Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Vulnerabilities in included mocha.js #246

Open
Niedzwiedz opened this issue Nov 28, 2022 · 1 comment
Open

Vulnerabilities in included mocha.js #246

Niedzwiedz opened this issue Nov 28, 2022 · 1 comment

Comments

@Niedzwiedz
Copy link

Hello,

Rack-cors gem comes packaged with test_files that includes mocha.js which is interpreted by our scans as version 1.11.0

Our product security analysis is "flashing red" and flagging those:
https://www.huntr.dev/bounties/1d8a3d95-d199-4129-a6ad-8eafe5e77b9e/
mochajs/mocha#4770

I was following this issue discussion on rubygems: rubygems/rubygems#735
which isn't really conclusive but many gem repos removed test_files
and I wonder what's your opinion on keeping/removing test_files part of gemspec?

Thanks,
Michal

@squadette
Copy link

If your product is flagging a javascript file in test suite as "flashing red" then how would it flag the actual vulnerabilities?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants