feat(frontend): Set up Storybook 8.x for component documentation and visual regression testing - #328
1 configuration not found
Warning: Code scanning may not have found all the alerts introduced by this pull request, because 1 configuration present on refs/heads/main was not found:
Actions workflow (ci.yml)
- ❓
.github/workflows/ci.yml:security-scan
New alerts in code changed by this pull request
Security Alerts:
- 4 critical
- 60 high
- 78 medium
- 10 low
Alerts not introduced by this pull request might have been detected because the code changes were too large.
See annotations below for details.
Annotations
Check failure on line 13537 in package-lock.json
Code scanning / Trivy
axios: Node.js: Axios: Denial of Service via unbounded recursion in toFormData with deeply nested request data High
Check failure on line 15598 in package-lock.json
Code scanning / Trivy
defu: Prototype pollution via `__proto__` key in defaults argument High
Check failure on line 16865 in package-lock.json
Code scanning / Trivy
ws: ws: Denial of Service via memory exhaustion from small WebSocket fragments High
Check failure on line 17383 in package-lock.json
Code scanning / Trivy
uuid: uuid: Out-of-bounds write vulnerability impacts data integrity and confidentiality High
Check failure on line 17474 in package-lock.json
Code scanning / Trivy
form-data: form-data: Form field override via CRLF injection High
Check failure on line 18283 in package-lock.json
Code scanning / Trivy
hono: CORS Middleware reflects any Origin with credentials when `origin` defaults to the wildcard High
Check failure on line 18475 in package-lock.json
Code scanning / Trivy
i18next-fs-backend vulnerable to prototype pollution via crafted missing-key string Critical
Check failure on line 18493 in package-lock.json
Code scanning / Trivy
i18next-http-middleware: MissingKeyHandler does not reject keys whose segments contain prototype-polluting names Critical
Check failure on line 19559 in package-lock.json
Code scanning / Trivy
socket.io: engine.io: Socket.IO: Denial of Service via invalid binary POST requests High
Check failure on line 21134 in package-lock.json
Code scanning / Trivy
lodash: lodash: Arbitrary code execution via untrusted input in template imports High
Check failure on line 21505 in package-lock.json
Code scanning / Trivy
minimatch: Minimatch: Denial of Service via catastrophic backtracking in glob expressions High
Check failure on line 21848 in package-lock.json
Code scanning / Trivy
Multer vulnerable to Denial of Service via memory leaks from unclosed streams High
Check failure on line 21848 in package-lock.json
Code scanning / Trivy
Multer vulnerable to Denial of Service from maliciously crafted requests High
Check failure on line 21848 in package-lock.json
Code scanning / Trivy
multer: Multer vulnerable to Denial of Service via unhandled exception High
Check failure on line 21848 in package-lock.json
Code scanning / Trivy
multer: Multer Denial of Service High
Check failure on line 21848 in package-lock.json
Code scanning / Trivy
multer: Multer: Denial of Service via dropped file upload connections High
Check failure on line 21848 in package-lock.json
Code scanning / Trivy
multer: Multer: Denial of Service via malformed requests High
Check failure on line 21848 in package-lock.json
Code scanning / Trivy
multer: Multer: Denial of Service via malformed requests High
Check failure on line 21848 in package-lock.json
Code scanning / Trivy
Multer vulnerable to Denial of Service via deeply nested field names High
Check failure on line 22163 in package-lock.json
Code scanning / Trivy
next.js: Next.js: Information disclosure due to middleware bypass in Pages Router with i18n High
Check failure on line 22163 in package-lock.json
Code scanning / Trivy
Next.js: Next.js: Server-Side Request Forgery via crafted WebSocket upgrade requests High
Check failure on line 22163 in package-lock.json
Code scanning / Trivy
Next.js Vulnerable to Denial of Service with Server Components High
Check failure on line 22163 in package-lock.json
Code scanning / Trivy
Next.js HTTP request deserialization can lead to DoS when using insecure React Server Components High
Check failure on line 22163 in package-lock.json
Code scanning / Trivy
Next.js has a Denial of Service with Server Components High
Check failure on line 13537 in package-lock.json
Code scanning / Trivy
axios: Axios: Denial of Service due to unenforced request and response size limits High