Skip to content

Don't force skills selection on Topgear challenge edits

46ed479
Select commit
Loading
Failed to load commit list.
Merged

Don't force skills selection on Topgear challenge edits #1706

Don't force skills selection on Topgear challenge edits
46ed479
Select commit
Loading
Failed to load commit list.
GitHub Advanced Security / Trivy failed Nov 4, 2025 in 5s

93 new alerts including 9 critical severity security vulnerabilities

New alerts in code changed by this pull request

Security Alerts:

  • 9 critical
  • 42 high
  • 34 medium
  • 8 low

Alerts not introduced by this pull request might have been detected because the code changes were too large.

See annotations below for details.

View all branch alerts.

Annotations

Check failure on line 1050 in test-automation/package-lock.json

See this annotation in the file changed.

Code scanning / Trivy

minimist: prototype pollution Critical test

Package: minimist
Installed Version: 1.2.5
Vulnerability CVE-2021-44906
Severity: CRITICAL
Fixed Version: 1.2.6, 0.2.4
Link: CVE-2021-44906

Check failure on line 1045 in test-automation/package-lock.json

See this annotation in the file changed.

Code scanning / Trivy

nodejs-minimatch: ReDoS via the braceExpand function High test

Package: minimatch
Installed Version: 3.0.4
Vulnerability CVE-2022-3517
Severity: HIGH
Fixed Version: 3.0.5
Link: CVE-2022-3517

Check failure on line 933 in test-automation/package-lock.json

See this annotation in the file changed.

Code scanning / Trivy

jszip: directory traversal via a crafted ZIP archive High test

Package: jszip
Installed Version: 3.7.0
Vulnerability CVE-2022-48285
Severity: MEDIUM
Fixed Version: 3.8.0
Link: CVE-2022-48285

Check failure on line 864 in test-automation/package-lock.json

See this annotation in the file changed.

Code scanning / Trivy

nodejs-json-schema: Prototype pollution vulnerability Critical test

Package: json-schema
Installed Version: 0.2.3
Vulnerability CVE-2021-3918
Severity: CRITICAL
Fixed Version: 0.4.0
Link: CVE-2021-3918

Check failure on line 578 in test-automation/package-lock.json

See this annotation in the file changed.

Code scanning / Trivy

form-data: Unsafe random function in form-data Critical test

Package: form-data
Installed Version: 2.3.3
Vulnerability CVE-2025-7783
Severity: CRITICAL
Fixed Version: 2.5.4, 3.0.4, 4.0.4
Link: CVE-2025-7783

Check failure on line 333 in test-automation/package-lock.json

See this annotation in the file changed.

Code scanning / Trivy

cross-spawn: regular expression denial of service High test

Package: cross-spawn
Installed Version: 6.0.5
Vulnerability CVE-2024-21538
Severity: HIGH
Fixed Version: 7.0.5, 6.0.6
Link: CVE-2024-21538

Check failure on line 243 in test-automation/package-lock.json

See this annotation in the file changed.

Code scanning / Trivy

nodejs-ansi-regex: Regular expression denial of service (ReDoS) matching ANSI escape codes High test

Package: ansi-regex
Installed Version: 5.0.0
Vulnerability CVE-2021-3807
Severity: HIGH
Fixed Version: 6.0.1, 5.0.1, 4.1.1, 3.0.1
Link: CVE-2021-3807

Check failure on line 1 in pnpm-lock.yaml

See this annotation in the file changed.

Code scanning / Trivy

loader-utils: prototype pollution in function parseQuery in parseQuery.js Critical

Package: loader-utils
Installed Version: 1.2.3
Vulnerability CVE-2022-37601
Severity: CRITICAL
Fixed Version: 2.0.3, 1.4.1
Link: CVE-2022-37601

Check failure on line 1 in pnpm-lock.yaml

See this annotation in the file changed.

Code scanning / Trivy

loader-utils: regular expression denial of service in interpolateName.js High

Package: loader-utils
Installed Version: 1.2.3
Vulnerability CVE-2022-37599
Severity: HIGH
Fixed Version: 1.4.2, 2.0.4, 3.2.1
Link: CVE-2022-37599

Check failure on line 1 in pnpm-lock.yaml

See this annotation in the file changed.

Code scanning / Trivy

loader-utils: Regular expression denial of service High

Package: loader-utils
Installed Version: 1.2.3
Vulnerability CVE-2022-37603
Severity: HIGH
Fixed Version: 1.4.2, 2.0.4, 3.2.1
Link: CVE-2022-37603

Check failure on line 1 in pnpm-lock.yaml

See this annotation in the file changed.

Code scanning / Trivy

nodejs-lodash: prototype pollution in defaultsDeep function leading to modifying properties Critical

Package: lodash
Installed Version: 4.17.11
Vulnerability CVE-2019-10744
Severity: CRITICAL
Fixed Version: 4.17.12
Link: CVE-2019-10744

Check failure on line 1 in pnpm-lock.yaml

See this annotation in the file changed.

Code scanning / Trivy

nodejs-lodash: prototype pollution in zipObjectDeep function High

Package: lodash
Installed Version: 4.17.11
Vulnerability CVE-2020-8203
Severity: HIGH
Fixed Version: 4.17.19
Link: CVE-2020-8203

Check failure on line 1 in pnpm-lock.yaml

See this annotation in the file changed.

Code scanning / Trivy

nodejs-lodash: command injection via template High

Package: lodash
Installed Version: 4.17.11
Vulnerability CVE-2021-23337
Severity: HIGH
Fixed Version: 4.17.21
Link: CVE-2021-23337

Check failure on line 143 in test-automation/package-lock.json

See this annotation in the file changed.

Code scanning / Trivy

async: Prototype Pollution in async High test

Package: async
Installed Version: 3.2.0
Vulnerability CVE-2021-43138
Severity: HIGH
Fixed Version: 3.2.2, 2.6.4
Link: CVE-2021-43138

Check failure on line 1 in pnpm-lock.yaml

See this annotation in the file changed.

Code scanning / Trivy

Prototype Pollution in merge High

Package: merge
Installed Version: 1.2.1
Vulnerability CVE-2020-28499
Severity: HIGH
Fixed Version: 2.1.1
Link: CVE-2020-28499

Check failure on line 1 in pnpm-lock.yaml

See this annotation in the file changed.

Code scanning / Trivy

nodejs-minimatch: ReDoS via the braceExpand function High

Package: minimatch
Installed Version: 3.0.4
Vulnerability CVE-2022-3517
Severity: HIGH
Fixed Version: 3.0.5
Link: CVE-2022-3517

Check failure on line 1 in pnpm-lock.yaml

See this annotation in the file changed.

Code scanning / Trivy

node-fetch: exposure of sensitive information to an unauthorized actor High

Package: node-fetch
Installed Version: 1.7.3
Vulnerability CVE-2022-0235
Severity: HIGH
Fixed Version: 3.1.1, 2.6.7
Link: CVE-2022-0235

Check failure on line 1 in pnpm-lock.yaml

See this annotation in the file changed.

Code scanning / Trivy

node-forge: Signature verification leniency in checking `digestAlgorithm` structure can lead to signature forgery High

Package: node-forge
Installed Version: 0.10.0
Vulnerability CVE-2022-24771
Severity: HIGH
Fixed Version: 1.3.0
Link: CVE-2022-24771

Check failure on line 1 in pnpm-lock.yaml

See this annotation in the file changed.

Code scanning / Trivy

node-forge: Signature verification failing to check tailing garbage bytes can lead to signature forgery High

Package: node-forge
Installed Version: 0.10.0
Vulnerability CVE-2022-24772
Severity: HIGH
Fixed Version: 1.3.0
Link: CVE-2022-24772

Check failure on line 1 in pnpm-lock.yaml

See this annotation in the file changed.

Code scanning / Trivy

webpack-dev-middleware: lack of URL validation may lead to file leak High

Package: webpack-dev-middleware
Installed Version: 3.7.3
Vulnerability CVE-2024-29180
Severity: HIGH
Fixed Version: 7.1.0, 6.1.2, 5.3.4
Link: CVE-2024-29180

Check failure on line 1 in pnpm-lock.yaml

See this annotation in the file changed.

Code scanning / Trivy

nodejs-trim-newlines: ReDoS in .end() method High

Package: trim-newlines
Installed Version: 1.0.0
Vulnerability CVE-2021-33623
Severity: HIGH
Fixed Version: 3.0.1, 4.0.1
Link: CVE-2021-33623

Check failure on line 1 in pnpm-lock.yaml

See this annotation in the file changed.

Code scanning / Trivy

nodejs-tar: Arbitrary File Creation/Overwrite on Windows via insufficient relative path sanitization High

Package: tar
Installed Version: 2.2.2
Vulnerability CVE-2021-37713
Severity: HIGH
Fixed Version: 4.4.18, 5.0.10, 6.1.9
Link: CVE-2021-37713

Check failure on line 1 in pnpm-lock.yaml

See this annotation in the file changed.

Code scanning / Trivy

nodejs-nth-check: inefficient regular expression complexity High

Package: nth-check
Installed Version: 1.0.2
Vulnerability CVE-2021-3803
Severity: HIGH
Fixed Version: 2.0.1
Link: CVE-2021-3803

Check failure on line 1 in pnpm-lock.yaml

See this annotation in the file changed.

Code scanning / Trivy

nodejs-tar: Insufficient absolute path sanitization allowing arbitrary file creation and overwrite High

Package: tar
Installed Version: 2.2.2
Vulnerability CVE-2021-32804
Severity: HIGH
Fixed Version: 3.2.2, 4.4.14, 5.0.6, 6.1.1
Link: CVE-2021-32804

Check failure on line 1 in pnpm-lock.yaml

See this annotation in the file changed.

Code scanning / Trivy

nodejs-semver: Regular expression denial of service High

Package: semver
Installed Version: 5.3.0
Vulnerability CVE-2022-25883
Severity: HIGH
Fixed Version: 7.5.2, 6.3.1, 5.7.2
Link: CVE-2022-25883