Skip to content

Cx743605c8-a95e @ Npm-momnet-2.29.1 #24

@YSLCx

Description

@YSLCx

Checkmarx (SCA): Vulnerable Package
Vulnerability: Read More about Cx743605c8-a95e
Checkmarx Project: YSLCx/workshop_demo
Repository URL: https://github.com/YSLCx/workshop_demo
Branch: main
Scan ID: 85f0b871-dd27-420e-95e1-91e06302f579


There is a weak link between the package's listed metadata and the referenced Git repository "https://github.com/moment/moment"

About

Package managers often display traction statistics per code package based on it's related GitHub repository. This statistics helps developers to evaluate code packages.

infographic

The statistics displayed by the package managers do not go through any validation process. It can easily be falsified to mislead developers because of how this information is acquired.

As part of the package metadata analysis capabilities Checkmarx has, StarJacking engine verifies the authenticity of such Git repository references and in case it's a false reference, this risk is shown


Additional Info

Metadata

Metadata

Assignees

No one assigned

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions