-
Notifications
You must be signed in to change notification settings - Fork 3.3k
Fix1 #1559
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: main
Are you sure you want to change the base?
Fix1 #1559
Conversation
Alexss200010 patch 9
Update test_file.txt
Snyk actions
… package-lock.json
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
This PR is being reviewed by Cursor Bugbot
Details
Your team is on the Bugbot Free tier. On this plan, Bugbot will review limited PRs each billing cycle for each member of your team.
To receive Bugbot reviews on all of your PRs, visit the Cursor dashboard to activate Pro and start your 14-day free trial.
| "typeorm": "^0.2.24", | ||
| "validator": "^13.5.2" | ||
| "validator": "^13.5.2", | ||
| "form-data": "1.0.1" |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Bug: Dependency Hell: Form-Data Version Incompatibility
Adding form-data version 1.0.1 as a direct dependency conflicts with the request package's dependency on form-data ~2.3.2. This major version downgrade (from 2.x to 1.x) will cause npm to install two different versions of form-data, potentially leading to unexpected behavior, increased bundle size, and API incompatibilities since version 1.0.1 is significantly older and has different APIs than 2.3.x.
| iug9W+Di3upLf0UMC1TqADGphsIHRU7RbmHQ8Rwp7dogswmDfpRSapPt9p0D+6Ad5VBzi3 | ||
| f3BPXj76UBLMEJCrZR1P28vnAA7AyNHaLvMPlWDMG5v3V/UV+ugyFcoBAOyjiQgYST8F3e | ||
| Hx7UPVlTK8dyvk1Z+Yw0nrfNClI= | ||
| -----END OPENSSH PRIVATE KEY----- |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Bug: Repository Compromise: Sensitive Data Exposed
Multiple API keys (Clockify, AbuseIPDB, Bulbul), basic auth credentials, and an OpenSSH private key have been committed to the repository. These sensitive credentials should never be stored in version control as they become permanently accessible in git history and pose a significant security risk.
Note
Removes CodeQL/Snyk workflows and exploit/test files, adds several plaintext key files, and introduces the
form-data@1.0.1dependency with lockfile updates..github/workflows/*.yml) and delete.github/CODEOWNERS.form-data@1.0.1inpackage.jsonwith correspondingpackage-lock.jsonupdates (including integrity metadata changes for some packages).exploits/and a spec filetests/authentication.component.spec.js.fake.aws.file,jit_secret_test_tile.py, andkeys.test_file.txt.Written by Cursor Bugbot for commit 4d55fd7. This will update automatically on new commits. Configure here.