Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Snyk] Security upgrade @openfga/sdk from 0.7.0 to 0.8.0 #931

Merged
merged 1 commit into from
Jan 15, 2025

Conversation

poovamraj
Copy link
Contributor

snyk-top-banner

Snyk has created this PR to fix 1 vulnerabilities in the npm dependencies of this project.

Snyk changed the following file(s):

  • package.json
  • package-lock.json

Vulnerabilities that will be fixed with an upgrade:

Issue Score
medium severity Cross-site Scripting (XSS)
SNYK-JS-AXIOS-6671926
  75  

Important

  • Check the changes in this PR to ensure they won't cause issues with your project.
  • Max score is 1000. Note that the real score may have changed since the PR was raised.
  • This PR was automatically created by Snyk using the credentials of a real user.

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report
📜 Customise PR templates
🛠 Adjust project settings
📚 Read about Snyk's upgrade logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Cross-site Scripting (XSS)

@poovamraj poovamraj requested review from a team as code owners January 15, 2025 07:18
Copy link
Contributor

Minder Vulnerability Report ✅

Minder analyzed this PR and found it does not add any new vulnerable dependencies.

Vulnerability scan of 68038105:

  • 🐞 vulnerable packages: 0
  • 🛠 fixes available for: 0

Copy link
Contributor

Dependency Information

Minder analyzed the dependencies introduced in this pull request and detected that some dependencies do not meet your security profile.

📦 Dependency: @openfga/sdk

Trusty Score: 0

📦 Dependency: axios

Trusty Score: 0

Scoring details
Component Score
Package activity 9
Repository activity 9.7
User activity 8.2
Provenance verified_provenance_match
Proof of Origin (Provenance)

This package can be linked back to its source code using a historical provenance map.

We were able to correlate a significant number of git tags and tagged releases in this package’s source code to versions of the published package. This mapping creates a strong link from the package back to its source code repository, verifying proof of origin.

Published package versions 107
Number of git tags or releases 150
Versions matched to tags or releases 80

This package has been digitally signed using sigtore.

Source repository https://github.com/axios/axios
Cerificate Issuer CN=sigstore-intermediate,O=sigstore.dev
GitHub action workflow .github/workflows/publish.yml
Rekor (public ledger) entry https://search.sigstore.dev/?logIndex=153252145
Alternatives
Package Score Description
got 0
http 0
fetch 0

Copy link
Contributor

github-actions bot commented Jan 15, 2025

PR Preview Action v1.4.8
Preview removed because the pull request was closed.
2025-01-15 14:20 UTC

@ewanharris ewanharris merged commit c144f0b into main Jan 15, 2025
12 checks passed
@ewanharris ewanharris deleted the snyk-fix-c9b5d1f0cef88f174579fe5d32039142 branch January 15, 2025 14:18
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants