-
Notifications
You must be signed in to change notification settings - Fork 158
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
PRISMA-2022-0039 - High vulnerability #329
Comments
Why does the CVE ID say PRISMA-2022-0039? PRISMA-2022-0039 is not a valid CVE ID. Is there a valid CVE for this? |
4 tasks
2 tasks
ZainRizvi
added a commit
to pytorch/test-infra
that referenced
this issue
Nov 16, 2022
…dejs12 runtime (#1090) This PR contains two changes: 1. Fixes a security vuln with the minimatch package (identified by github). More details below 2. Upgrades the aws nodejs runtime past the now End-of-support nodejs12 runtime, which the tflint complained about after fixing the above security vuln # Package Dependency - Repository: [pytorch/test-infra](https://github.com/pytorch/test-infra) - Manifest file: [terraform-aws-github-runner/modules/webhook/lambdas/webhook/yarn.lock](https://github.com/pytorch/test-infra/blob/main/terraform-aws-github-runner/modules/webhook/lambdas/webhook/yarn.lock) - Package name: [minimatch](https://npmjs.com/package/minimatch) - Affected versions: < 3.0.5 - Fixed in version: 3.0.5 - Severity: HIGH # References https://nvd.nist.gov/vuln/detail/CVE-2022-3517 grafana/grafana-image-renderer#329 isaacs/minimatch@a8763f4 nodejs/node#42510 GHSA-f8q6-p94x-37v3
kit1980
pushed a commit
to pytorch/test-infra
that referenced
this issue
Nov 23, 2022
…dejs12 runtime (#1090) This PR contains two changes: 1. Fixes a security vuln with the minimatch package (identified by github). More details below 2. Upgrades the aws nodejs runtime past the now End-of-support nodejs12 runtime, which the tflint complained about after fixing the above security vuln # Package Dependency - Repository: [pytorch/test-infra](https://github.com/pytorch/test-infra) - Manifest file: [terraform-aws-github-runner/modules/webhook/lambdas/webhook/yarn.lock](https://github.com/pytorch/test-infra/blob/main/terraform-aws-github-runner/modules/webhook/lambdas/webhook/yarn.lock) - Package name: [minimatch](https://npmjs.com/package/minimatch) - Affected versions: < 3.0.5 - Fixed in version: 3.0.5 - Severity: HIGH # References https://nvd.nist.gov/vuln/detail/CVE-2022-3517 grafana/grafana-image-renderer#329 isaacs/minimatch@a8763f4 nodejs/node#42510 GHSA-f8q6-p94x-37v3
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
What happened: Vulnerability PRISMA-2022-0039 is found in scan.
What you expected to happen: Need to fix this security risk
How to reproduce it (as minimally and precisely as possible): Its coming in twistlock scan
Report details:
<style> </style>Anything else we need to know?: N/A
Environment: N/A
The text was updated successfully, but these errors were encountered: