Skip to content

Package shows as having critical vulnerability in scans #3604

@fstaffa

Description

@fstaffa

Description

We use snyk for dependency scan and latest newrelic package is marked as impacted by a critical vulnerability https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N/E:P through it's dependencies. I don't think this actually is a security problem, but creates noise in any security scans.

Expected Behavior

Don't show the alert

Steps to Reproduce

run npm audit

Your Environment

does not depend on environment

Additional context

The transitive dependency is already removed in latest https://github.com/newrelic/csec-node-agent

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    Status

    Done: Issues recently completed

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions