-
Notifications
You must be signed in to change notification settings - Fork 78
Moderate Vulnerability in sonarqube-scanner > download > got #140
Comments
Same issue here.
|
+1 please fix |
+1 confirm |
I'm getting the same issue. |
+1 affecting our applications |
+1 |
As OP @dtomasbar mentioned, the latest version of the The open issue to upgrade that dependency is here, but likely won't be acted on with that package lacking any active maintainers. If Sonar has funding for its offerings, I'd recommend picking from this list:
Having a persistent transitive vulnerability in a product aimed at organizations who are especially picky about eliminating potential issues from their code base is not a good look. |
+1 we have the same issues on all our apps +10 |
+1 |
This was fixed with 2.8.2 release, see: |
While installing sonarqube-scanner npm reveled the following vulnerability:
Reviewing download issues they haven't yet patched their package, but already have and open issue.
However, sonnarqube-scanner is not using the latest version of download library (v8.0.0) so it may be worth it to check compatibility with the current version of downalod to ensure that there are no issues
The text was updated successfully, but these errors were encountered: