getsentry / getsentry/sentry-javascript
New Semgrep Finding for getsentry/javascript-debug-ids
オープン
Bug
javascript
Security
Supply-Chain-Vuln
- 主要言語
- TypeScript
- スター
- 8.7k
- フォーク
- 1.8k
- 平均マージ
- 1日 17時間
- マージ済み PR(30日)
- 515
説明
Repo: `getsentry/javascript-debug-ids`
Finding Confidence: Conditionally Reachable
Finding Severity: High
---
To reduce risk of accidental information disclosure, we are intentionally not exposing full vulnerability details here
Please see the parent ticket or Semgrep Console for more details: [https://semgrep.dev/orgs/sentry/supply-chain/findings/909969329]()
コントリビューションガイド
調査の方向性
Start with the parent ticket or Semgrep Console finding 909969329 for the vulnerability details, then inspect the getsentry/javascript-debug-ids repository and its TypeScript code. Confirm the affected path and use resolution of the Semgrep finding as the completion criterion.
索引モデルが issue の本文から書いたものです。
評価
- 技術スタック
- typescript
- 領域
- security
- issue の種類
- バグ
- 難易度
- 4/5
- 見積もり時間
- 3〜5日
- 活発さ
- 静か
- 明瞭さ
- 説明が足りない
- 初心者へのやさしさ
- 25/100