getsentry / getsentry/sentry-javascript

New Semgrep Finding for getsentry/javascript-debug-ids

未关闭
#22,936 1 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看
Bug javascript Security Supply-Chain-Vuln
主要语言
TypeScript
星标
8.7k
派生
1.8k
平均合并
1 天 17 小时
30 天内合并 PR
523

描述

Repo: `getsentry/javascript-debug-ids`
Finding Confidence: Conditionally Reachable
Finding Severity: High

---

To reduce risk of accidental information disclosure, we are intentionally not exposing full vulnerability details here
Please see the parent ticket or Semgrep Console for more details: [https://semgrep.dev/orgs/sentry/supply-chain/findings/909969329]()

贡献指南

打开贡献指南

调研方向

Start with the parent ticket or Semgrep Console finding 909969329 for the vulnerability details, then inspect the getsentry/javascript-debug-ids repository and its TypeScript code. Confirm the affected path and use resolution of the Semgrep finding as the completion criterion.

由索引模型根据 Issue 内容生成。

评估

技术栈
typescript
领域
security
Issue 类型
缺陷
难度
4/5
预计耗时
3-5 天
活跃度
冷清
描述清晰度
需要澄清
新手友好度
25/100

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。