[PROD RELEASE V6] #1288
[PROD RELEASE V6] #1288
14 new alerts including 7 high severity security vulnerabilities
New alerts in code changed by this pull request
Security Alerts:
- 7 high
- 6 medium
- 1 low
Alerts not introduced by this pull request might have been detected because the code changes were too large.
See annotations below for details.
Annotations
Check failure on line 27 in ssl-local/local.topcoder-dev.com+2-key.pem
Code scanning / Trivy
Asymmetric Private Key High
Check failure on line 27 in ssl-local/local.topcoder-dev.com+2-key.pem.bak
Code scanning / Trivy
Asymmetric Private Key High
Check failure on line 27 in ssl-local/local.topcoder.com-key.pem
Code scanning / Trivy
Asymmetric Private Key High
Check notice on line 1 in yarn.lock
Code scanning / Trivy
ISC in @topcoder-platform/platform-ui Low
Check failure on line 5749 in yarn.lock
Code scanning / Trivy
axios: Possible SSRF and Credential Leakage via Absolute URL in axios Requests High
Check failure on line 5749 in yarn.lock
Code scanning / Trivy
axios: Axios DoS via lack of data size check High
Check warning on line 5749 in yarn.lock
Code scanning / Trivy
axios: exposure of confidential data stored in cookies Medium
Check warning on line 7895 in yarn.lock
Code scanning / Trivy
dompurify: Mutation XSS in DOMPurify Due to Improper Template Literal Handling Medium
Check warning on line 8527 in yarn.lock
Code scanning / Trivy
esbuild enables any website to send any requests to the development server and read the response Medium
Check failure on line 13766 in yarn.lock
Code scanning / Trivy
node-fetch: exposure of sensitive information to an unauthorized actor High
Check failure on line 13841 in yarn.lock
Code scanning / Trivy
nodejs-nth-check: inefficient regular expression complexity High
Check warning on line 15211 in yarn.lock
Code scanning / Trivy
PostCSS: Improper input validation in PostCSS Medium
Check warning on line 19227 in yarn.lock
Code scanning / Trivy
webpack-dev-server: webpack-dev-server information exposure Medium
Check warning on line 19227 in yarn.lock
Code scanning / Trivy
webpack-dev-server: webpack-dev-server information exposure Medium