
Policy Name: Phoenix-Policy The following violations of your team's AppSec policy rules were identified in this project. Since 'Break Build' is enabled for these rules, you must resolve these issues before the Pull Request can be merged.
  • Rule Name: New vulnerabilities of High, Medium and Low severity levels detected
    Scanner: SAST,SCA,IaC-Security

@cx-daniel-greenspan cx-daniel-greenspan merged commit d0beced into main Jun 4, 2025
4 of 5 checks passed
@cx-daniel-greenspan cx-daniel-greenspan deleted the feature/update_cli_2.3.22 branch June 4, 2025 13:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants