patternfly / patternfly/patternfly-org

Bug - address vulnerabilities in documentation-framework

Open
#3,794 1 comment 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

  • #4079 by @nicolethoen — closed without merging
PF Team
Dominant language
JavaScript
Stars
74
Forks
147
Avg merge
4d 11h
Merged PRs (30d)
2

Description

From documentation-framework/package.json

critical:

Introduced through: sharp@0.30.6
Fixed in: sharp@0.32.6

High:

Introduced through: @patternfly/documentation-framework@5.3.0 › remark-parse@8.0.3 › trim@0.0.1
Fix: Upgrade to remark-parse@9.0.0

Introduced through: codesandbox@2.2.0
Fixed in: axios@1.6.0

Introduced through: codesandbox@2.2.0
Fixed in: ansi-regex@3.0.1, @4.1.1, @5.0.1, @6.0.1

Introduced through: @babel/core@7.18.2, @babel/preset-env@7.18.2 and others
Fixed in: semver@5.7.2, @6.3.1, @7.5.2

Introduced through: codesandbox@2.2.0
Fixed in: ssri@6.0.2, @7.1.1, @8.0.1

https://app.snyk.io/org/patternfly/project/95e300e5-89ce-41ad-9f3b-93d6d8f065ef


Jira Issue: PF-1838

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start with documentation-framework/package.json and the listed Snyk findings, then inspect linked pull request #4079 for prior context. Verify that each reported vulnerability is addressed with the stated fixed versions, and run the repository’s available dependency audit or tests; done means the listed vulnerabilities no longer apply.

Written by the indexing model from the issue text.

Assessment

Tech stack
javascript
Domain
documentation, security
Issue type
Bug
Difficulty
3/5
Estimated time
1-2 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.