Security Vulnerabilities Detected in package-lock.json (npm) via Trivy Scan

Created on 9 January 2025, 6 months ago

A Trivy scan of the package-lock.json file for the Media Library Form API Element module has identified a total of 85 security vulnerabilities. These include 64 vulnerabilities of HIGH severity and 21 vulnerabilities of CRITICAL severity. These vulnerabilities pose significant security risks and must be addressed promptly to safeguard the application.

Vulnerability Breakdown:

Total vulnerabilities found: 85
High severity: 64
Critical severity: 21

πŸ’¬ Support request
Status

Active

Version

2.1

Component

Code

Created by

Live updates comments and jobs are added and updated live.
Sign in to follow issues

Merge Requests

Comments & Activities

  • Issue created by @a.err
  • πŸ‡ΊπŸ‡ΈUnited States mark_fullmer Tucson

    I don't think this needs to be marked as critical, since these packages are not part of the distributed Drupal module; they are internal build tools only. Setting priority to "Normal."

  • πŸ‡ΊπŸ‡ΈUnited States mark_fullmer Tucson
  • Merge request !22Remove build directory β†’ (Merged) created by mark_fullmer
  • πŸ‡ΊπŸ‡ΈUnited States mark_fullmer Tucson

    Reviewing the use of the Gulp build process in this module and the resulting output, I conclude that it does so little that it is more of a liability to keep the build process in the codebase than it is an asset: there is a a fair amount of boilerplate code for SCSS that doesn't exist, and the JS is only very slightly modified. I propose that we work directly from the relatively small JS file in /assets.

    If others in the community feel strongly that the build process should continue to be used, it can be reverted -- I'm not strictly opposed to that, but I will proceed to do the removal here in the absence of other strong opinions. Thanks!

  • Pipeline finished with Skipped
    8 days ago
    #541260
  • Pipeline finished with Skipped
    8 days ago
    #541261
  • πŸ‡ΊπŸ‡ΈUnited States mark_fullmer Tucson
Production build 0.71.5 2024