Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Dependency confusion supply-chain vulnerability detected #271

Open
ashishbijlani opened this issue Aug 4, 2023 · 0 comments
Open

Dependency confusion supply-chain vulnerability detected #271

ashishbijlani opened this issue Aug 4, 2023 · 0 comments

Comments

@ashishbijlani
Copy link

Hi,

I'm a Cybersecurity researcher developing PackjGuard [1]. Our tool has detected a dependency confusion vulnerability in this repository.

The package @getnova/components mentioned in the README at line 19 does not exist on public NPM registry. A bad actor can hijack this package to propagate malicious code.

Not only your apps/service is vulnerable to this attack, but the users of your open-source Github repo are also vulnerable to this attack.

Please register a placeholder package for @getnova/components on public NPM soon to remediate.

Thanks!

  1. PackjGuard is a Github app that monitors repos for malicious/vulnerable dependencies and mitigates attacks by creating pull requests for automatic remediation https://github.com/marketplace/packjguard
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Development

No branches or pull requests

1 participant