-
Notifications
You must be signed in to change notification settings - Fork 380
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Critical vulnerabilities reported for cypress/factory #1115
Comments
Cypress Docker images cannot fix vulnerabilities which have not been fixed upstream.
|
Right, but Cypress uses some node modules that have Critical issues:
|
I can only give the same comment that I gave in the other issue:
|
Thank you |
There are separate issues for each of the vulnerabilities you mention:
I'm going to close this issue now as the follow-up needs to be done through https://github.com/cypress-io/cypress. As soon as any new Cypress version is released, a new |
I have linked the existing reports back to this issue. You can subscribe to the issues if you want to follow their resolution. |
Hello,
I'm using the latest
cypress/factory:4.0.2
image to run our tests in CI/CD pipelines. When building our image we are also scanning it for known security vulnerabilities with wiz.I am using the following Node, Chrome and Cypress versions:
It finds a lot of outdated versions and security issues:
Here's a text file with all the scan results:
scan-cypress.txt
The text was updated successfully, but these errors were encountered: