Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Investigate dependabot security alert #8 - tough cookie #187

Closed
edhamiltonHO opened this issue Jul 14, 2023 · 8 comments
Closed

Investigate dependabot security alert #8 - tough cookie #187

edhamiltonHO opened this issue Jul 14, 2023 · 8 comments
Assignees
Labels
dependencies Pull requests that update a dependency file

Comments

@edhamiltonHO
Copy link
Contributor

No description provided.

@edhamiltonHO edhamiltonHO added the dependencies Pull requests that update a dependency file label Jul 14, 2023
@keithkennedyHO keithkennedyHO self-assigned this Jul 21, 2023
@keithkennedyHO
Copy link
Contributor

@edhamiltonHO it appears this is being looked at upstream, there is an open issue for this. My suggestion would to wait until resolved.

@edhamiltonHO
Copy link
Contributor Author

OK, do we have a view on the risk this presents to us?

I'd presume fairly low as related to cookies, which we aren't using, but would be good to be clear

@robertdeniszczyc2
Copy link
Contributor

This looks to have been resolved in a release of cypress/request last week: https://github.com/cypress-io/request/releases/tag/v2.88.12

@keithkennedyHO
Copy link
Contributor

@robertdeniszczyc2 Unfortunately, this is for the cypress/request package and not the main cypress (https://github.com/cypress-io/cypress/releases), which has not yet been updated with the fix.

@keithkennedyHO
Copy link
Contributor

@robertdeniszczyc2 I misread that, apologies. Yes, hopefully the fix above suggests a fix for the cypress package will come soon to resolve this.

@robertdeniszczyc2
Copy link
Contributor

Looks like there are two open PRs on Cypress for this:

cypress-io/cypress#27439

cypress-io/cypress#27493

@robertdeniszczyc2
Copy link
Contributor

A fix has been merged under cypress-io/cypress#27515, hopefully will be included in the next release

@robertdeniszczyc2
Copy link
Contributor

According to the thread the change was merged to Cypress in 12.17.4, from https://github.com/HO-CTO/engineering-guidance-and-standards/pull/248 we are now on 13.x so I think this can be closed

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies Pull requests that update a dependency file
Projects
None yet
Development

No branches or pull requests

3 participants