-
Notifications
You must be signed in to change notification settings - Fork 3.2k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
CVE-2021-44906 found on trivy scan for minimist
dependency
#28209
Comments
Hey @eagle-txec, If relevant, check out our GitHub repo if you wish to learn more, or start using our app. Please feel free to reach us at [email protected] if you have any requests/questions. |
The issue exists with 13.7.3 as well |
To reproduce report, use for example: trivy image --ignore-unfixed --vuln-type library --severity CRITICAL cypress/included:13.11.0 |
From
|
We're open to PRs to fix this. We have no reason to believe this critical vulnerability has any actual exposure with the way Cypress is executed. |
minimist
dependency
Two of the vulnerabilities you listed have now been fixed. Current status for
|
@MikeMcC399 I don't see this version of |
-Since this issue is about |
#30546 will remove some old minimist versions, but not all |
Current behavior
Installed version is 0.0.8
Desired behavior
Upgrade fix version is 1.2.6
Test code to reproduce
Cypress Version
13.3.3
Node version
16.20.2
Operating System
Debug Logs
Other
No response
The text was updated successfully, but these errors were encountered: