PNPM - False positives for types packages. #6749
Closed
cristobal
started this conversation in
False Detection
Replies: 1 comment 2 replies
-
duplicate of #6509 |
Beta Was this translation helpful? Give feedback.
2 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
IDs
CVE-2021-44906, CVE-2022-0235, CVE-2022-46175
Description
The mentioned IDs above are reported as vulnerabilities for
@types/package-name
, when the pnpm package manager is used, this does not happen when default npm package manager is used.My suspicion is how the
pnpm-lock.yaml
is parsed for vulnerabilities rather than seeing the complete@types/package-name
it sees them aspackage-name
instead, i have a repo here that highlights this. The repo has the following@types
packages installed via pnpm,:@types/[email protected]
@types/[email protected]
@types/[email protected]
Running
trivy fs
scan yields the following false positive errors:Reproduction Steps
Target
Filesystem
Scanner
Vulnerability
Target OS
Mac OS, Ubuntu, Alpine
Debug Output
Version
Checklist
-f json
that shows data sources and confirmed that the security advisory in data sources was correctBeta Was this translation helpful? Give feedback.
All reactions