Skip to content

feat(frontend): Set up Storybook 8.x for component documentation and visual regression testing - #328

Closed
Moonwalker-rgb wants to merge 8 commits into
AetherEdu:mainfrom
Moonwalker-rgb:feature/storybook-setup-174
Closed

feat(frontend): Set up Storybook 8.x for component documentation and visual regression testing#328
Moonwalker-rgb wants to merge 8 commits into
AetherEdu:mainfrom
Moonwalker-rgb:feature/storybook-setup-174

fix(ci): Disable Next.js splitChunks in Storybook to resolve webpack …

2f20ce3
Select commit
Loading
Failed to load commit list.
GitHub Advanced Security / Trivy failed Jul 21, 2026 in 6s

1 configuration not found

Warning: Code scanning may not have found all the alerts introduced by this pull request, because 1 configuration present on refs/heads/main was not found:

Actions workflow (ci.yml)

  • ❓  .github/workflows/ci.yml:security-scan

New alerts in code changed by this pull request

Security Alerts:

  • 4 critical
  • 60 high
  • 78 medium
  • 10 low

Alerts not introduced by this pull request might have been detected because the code changes were too large.

See annotations below for details.

View all branch alerts.

Annotations

Check failure on line 13537 in package-lock.json

See this annotation in the file changed.

Code scanning / Trivy

axios: Node.js: Axios: Denial of Service via unbounded recursion in toFormData with deeply nested request data High

Package: axios
Installed Version: 1.13.5
Vulnerability CVE-2026-42039
Severity: MEDIUM
Fixed Version: 1.15.1, 0.31.1
Link: CVE-2026-42039

Check failure on line 15598 in package-lock.json

See this annotation in the file changed.

Code scanning / Trivy

defu: Prototype pollution via `__proto__` key in defaults argument High

Package: defu
Installed Version: 6.1.4
Vulnerability CVE-2026-35209
Severity: HIGH
Fixed Version: 6.1.5
Link: CVE-2026-35209

Check failure on line 16865 in package-lock.json

See this annotation in the file changed.

Code scanning / Trivy

ws: ws: Denial of Service via memory exhaustion from small WebSocket fragments High

Package: ws
Installed Version: 8.17.1
Vulnerability CVE-2026-48779
Severity: HIGH
Fixed Version: 5.2.5, 6.2.4, 7.5.11, 8.21.0
Link: CVE-2026-48779

Check failure on line 17383 in package-lock.json

See this annotation in the file changed.

Code scanning / Trivy

uuid: uuid: Out-of-bounds write vulnerability impacts data integrity and confidentiality High

Package: uuid
Installed Version: 11.1.0
Vulnerability CVE-2026-41907
Severity: MEDIUM
Fixed Version: 11.1.1, 12.0.1, 13.0.1
Link: CVE-2026-41907

Check failure on line 17474 in package-lock.json

See this annotation in the file changed.

Code scanning / Trivy

form-data: form-data: Form field override via CRLF injection High

Package: form-data
Installed Version: 4.0.5
Vulnerability CVE-2026-12143
Severity: HIGH
Fixed Version: 2.5.6, 3.0.5, 4.0.6
Link: CVE-2026-12143

Check failure on line 18283 in package-lock.json

See this annotation in the file changed.

Code scanning / Trivy

hono: CORS Middleware reflects any Origin with credentials when `origin` defaults to the wildcard High

Package: hono
Installed Version: 4.12.9
Vulnerability CVE-2026-54290
Severity: HIGH
Fixed Version: 4.12.25
Link: CVE-2026-54290

Check failure on line 18475 in package-lock.json

See this annotation in the file changed.

Code scanning / Trivy

i18next-fs-backend vulnerable to prototype pollution via crafted missing-key string Critical

Package: i18next-fs-backend
Installed Version: 2.6.5
Vulnerability CVE-2026-48713
Severity: CRITICAL
Fixed Version: 2.6.6
Link: CVE-2026-48713

Check failure on line 18493 in package-lock.json

See this annotation in the file changed.

Code scanning / Trivy

i18next-http-middleware: MissingKeyHandler does not reject keys whose segments contain prototype-polluting names Critical

Package: i18next-http-middleware
Installed Version: 3.9.6
Vulnerability CVE-2026-48714
Severity: CRITICAL
Fixed Version: 3.9.7
Link: CVE-2026-48714

Check failure on line 19559 in package-lock.json

See this annotation in the file changed.

Code scanning / Trivy

socket.io: engine.io: Socket.IO: Denial of Service via invalid binary POST requests High

Package: engine.io
Installed Version: 6.6.5
Vulnerability CVE-2026-59725
Severity: HIGH
Fixed Version: 6.6.7
Link: CVE-2026-59725

Check failure on line 21134 in package-lock.json

See this annotation in the file changed.

Code scanning / Trivy

lodash: lodash: Arbitrary code execution via untrusted input in template imports High

Package: lodash
Installed Version: 4.17.23
Vulnerability CVE-2026-4800
Severity: HIGH
Fixed Version: 4.18.0
Link: CVE-2026-4800

Check failure on line 21505 in package-lock.json

See this annotation in the file changed.

Code scanning / Trivy

minimatch: Minimatch: Denial of Service via catastrophic backtracking in glob expressions High

Package: minimatch
Installed Version: 3.1.3
Vulnerability CVE-2026-27904
Severity: HIGH
Fixed Version: 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, 3.1.4
Link: CVE-2026-27904

Check failure on line 21848 in package-lock.json

See this annotation in the file changed.

Code scanning / Trivy

Multer vulnerable to Denial of Service via memory leaks from unclosed streams High

Package: multer
Installed Version: 1.4.5-lts.2
Vulnerability CVE-2025-47935
Severity: HIGH
Fixed Version: 2.0.0
Link: CVE-2025-47935

Check failure on line 21848 in package-lock.json

See this annotation in the file changed.

Code scanning / Trivy

Multer vulnerable to Denial of Service from maliciously crafted requests High

Package: multer
Installed Version: 1.4.5-lts.2
Vulnerability CVE-2025-47944
Severity: HIGH
Fixed Version: 2.0.0
Link: CVE-2025-47944

Check failure on line 21848 in package-lock.json

See this annotation in the file changed.

Code scanning / Trivy

multer: Multer vulnerable to Denial of Service via unhandled exception High

Package: multer
Installed Version: 1.4.5-lts.2
Vulnerability CVE-2025-48997
Severity: HIGH
Fixed Version: 2.0.1
Link: CVE-2025-48997

Check failure on line 21848 in package-lock.json

See this annotation in the file changed.

Code scanning / Trivy

multer: Multer Denial of Service High

Package: multer
Installed Version: 1.4.5-lts.2
Vulnerability CVE-2025-7338
Severity: HIGH
Fixed Version: 2.0.2
Link: CVE-2025-7338

Check failure on line 21848 in package-lock.json

See this annotation in the file changed.

Code scanning / Trivy

multer: Multer: Denial of Service via dropped file upload connections High

Package: multer
Installed Version: 1.4.5-lts.2
Vulnerability CVE-2026-2359
Severity: HIGH
Fixed Version: 2.1.0
Link: CVE-2026-2359

Check failure on line 21848 in package-lock.json

See this annotation in the file changed.

Code scanning / Trivy

multer: Multer: Denial of Service via malformed requests High

Package: multer
Installed Version: 1.4.5-lts.2
Vulnerability CVE-2026-3304
Severity: HIGH
Fixed Version: 2.1.0
Link: CVE-2026-3304

Check failure on line 21848 in package-lock.json

See this annotation in the file changed.

Code scanning / Trivy

multer: Multer: Denial of Service via malformed requests High

Package: multer
Installed Version: 1.4.5-lts.2
Vulnerability CVE-2026-3520
Severity: HIGH
Fixed Version: 2.1.1
Link: CVE-2026-3520

Check failure on line 21848 in package-lock.json

See this annotation in the file changed.

Code scanning / Trivy

Multer vulnerable to Denial of Service via deeply nested field names High

Package: multer
Installed Version: 1.4.5-lts.2
Vulnerability CVE-2026-5079
Severity: HIGH
Fixed Version: 2.2.0, 3.0.0-alpha.2
Link: CVE-2026-5079

Check failure on line 22163 in package-lock.json

See this annotation in the file changed.

Code scanning / Trivy

next.js: Next.js: Information disclosure due to middleware bypass in Pages Router with i18n High

Package: next
Installed Version: 14.2.35
Vulnerability CVE-2026-44573
Severity: HIGH
Fixed Version: 15.5.16, 16.2.5
Link: CVE-2026-44573

Check failure on line 22163 in package-lock.json

See this annotation in the file changed.

Code scanning / Trivy

Next.js: Next.js: Server-Side Request Forgery via crafted WebSocket upgrade requests High

Package: next
Installed Version: 14.2.35
Vulnerability CVE-2026-44578
Severity: HIGH
Fixed Version: 15.5.16, 16.2.5
Link: CVE-2026-44578

Check failure on line 22163 in package-lock.json

See this annotation in the file changed.

Code scanning / Trivy

Next.js Vulnerable to Denial of Service with Server Components High

Package: next
Installed Version: 14.2.35
Vulnerability GHSA-8h8q-6873-q5fj
Severity: HIGH
Fixed Version: 15.5.16, 16.2.5
Link: GHSA-8h8q-6873-q5fj

Check failure on line 22163 in package-lock.json

See this annotation in the file changed.

Code scanning / Trivy

Next.js HTTP request deserialization can lead to DoS when using insecure React Server Components High

Package: next
Installed Version: 14.2.35
Vulnerability GHSA-h25m-26qc-wcjf
Severity: HIGH
Fixed Version: 15.0.8, 15.1.12, 15.2.9, 15.3.9, 15.4.11, 15.5.10, 15.6.0-canary.61, 16.0.11, 16.1.5
Link: GHSA-h25m-26qc-wcjf

Check failure on line 22163 in package-lock.json

See this annotation in the file changed.

Code scanning / Trivy

Next.js has a Denial of Service with Server Components High

Package: next
Installed Version: 14.2.35
Vulnerability GHSA-q4gf-8mx6-v5v3
Severity: HIGH
Fixed Version: 15.5.15, 16.2.3
Link: GHSA-q4gf-8mx6-v5v3

Check failure on line 13537 in package-lock.json

See this annotation in the file changed.

Code scanning / Trivy

axios: Axios: Denial of Service due to unenforced request and response size limits High

Package: axios
Installed Version: 1.13.5
Vulnerability CVE-2026-44488
Severity: HIGH
Fixed Version: 1.16.0
Link: CVE-2026-44488