You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
How as this closed?
The latest version is vulnerable. mfncooper/mockery appears to be an unmaintained package that hasn't been updated since 2017 or closed pull requests since 2018. The code is fairly short.
Perhaps this repo should copy it or import a different package.
The Security team of one of our customers is reporting this vulnerability to us and are demanding to provide a fix for it. Is the a work around to remove this mockery library somehow?
Please check our current Issues to see if someone already reported this https://github.com/Microsoft/azure-pipelines-task-lib/issues
Environment
azure-pipelines-task-lib version: 3.3.1
Issue Description
There is a prototype pollution bug in mockery, a prod dependency
package.json here
Steps to reproduce
Run Component Governance on the pipeline
Logs
n/a
The text was updated successfully, but these errors were encountered: