test! deliberately introduce vuln by installing axios - #1152
Conversation
This reverts commit ccbf845.
former test with axios was too Bad, broke yarn install, trivy didn't even run
|
ping @nikola-maric-aula so this is what a PR with a newly introduced high severity would look like atm. (please disregard the axios stuff above, that was too explosive :P ) see also https://github.com/aula-app/aula-frontend/security/code-scanning?query=is%3Aopen+pr%3A1152 where the svgo vuln shows up as |
|
trashing my secret github reputation by introducing the dumbest vulns possible... |
^^
i made FE only allow merging PRs that pass the Trivy check, although I set the threshold "Critical" and this PR is blocked even with its "High" severity: we can talk more about it tomorrow.. |

this is a TEST to see how a trivy vuln looks like, cf.
https://github.com/aula-app/infra/issues/4#issuecomment-4420234144
do not merge!