Skip to content

test! deliberately introduce vuln by installing axios - #1152

Open
bikubi wants to merge 3 commits into
mainfrom
testing-trivy-introduce-vuln-do-not-merge
Open

test! deliberately introduce vuln by installing axios#1152
bikubi wants to merge 3 commits into
mainfrom
testing-trivy-introduce-vuln-do-not-merge

Conversation

@bikubi

@bikubi bikubi commented May 11, 2026

Copy link
Copy Markdown
Contributor

this is a TEST to see how a trivy vuln looks like, cf.

https://github.com/aula-app/infra/issues/4#issuecomment-4420234144

do not merge!

Comment thread yarn.lock Fixed
Comment thread yarn.lock Fixed
Comment thread yarn.lock Fixed
Comment thread yarn.lock Fixed
Comment thread yarn.lock Fixed
Comment thread yarn.lock Fixed
Comment thread yarn.lock Fixed
Comment thread yarn.lock Fixed
Comment thread yarn.lock Fixed
Comment thread yarn.lock Fixed
bikubi added 2 commits May 11, 2026 16:07
former test with axios was too Bad, broke yarn install, trivy didn't even run
Comment thread yarn.lock Dismissed
@bikubi

bikubi commented May 11, 2026

Copy link
Copy Markdown
Contributor Author

ping @nikola-maric-aula so this is what a PR with a newly introduced high severity would look like atm.

(please disregard the axios stuff above, that was too explosive :P )

see also https://github.com/aula-app/aula-frontend/security/code-scanning?query=is%3Aopen+pr%3A1152 where the svgo vuln shows up as #19, opened N minutes ago · Detected by Trivy (cf. #2 opened last week)

@bikubi

bikubi commented May 11, 2026

Copy link
Copy Markdown
Contributor Author

trashing my secret github reputation by introducing the dumbest vulns possible...

@nikola-maric-aula

Copy link
Copy Markdown
Contributor

trashing my secret github reputation by introducing the dumbest vulns possible...

^^

see also https://github.com/aula-app/aula-frontend/security/code-scanning?query=is%3Aopen+pr%3A1152 where the svgo vuln shows up as #19, opened N minutes ago · Detected by Trivy (cf. #2 opened last week)

i made FE only allow merging PRs that pass the Trivy check, although I set the threshold "Critical" and this PR is blocked even with its "High" severity:
image

we can talk more about it tomorrow..

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants