Skip to content

chore: verify spec-renderer preview for sanitization - #261

Closed
vaibhavrajsingh2001 wants to merge 1 commit into
mainfrom
chore/test-overview-sanitization
Closed

chore: verify spec-renderer preview for sanitization#261
vaibhavrajsingh2001 wants to merge 1 commit into
mainfrom
chore/test-overview-sanitization

Conversation

@vaibhavrajsingh2001

Copy link
Copy Markdown
Collaborator

@netlify

netlify Bot commented Jul 31, 2026

Copy link
Copy Markdown

Deploy Preview for kong-spec-editor ready!

Name Link
🔨 Latest commit 13acdc5
🔍 Latest deploy log https://app.netlify.com/projects/kong-spec-editor/deploys/6a6cbb39fe228c00085681c3
😎 Deploy Preview https://deploy-preview-261--kong-spec-editor.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.
🤖 Make changes Run an agent on this branch

To edit notification comments on pull requests, go to your Netlify project configuration.

@kongponents-bot

Copy link
Copy Markdown
Collaborator

🔴 PR audit failed. 🔴

🔥 Renovate Security PRs detected.

There are 5 open renovate security PRs older than 3 days.

This PR cannot be merged until all renovate security PRs created more than 3 days ago are resolved.

🔥 PNPM Audit issues detected.

┌─────────────────────┬────────────────────────────────────────────────────────┐
│ high                │ brace-expansion: DoS via exponential-time expansion of │
│                     │ consecutive non-expanding {} groups                    │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Package             │ brace-expansion                                        │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Vulnerable versions │ <1.1.16                                                │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Patched versions    │ >=1.1.16                                               │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Paths               │ .>eslint>minimatch>brace-expansion                     │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ More info           │ https://github.com/advisories/GHSA-3jxr-9vmj-r5cp      │
└─────────────────────┴────────────────────────────────────────────────────────┘
┌─────────────────────┬────────────────────────────────────────────────────────┐
│ high                │ brace-expansion: DoS via exponential-time expansion of │
│                     │ consecutive non-expanding {} groups                    │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Package             │ brace-expansion                                        │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Vulnerable versions │ >=3.0.0 <5.0.7                                         │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Patched versions    │ >=5.0.7                                                │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Paths               │ .>@kong/eslint-config-kong-ui>typescript-              │
│                     │ eslint>@typescript-eslint/typescript-                  │
│                     │ estree>minimatch>brace-expansion                       │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ More info           │ https://github.com/advisories/GHSA-3jxr-9vmj-r5cp      │
└─────────────────────┴────────────────────────────────────────────────────────┘
┌─────────────────────┬────────────────────────────────────────────────────────┐
│ high                │ js-yaml: YAML merge-key chains can force quadratic CPU │
│                     │ consumption                                            │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Package             │ js-yaml                                                │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Vulnerable versions │ >=4.0.0 <4.3.0                                         │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Patched versions    │ >=4.3.0                                                │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Paths               │ .>@commitlint/cli>@commitlint/load>cosmiconfig>js-yaml │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ More info           │ https://github.com/advisories/GHSA-52cp-r559-cp3m      │
└─────────────────────┴────────────────────────────────────────────────────────┘
┌─────────────────────┬────────────────────────────────────────────────────────┐
│ high                │ shell-quote: Quadratic-complexity Denial of Service in │
│                     │ `parse()` (CWE-407)                                    │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Package             │ shell-quote                                            │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Vulnerable versions │ <=1.8.4                                                │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Patched versions    │ >=1.9.0                                                │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Paths               │ .>npm-run-all2>shell-quote                             │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ More info           │ https://github.com/advisories/GHSA-395f-4hp3-45gv      │
└─────────────────────┴────────────────────────────────────────────────────────┘
┌─────────────────────┬────────────────────────────────────────────────────────┐
│ high                │ Immutable.js `List` 32-bit trie overflow →             │
│                     │ unrecoverable DoS                                      │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Package             │ immutable                                              │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Vulnerable versions │ >=5.0.0-beta.1 <5.1.8                                  │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Patched versions    │ >=5.1.8                                                │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Paths               │ .>sass>immutable                                       │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ More info           │ https://github.com/advisories/GHSA-v56q-mh7h-f735      │
└─────────────────────┴────────────────────────────────────────────────────────┘
┌─────────────────────┬────────────────────────────────────────────────────────┐
│ high                │ Immutabl: Hash-collision algorithmic complexity denial │
│                     │ of service in Immutable.Map/Set                        │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Package             │ immutable                                              │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Vulnerable versions │ >=5.0.0-beta.1 <5.1.8                                  │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Patched versions    │ >=5.1.8                                                │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Paths               │ .>sass>immutable                                       │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ More info           │ https://github.com/advisories/GHSA-xvcm-6775-5m9r      │
└─────────────────────┴────────────────────────────────────────────────────────┘
┌─────────────────────┬────────────────────────────────────────────────────────┐
│ high                │ fast-uri vulnerable to host confusion via literal      │
│                     │ backslash authority delimiter                          │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Package             │ fast-uri                                               │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Vulnerable versions │ >=4.0.0 <=4.1.0                                        │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Patched versions    │ >=4.1.1                                                │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Paths               │ .>@commitlint/cli>@commitlint/load>@commitlint/config- │
│                     │ validator>ajv>fast-uri                                 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ More info           │ https://github.com/advisories/GHSA-v2hh-gcrm-f6hx      │
└─────────────────────┴────────────────────────────────────────────────────────┘
┌─────────────────────┬────────────────────────────────────────────────────────┐
│ high                │ PostCSS: Arbitrary file read and information           │
│                     │ disclosure via attacker-controlled sourceMappingURL in │
│                     │ CSS comments                                           │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Package             │ postcss                                                │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Vulnerable versions │ <=8.5.11                                               │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Patched versions    │ >=8.5.12                                               │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Paths               │ .>@stylistic/stylelint-plugin>postcss                  │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ More info           │ https://github.com/advisories/GHSA-6g55-p6wh-862q      │
└─────────────────────┴────────────────────────────────────────────────────────┘
┌─────────────────────┬────────────────────────────────────────────────────────┐
│ high                │ PostCSS: Path Traversal in Previous Source Map         │
│                     │ Auto-Loading (sourceMappingURL) leads to Arbitrary     │
│                     │ .map File Disclosure                                   │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Package             │ postcss                                                │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Vulnerable versions │ <=8.5.17                                               │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Patched versions    │ >=8.5.18                                               │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Paths               │ .>@stylistic/stylelint-plugin>postcss                  │
│                     │                                                        │
│                     │ .>stylelint>postcss                                    │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ More info           │ https://github.com/advisories/GHSA-r28c-9q8g-f849      │
└─────────────────────┴────────────────────────────────────────────────────────┘
┌─────────────────────┬────────────────────────────────────────────────────────┐
│ high                │ brace-expansion: DoS via unbounded expansion length    │
│                     │ causing an out-of-memory process crash                 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Package             │ brace-expansion                                        │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Vulnerable versions │ <=5.0.7                                                │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Patched versions    │ >=5.0.8                                                │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Paths               │ .>@kong/eslint-config-kong-ui>typescript-              │
│                     │ eslint>@typescript-eslint/typescript-                  │
│                     │ estree>minimatch>brace-expansion                       │
│                     │                                                        │
│                     │ .>eslint>minimatch>brace-expansion                     │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ More info           │ https://github.com/advisories/GHSA-mh99-v99m-4gvg      │
└─────────────────────┴────────────────────────────────────────────────────────┘
┌─────────────────────┬────────────────────────────────────────────────────────┐
│ high                │ fast-uri vulnerable to host confusion via failed IDN   │
│                     │ canonicalization                                       │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Package             │ fast-uri                                               │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Vulnerable versions │ >=4.0.0 <4.0.1                                         │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Patched versions    │ >=4.0.1                                                │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Paths               │ .>@commitlint/cli>@commitlint/load>@commitlint/config- │
│                     │ validator>ajv>fast-uri                                 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ More info           │ https://github.com/advisories/GHSA-4c8g-83qw-93j6      │
└─────────────────────┴────────────────────────────────────────────────────────┘
11 vulnerabilities found
Severity: 11 high

PR with those issues cannot be merged.

How to resolve:

  • Check open renovate PRs for updates to the dependencies mentioned in the audit report
  • try to update dependencies listed in the audit report to the latest versions
  • use pnpm audit --fix to automatically fix issues

🔥 PR preview packages detected .


PR preview package version found in ./package.json:
    "@kong/spec-renderer": "1.110.1-pr.937.cc71c67.0",

PR with those dependencies cannot be merged.

🔥 Old Open Renovate PRs detected.

There are 9 open renovate PRs created more than 30 days ago. PR cannot be merged until those old open renovate PRs are resolved.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants