Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

feat: add shim to target Vonage APIs #254

Merged
merged 8 commits into from
Nov 14, 2024

Merge branch 'main' into shim

25c956f
Select commit
Loading
Failed to load commit list.
Merged

feat: add shim to target Vonage APIs #254

Merge branch 'main' into shim
25c956f
Select commit
Loading
Failed to load commit list.
Mend for GitHub.com / WhiteSource Security Check failed Nov 14, 2024 in 7m 14s

Security Report

❗️Scan Warnings: The scan completed with warnings. The integration encountered issues with one or more projects in this repository. Consequently, there may be gaps in the coverage of open-source dependencies used in the repository.

Scan Details Report

general

https://vonagecc.jfrog.io/artifactory

Step Level Description Details
Checking registry connectivity ⚠Warn Unsupported configuration was provided unsupported host type gradle, skipped

You have successfully remediated 1 vulnerabilities, but introduced 1 new vulnerabilities in this branch.

❌ New vulnerabilities:
CVE Severity CVSS Score Exploit Maturity EPSS Vulnerable Library Suggested Fix Issue Reachability
CVE-2024-43485

Path to dependency file: /OpenTokTest/OpenTokTest.csproj

Path to vulnerable library: /home/wss-scanner/.nuget/packages/system.text.json/8.0.4/system.text.json.8.0.4.nupkg,/home/wss-scanner/.nuget/packages/system.text.json/8.0.4/system.text.json.8.0.4.nupkg

Dependency Hierarchy:

-> opentok.3.14.0.nupkg (Root Library)

   -> jwt.10.1.0.nupkg

     -> ❌ system.text.json.8.0.4.nupkg (Vulnerable Library)

High 7.5 Unproven 0.1% system.text.json.8.0.4.nupkg Upgrade to version: System.Text.Json - 6.0.10,8.0.5 #251

✔️ Remediated vulnerabilities:

CVE Vulnerable Library
CVE-2024-43485 system.text.json.6.0.7.nupkg

Base branch total remaining vulnerabilities: 2
Base branch commit: 0e991a2c5b649da7c9f9347ca863f574593f83e9


Total libraries scanned: 191

Scan token: 02f1b871d19742b6ae5c9ce14f212959