Summary
Tracking issue for the open GitHub security alerts on this repository. This covers both:
As of triage there are 17 open Dependabot alerts and 1 open code scanning alert. Items are grouped so that alerts fixable by a single dependency bump / PR share one checkbox, with the individual alerts bulleted underneath. Resolve each by upgrading the affected dependency (or applying a fix), or dismiss with a rationale if it doesn't apply to how the Inspector uses it.
Code scanning
Dependabot
Counts and links captured at time of filing; check the Security tab for the current live state.
Summary
Tracking issue for the open GitHub security alerts on this repository. This covers both:
As of triage there are 17 open Dependabot alerts and 1 open code scanning alert. Items are grouped so that alerts fixable by a single dependency bump / PR share one checkbox, with the individual alerts bulleted underneath. Resolve each by upgrading the affected dependency (or applying a fix), or dismiss with a rationale if it doesn't apply to how the Inspector uses it.
Code scanning
server/src/index.tsjs/request-forgery— Server-side request forgeryDependabot
honoupgrade (High + Medium)origindefaults to wildcardContent-Lengthserve-staticon Windows via encoded backslash (%5C)Set-Cookieheaders, dropping cookiesminimatchupgrade (High)matchOne()combinatorial backtracking via non-adjacent GLOBSTAR segments*()extglobs generate catastrophically backtracking regexesviteupgrade (High + Medium)server.fs.denybypass on Windows alternate pathslaunch-editor(transitive): NTLMv2 hash disclosure via UNC path handling on Windowsjs-yamlupgrade (Medium)shell-quoteupgrade (Critical)quote()does not escape newlines in object.opvaluesvitestupgrade (Critical)form-dataupgrade (High)@babel/coreupgrade (Low)sourceMappingURLcommentesbuildupgrade (Low)Counts and links captured at time of filing; check the Security tab for the current live state.