getsentry / getsentry/sentry-javascript

New Semgrep Finding for getsentry/javascript-debug-ids

オープン
#22,936 コメント 1 件 リアクション 0 件 担当者 0 名 GitHub で見る
Bug javascript Security Supply-Chain-Vuln
主要言語
TypeScript
スター
8.7k
フォーク
1.8k
平均マージ
1日 17時間
マージ済み PR(30日)
515

説明

Repo: `getsentry/javascript-debug-ids`
Finding Confidence: Conditionally Reachable
Finding Severity: High

---

To reduce risk of accidental information disclosure, we are intentionally not exposing full vulnerability details here
Please see the parent ticket or Semgrep Console for more details: [https://semgrep.dev/orgs/sentry/supply-chain/findings/909969329]()

コントリビューションガイド

コントリビューションガイドを開く

調査の方向性

Start with the parent ticket or Semgrep Console finding 909969329 for the vulnerability details, then inspect the getsentry/javascript-debug-ids repository and its TypeScript code. Confirm the affected path and use resolution of the Semgrep finding as the completion criterion.

索引モデルが issue の本文から書いたものです。

評価

技術スタック
typescript
領域
security
issue の種類
バグ
難易度
4/5
見積もり時間
3〜5日
活発さ
静か
明瞭さ
説明が足りない
初心者へのやさしさ
25/100

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。