Conversation
Signed-off-by: Kunal Singh <kunalsin9h@gmail.com>
|
@calebbrown please review. |
| "affected": [ | ||
| { | ||
| "package": { | ||
| "name": "frontend-backoffice", |
There was a problem hiding this comment.
I wonder about the other packages by the same user: https://www.npmjs.com/~abuelkhairbugbounty - but maybe they aren't bad enough. Won't block on this tho.
There was a problem hiding this comment.
@elitsa-gosst added other 2 packages too!
There was a problem hiding this comment.
Thanks! Just a nit - why didn't you specify a version for this package but you did for the others?
There was a problem hiding this comment.
@elitsa-gosst since all version of it is malicious, i use 0, for one of the package @telekom-wfa/auth-core, the latest version has removed the payload, hence only one version is malicious, for other package, it already had the record, so i just added 2 more versions, keeping original record.
elitsa-gosst
left a comment
There was a problem hiding this comment.
Thanks for contributing!
Signed-off-by: Kunal Singh <kunalsin9h@gmail.com>
No description provided.