Checkmarx high severity risk for cy.api's yauzl dep
- Dominant language
- TypeScript
- Stars
- 210
- Forks
- 26
- PR merge metrics
- No merged PRs in 30d
Description
We are running Cypress 12.8 (planning to upgrade sooner than later) and using this plugin... since a couple of weeks ago our Checkmarx validation started to yell due to a high severity security risk for the "yauzl" package (among others) which is a dependency of cy-api.
What would be the approach to try to solve this? (For cy-api or any other packages.. we are getting high severity risk for other dependencies, most of them are Cypress' deps, but also some of other packages). Try asking Cypress and every npm package developer that has this issues to try to upgrade their dependencies?
I guess that just bypassing or ignoring these kind of warnings in Checkmarx is not an option.
cypress / yauzl @ 2.10.0
cypress / debug @ 3.2.7
cypress-grep / debug @ 4.3.1
cypress / debug @ 4.3.4
cypress / inflight @ 1.0.6

Thanks
Contributor guide
No contributing guide indexed for this repository
Research direction
Start by reproducing the Checkmarx report for cy-api's dependency tree, beginning with yauzl 2.10.0 and the listed debug and inflight versions. Determine whether each finding comes from cy-api, Cypress, or cypress-grep, then confirm an actionable upgrade path with the relevant package maintainers. Done means the high-severity findings are resolved or their ownership and remediation are documented.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- cypress, typescript
- Domain
- devtools, security
- Issue type
- Bug
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 20/100