Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Snyk] Snyk check for week of 12/9/24 #172

Closed
exalate-issue-sync bot opened this issue Dec 9, 2024 · 4 comments
Closed

[Snyk] Snyk check for week of 12/9/24 #172

exalate-issue-sync bot opened this issue Dec 9, 2024 · 4 comments
Assignees

Comments

@exalate-issue-sync
Copy link

exalate-issue-sync bot commented Dec 9, 2024

Snyk check:

Per the snyk spreadsheet (https://docs.google.com/spreadsheets/d/1SNMOyGS4JAKgXQ0RhhzoX7M2ib1vm14dD0LxWNpssP4/edit?gid=0#gid=0 ) check snyk alerts for all projects and create tickets to address ALL alerts.

Steps to create tickets for alerts:

https://github.com/fecgov/fecfile-web-api?tab=readme-ov-file#snyk-security-scanning

QA Notes

null

DEV Notes

null

Design

null

See full ticket and images here: FECFILE-1884

Pull Request: https://www.github.com/

@exalate-issue-sync exalate-issue-sync bot changed the title [Snyk] Snyk check for week of [Snyk] Snyk check for week of 12/9/24 Dec 9, 2024
Copy link
Author

Elaine Krauss commented: This week’s Snyk review has shown two API-side vulnerabilities, one critical and one high. Both of these are fixed by upgrading the same package, so I’ve created one new ticket to resolve them, and I’ve linked that to this ticket.

Copy link
Author

Todd Lees commented: tickets created. no code changes

Copy link
Author

Shelly Wise commented: QA review not needed for this ticket. No code changes per DEV.

Moved to Stage Ready.

Copy link
Author

Automation for Jira commented: Sprint accepted by Paul Clark during DSU on 1/15/2025 after verification of FECFILE-1770.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant