Dependabot-core: Depandabot wont recognise package with vulnerability from WhiteSource Vulnerability Database

Created on 18 Dec 2020  路  4Comments  路  Source: dependabot/dependabot-core

Package manager/ecosystem
JavaScript

Manifest contents prior to update
yarn.lock
package.json

Description

One of hour packages, hellojs, is flagged with a vulnerability in WhiteSource Vulnerability Database all version below 1.18.6 is affected. However dependabot won't recognise this vulnerability. Goto WhiteSource Vulnerability Database and search for CVE-2020-7741.

I have created a repo where I can reproduce the issue. I have added hellojs and jquery at a version that has a vulnerability. We can see that dependabot finds the jquery vulnerability and creates a PR but no for hellojs.

Is this a bug or have I missed something?

/C

bug 馃悶

All 4 comments

Your package.json has hellojs as ^1.17.1 (minor updates), therefore it will update to the latest which is 1.18.6 (Since it's a minor update). If you check your yarn.lock you can see that it is indeed at 1.18.6. So, this is working as intended as the dependency is at the latest version.

For more information on the versioning check: https://docs.npmjs.com/about-semantic-versioning/ and to see what updates can be accepted with the version in package.json you can refer to this: https://semver.npmjs.com/

Ohh sorry about the noice, thought I had pushed the correct commit.. I really need the upcoming christmas break :)

But, I have pushed the right commit now and I cant see the hellojs vulnerability over at

Thanks for the quick response!

/C

Hello and Happy new year! I realise I made some mistakes when I created this issue. I have now put my repo in a state where I think dependabot should find the vulnerability.

So I have updated the repo where hellojs is installed @1.18.4 but still no depenadabot alerts nor pull requests in regards to hellojs.

If you go to WhiteSource Vulnerability Database and search for CVE-2020-7741 you will see the vulnerability and all versions below 1.18.5 should be affected.

@WalshyDev

We are still not seeing any vulnerabilities alerts from dependabot in regards to hellojs. Could we re-open this issue to get someone to take a closer look at it?

Was this page helpful?
0 / 5 - 0 ratings

Related issues

Spomky picture Spomky  路  4Comments

LankyLou picture LankyLou  路  4Comments

tjwallace picture tjwallace  路  3Comments

rebelagentm picture rebelagentm  路  3Comments

ZebraFlesh picture ZebraFlesh  路  3Comments