You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
If I build a simple synthetic monitoring check and push it to artifact registry with vulnerability scanning enabled, I receive a vulnerability report for a CVE from 2019:
Hi,
If I build a simple synthetic monitoring check and push it to artifact registry with vulnerability scanning enabled, I receive a vulnerability report for a CVE from 2019:
GHSA-mxhp-79qh-mcx6
Once the sdk-api package is introduced, the taffydb vulnerability appears:
Here are the details of the vulnerability:
As you can see, the vulnerability is introduced by ts-proto-descriptors. A more recent version of this package does not contain the vulnerability.
This issue has also been confirmed by Google Support in the Case 58708898
The text was updated successfully, but these errors were encountered: