-
Notifications
You must be signed in to change notification settings - Fork 212
[dev] [Marfuen] mariano/trust-ff #1757
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Conversation
🔒 Comp AI - Security Review🟡 Risk Level: MEDIUMOSV: 3 npm CVEs found (xlsx@0.18.5: prototype pollution + ReDoS; ai@5.0.0: filetype whitelist bypass, fixed in 5.0.52). DomainVerificationDto lacks validation and has a restrictive domain regex. 📦 Dependency Vulnerabilities🟠 NPM Packages (HIGH)Risk Score: 8/10 | Summary: 2 high, 1 low CVEs found
🛡️ Code Security AnalysisView 1 file(s) with issues🟡 apps/api/src/trust-portal/dto/domain-status.dto.ts (MEDIUM Risk)
Recommendations:
💡 RecommendationsView 3 recommendation(s)
Powered by Comp AI - AI that handles compliance for you. Reviewed Nov 17, 2025 |
🔒 Comp AI - Security Review🟡 Risk Level: MEDIUMOSV scan found 2 high CVEs in xlsx@0.18.5 (GHSA-4r6h-8v6p-xvw6, GHSA-5pgg-2g8v-p4x9) and 1 low CVE in ai@5.0.0; code lacks DTO validation and unsafe orgId/pathname usage in main-menu. 📦 Dependency Vulnerabilities🟠 NPM Packages (HIGH)Risk Score: 8/10 | Summary: 2 high, 1 low CVEs found
🛡️ Code Security AnalysisView 2 file(s) with issues🟡 apps/api/src/trust-portal/dto/domain-status.dto.ts (MEDIUM Risk)
Recommendations:
🟡 apps/app/src/components/main-menu.tsx (MEDIUM Risk)
Recommendations:
💡 RecommendationsView 3 recommendation(s)
Powered by Comp AI - AI that handles compliance for you. Reviewed Nov 17, 2025 |
🔒 Comp AI - Security Review🟡 Risk Level: MEDIUMOSV scan: xlsx@0.18.5 has two HIGH issues (Prototype Pollution, ReDoS). ai@5.0.0 has a LOW filetype-whitelist bypass (fixed in 5.0.52). 📦 Dependency Vulnerabilities🟠 NPM Packages (HIGH)Risk Score: 8/10 | Summary: 2 high, 1 low CVEs found
🛡️ Code Security AnalysisView 1 file(s) with issues🟡 apps/api/src/trust-portal/dto/domain-status.dto.ts (MEDIUM Risk)
Recommendations:
💡 RecommendationsView 3 recommendation(s)
Powered by Comp AI - AI that handles compliance for you. Reviewed Nov 17, 2025 |
|
🎉 This PR is included in version 1.59.0 🎉 The release is available on GitHub release Your semantic-release bot 📦🚀 |
This is an automated pull request to merge mariano/trust-ff into dev.
It was created by the [Auto Pull Request] action.