Skip to content

Conversation

@thc202
Copy link
Member

@thc202 thc202 commented Nov 27, 2025

Install the extension with BiDi, using the command line argument is no longer supported.

Install the extension with BiDi, using the command line argument is no
longer supported.

Signed-off-by: thc202 <[email protected]>
@thc202 thc202 marked this pull request as draft November 27, 2025 10:37
@psiinon
Copy link
Member

psiinon commented Nov 27, 2025

Logo
Checkmarx One – Scan Summary & Details28143578-4c46-49db-aa62-dedb4592a397

New Issues (3)

Checkmarx found the following issues in this Pull Request

Severity Issue Source File / Package Checkmarx Insight
MEDIUM CVE-2025-64718 Npm-js-yaml-4.1.0
detailsRecommended version: 4.1.1
Description: js-yaml is a JavaScript YAML parser and dumper. In js-yaml versions through 3.14.1 and 4.x through 4.1.0, it's possible for an attacker to modify t...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: t%2B3u983CW6%2FEu8MU5C3NWBKTLk7K3HTMqC6JgpXP0A4%3D
Vulnerable Package
MEDIUM CVE-2025-64718 Npm-js-yaml-3.14.1
detailsRecommended version: 3.14.2
Description: js-yaml is a JavaScript YAML parser and dumper. In js-yaml versions through 3.14.1 and 4.x through 4.1.0, it's possible for an attacker to modify t...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: ye%2F32vXMVktMB7qb7PG%2BXNFJQi9WFGWMXjgpO3xWeAI%3D
Vulnerable Package
LOW CVE-2025-7339 Npm-on-headers-1.0.2
detailsRecommended version: 1.1.0
Description: The on-headers is a node.js middleware for listening to when a response writes headers. A bug in on-headers versions prior to 1.1.0 may result in r...
Attack Vector: LOCAL
Attack Complexity: LOW

ID: ZQHA009nzmmKMjrUWNclsbSyXSo7Nciwi420YBnoTUc%3D
Vulnerable Package

Use @Checkmarx to reach out to us for assistance.

Just send a PR comment with @Checkmarx followed by a natural language request.

Examples: @Checkmarx how are you able to help me? @Checkmarx rescan this PR

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants