getsentry / getsentry/sentry-javascript

New Semgrep Finding for getsentry/javascript-debug-ids

Open
#22,936 1 comment 0 reactions 0 assignees View on GitHub
Bug javascript Security Supply-Chain-Vuln
Dominant language
TypeScript
Stars
8.7k
Forks
1.8k
Avg merge
1d 17h
Merged PRs (30d)
515

Description

Repo: `getsentry/javascript-debug-ids`
Finding Confidence: Conditionally Reachable
Finding Severity: High

---

To reduce risk of accidental information disclosure, we are intentionally not exposing full vulnerability details here
Please see the parent ticket or Semgrep Console for more details: [https://semgrep.dev/orgs/sentry/supply-chain/findings/909969329]()

Contributor guide

Open the contributing guide

Research direction

Start with the parent ticket or Semgrep Console finding 909969329 for the vulnerability details, then inspect the getsentry/javascript-debug-ids repository and its TypeScript code. Confirm the affected path and use resolution of the Semgrep finding as the completion criterion.

Written by the indexing model from the issue text.

Assessment

Tech stack
typescript
Domain
security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Quiet
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.