Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Detected security vulnerabilities in underlying bootstrap dependency #228

Open
2 tasks done
acn-harryseong opened this issue Nov 6, 2024 · 1 comment
Open
2 tasks done
Labels
bug Something isn't working

Comments

@acn-harryseong
Copy link

Prerequisites

Describe the issue

React projects using @govtechsg/sgds-web-component latest version 2.1.2 were scanned and found to have the following 2 vulnerabilities related to the bootstrap dependency within the @govtechsg/sgds-web-component library:

  1. https://nvd.nist.gov/vuln/detail/CVE-2024-6531
  2. https://nvd.nist.gov/vuln/detail/CVE-2024-6484

According to SonaType NexusIQ, there is no non-vulnerable upgrade path currently, but this is an FYI in case there is an upgrade path to mitigate these detected vulnerabilities in the future for the underlying bootstrap dependency.

What operating system(s) are you seeing the problem on?

Windows

What browser(s) are you seeing the problem on?

Chrome

Describe your frontend stack. What version of React and @govtechsg/sgds-web-component are you using? CSR or SSR?

React 18.3.x, @govtechsg/sgds-web-component 2.1.2, CSR

@acn-harryseong acn-harryseong added the bug Something isn't working label Nov 6, 2024
@acn-harryseong acn-harryseong changed the title Provide a general summary of the issue Detected security vulnerabilities in underlying bootstrap dependency Nov 6, 2024
@clukhei
Copy link
Collaborator

clukhei commented Dec 13, 2024

@acn-harryseong We are currently using Snyk to detect vulnerabilities and it does not report any vulnerabilities for bootstrap version 5.1.3 that we are using. Did the SonaType NexusIQ specify the version of bootstrap that had 2 vulnerabilites? https://security.snyk.io/package/npm/bootstrap

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Something isn't working
Projects
None yet
Development

No branches or pull requests

2 participants