Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Bug] Compodoc : zepto vulnerability #1416

Open
turbo-xav opened this issue Nov 30, 2023 · 0 comments
Open

[Bug] Compodoc : zepto vulnerability #1416

turbo-xav opened this issue Nov 30, 2023 · 0 comments
Assignees

Comments

@turbo-xav
Copy link

Hi,

My problem

Compodoc 1.1.23 pulls the lib zepto which is vulnerable to Cross-Site Scripting (XSS) attacks.

My company's IQ server reports the vulnerability and blocks my deployments

Sonatype

Ref : sonatype-2020-1437

Advisories link :https://securitylab.github.com/advisories/GHSL-2020-098-mxss-zepto

Iq recommandation : There is no non-vulnerable upgrade path for this component/package. We recommend investigating alternative components or a potential mitigating control.

My question is :

Is there a next version of compodoc planned without the lib zepto

Thanks

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

2 participants