getsentry / getsentry/sentry-javascript
New Semgrep Finding for getsentry/javascript-debug-ids
オープン
Bug
javascript
Security
Supply-Chain-Vuln
- 主要言語
- TypeScript
- スター
- 8.7k
- フォーク
- 1.8k
- 平均マージ
- 1日 17時間
- マージ済み PR(30日)
- 523
説明
Repo: `getsentry/javascript-debug-ids`
Finding Confidence: Conditionally Reachable
Finding Severity: High
---
To reduce risk of accidental information disclosure, we are intentionally not exposing full vulnerability details here
Please see the parent ticket for more details. Semgrep Console: [https://semgrep.dev/orgs/sentry/supply-chain/findings/965341898]()
コントリビューションガイド
調査の方向性
Start with the parent ticket and Semgrep Console finding 965341898; this issue intentionally omits the vulnerability details. Use those sources to identify the affected code and required remediation, then confirm that the finding is resolved.
索引モデルが issue の本文から書いたものです。
評価
- 技術スタック
- typescript
- 領域
- security
- issue の種類
- バグ
- 難易度
- 4/5
- 見積もり時間
- 3〜5日
- 活発さ
- 活発
- 明瞭さ
- 説明が足りない
- 初心者へのやさしさ
- 20/100