Skip to content

Conversation

@cx-anurag-dalke
Copy link
Collaborator

No description provided.

@cx-anurag-dalke cx-anurag-dalke changed the title Fix test cases Fix test cases (AST-0000) Oct 16, 2025
@cx-ben-alvo
Copy link
Collaborator

cx-ben-alvo commented Oct 16, 2025

Logo
Checkmarx One – Scan Summary & Details366a5c46-031a-44ee-b51f-7f59c8663bd8

New Issues (2)

Checkmarx found the following issues in this Pull Request

Severity Issue Source File / Package Checkmarx Insight
HIGH CVE-2025-59343 Npm-tar-fs-2.1.2
detailsRecommended version: 2.1.4
Description: tar-fs provides filesystem bindings for tar-stream. Versions prior to 3.1.1, 2.1.4, and 1.16.6 are vulnerable to symlink validation bypass if the d...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: Bdno21EY1m%2BN0RdYjLCXSOsHcZlP5k4WdIykWtas31c%3D
Vulnerable Package
HIGH CVE-2025-59343 Npm-tar-fs-1.16.4
detailsRecommended version: 1.16.6
Description: tar-fs provides filesystem bindings for tar-stream. Versions prior to 3.1.1, 2.1.4, and 1.16.6 are vulnerable to symlink validation bypass if the d...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: MGet1CuBfT3lrthRVOvL7f42T%2Fb4%2FARWTqjmLZyXQRE%3D
Vulnerable Package
Policy Management Violations (1)
Policy Name: Phoenix-Policy The following violations of your team's AppSec policy rules were identified in this project. Since 'Break Build' is enabled for these rules, you must resolve these issues before the Pull Request can be merged.
  • Rule Name: New vulnerabilities of High, Medium and Low severity levels detected
    Scanner: SAST,SCA,IaC-Security

Use @Checkmarx to reach out to us for assistance.

Just send a PR comment with @Checkmarx followed by a natural language request.

Examples: @Checkmarx how are you able to help me? @Checkmarx rescan this PR

@cx-anurag-dalke cx-anurag-dalke merged commit c2ba86d into main Oct 16, 2025
4 of 5 checks passed
@cx-anurag-dalke cx-anurag-dalke deleted the other/fixtestCases branch October 16, 2025 06:57
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants