[Snyk] Security upgrade onfido-sdk-ui from 13.6.1 to 14.15.0 #24
DryRunSecurity / Sensitive Files Analyzer
succeeded
Sep 17, 2024 in 1s
DryRun Security
Details
Sensitive Files Analyzer Findings: 2 detected
⚠️ Potential Sensitive File package-lock.json (click for details)
Type | Potential Sensitive File |
Description | Node.js/ExpressJS/Next.js applications manage their dependencies through package.json and package-lock.json files. A change in these files may indicate an addition of a library/dependency which could introduce additional risk to the application either through vulnerable code, expansion of the application's attack surface via additional routes, or malicious code. |
Filename | package-lock.json |
CodeLink | https://github.com/be4solutions/App/blob/304e5d36901c3ad9a5abcfb756986cb80d59ee0f/package-lock.json#L63-L69 |
⚠️ Potential Sensitive File package.json (click for details)
Type | Potential Sensitive File |
Description | Node.js/ExpressJS/Next.js applications manage their dependencies through package.json and package-lock.json files. A change in these files may indicate an addition of a library/dependency which could introduce additional risk to the application either through vulnerable code, expansion of the application's attack surface via additional routes, or malicious code. |
Filename | package.json |
CodeLink | Lines 111 to 117 in 304e5d3 |
Loading