Skip to content

Navigation Menu

Sign in
Appearance settings

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Sign up
Appearance settings

[Snyk] Fix for 1 vulnerabilities #1618

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Closed
ArduinoBot wants to merge 1 commit into main from snyk-fix-d2de148ecbca6f6e54017dc48039c45f

Conversation

@ArduinoBot
Copy link
Collaborator

@ArduinoBot ArduinoBot commented Nov 2, 2022

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to fix one or more vulnerable packages in the `yarn` dependencies of this project.

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • arduino-ide-extension/package.json
⚠️ Warning
Failed to update the yarn.lock, please update manually before merging.

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
critical severity 776/1000
Why? Recently disclosed, Has a fix available, CVSS 9.8
Improper Input Validation
SNYK-JS-SOCKETIOPARSER-3091012
No No Known Exploit

(*) Note that the real score may have changed since the PR was raised.

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Improper Input Validation

Copy link

CLA assistant check
Thank you for your submission! We really appreciate it. Like many open source projects, we ask that you sign our Contributor License Agreement before we can accept your contribution.
You have signed the CLA already but the status is still pending? Let us recheck it.

@per1234 per1234 added topic: infrastructure Related to project infrastructure topic: security Related to the protection of user data type: imperfection Perceived defect in any part of project labels Nov 2, 2022
Copy link
Contributor

Unfortunately, it's a useless auto-bump. 😕

@kittaakos kittaakos self-requested a review November 4, 2022 07:39
Copy link
Contributor

@kittaakos kittaakos left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

IDE2 cannot do much with the PR.

Problems:

  • The bot needs to sign the CLI. This is probably easy.
  • The auto PR is shiny and tip-top but does not solve anything:
    • First off, it creates a false public warning,
    • Theia dependencies must be updated together, so bumping one or two of them will break the dependency injection as the same module will be under the node_modules multiple times (this is how npm hoisting works),
    • The auto PR does not re-generate the yarn.lock file, so essentially, after a merge + pull cycle, all the devs will have an outgoing git change, and the new, partial Theia update will be indeterministic as the version is not pinned.

In summary, the way it works now does not solve anything but creates a false public warning on GH.

Closing as invalid. Feel free to reopen and take care of this PR if you disagree and want to handle the version update.

@kittaakos kittaakos added the conclusion: invalid Issue/PR not valid label Nov 4, 2022
@per1234 per1234 deleted the snyk-fix-d2de148ecbca6f6e54017dc48039c45f branch December 4, 2022 06:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Reviewers

1 more reviewer

@kittaakos kittaakos kittaakos left review comments

Reviewers whose approvals may not affect merge requirements

Assignees

No one assigned

Labels

conclusion: invalid Issue/PR not valid topic: infrastructure Related to project infrastructure topic: security Related to the protection of user data type: imperfection Perceived defect in any part of project

Projects

None yet

Milestone

No milestone

Development

Successfully merging this pull request may close these issues.

AltStyle によって変換されたページ (->オリジナル) /