bahmutov / bahmutov/cy-api

Checkmarx high severity risk for cy.api's yauzl dep

Open
#224 3 comments 0 reactions 0 assignees View on GitHub
Dominant language
TypeScript
Stars
210
Forks
26
PR merge metrics
No merged PRs in 30d

Description

We are running Cypress 12.8 (planning to upgrade sooner than later) and using this plugin... since a couple of weeks ago our Checkmarx validation started to yell due to a high severity security risk for the "yauzl" package (among others) which is a dependency of cy-api.

What would be the approach to try to solve this? (For cy-api or any other packages.. we are getting high severity risk for other dependencies, most of them are Cypress' deps, but also some of other packages). Try asking Cypress and every npm package developer that has this issues to try to upgrade their dependencies?

I guess that just bypassing or ignoring these kind of warnings in Checkmarx is not an option.

cypress / yauzl @ 2.10.0
cypress / debug @ 3.2.7
cypress-grep / debug @ 4.3.1
cypress / debug @ 4.3.4
cypress / inflight @ 1.0.6

![image](https://github.com/bahmutov/cy-api/assets/7246755/ab0c6f59-cd53-426c-8ebc-40f8d7596f8b)

Thanks

Contributor guide

No contributing guide indexed for this repository

Research direction

Start by reproducing the Checkmarx report for cy-api's dependency tree, beginning with yauzl 2.10.0 and the listed debug and inflight versions. Determine whether each finding comes from cy-api, Cypress, or cypress-grep, then confirm an actionable upgrade path with the relevant package maintainers. Done means the high-severity findings are resolved or their ownership and remediation are documented.

Written by the indexing model from the issue text.

Assessment

Tech stack
cypress, typescript
Domain
devtools, security
Issue type
Bug
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
20/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.