Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Story #12364: improve saml documentation & #13112: upgrade external providers #1944

Merged
merged 2 commits into from
Jul 15, 2024

Conversation

bbenaissa
Copy link
Collaborator

@bbenaissa bbenaissa commented Jul 12, 2024

Description

  • L'objectif de cette US est d'améliorer la documentation CAS pour l'integration d'IDP en Saml
  • Ajouter un script de migration des providers externes existants pour s'adapter au nouveau modèle
  • Ajouter un message d'information pour indiquer la nécessite de redémarrage de cas server suite à la création/modification des providers externes.

Type de changement

Indiquer le ou les types de changements

  • Build
  • Ansiblerie
  • Correction

Contributeur

  • VAS (Vitam Accessible en Service)

@bbenaissa bbenaissa self-assigned this Jul 12, 2024
@vitam-devops
Copy link
Collaborator

vitam-devops commented Jul 12, 2024

Logo
Checkmarx One – Scan Summary & Details0aa2330a-19a6-4515-a41a-9ec62cdea322

New Issues

Severity Issue Source File / Package Checkmarx Insight
HIGH CVE-2019-15599 Npm-tree-kill-1.2.1 Vulnerable Package
HIGH CVE-2020-28469 Npm-glob-parent-3.1.0 Vulnerable Package
HIGH CVE-2020-28502 Npm-xmlhttprequest-ssl-1.5.5 Vulnerable Package
HIGH CVE-2020-36048 Npm-engine.io-3.2.1 Vulnerable Package
HIGH CVE-2020-36049 Npm-socket.io-parser-3.2.0 Vulnerable Package
HIGH CVE-2020-7660 Npm-serialize-javascript-1.9.1 Vulnerable Package
HIGH CVE-2020-7788 Npm-ini-1.3.5 Vulnerable Package
HIGH CVE-2021-23382 Npm-postcss-7.0.14 Vulnerable Package
HIGH CVE-2021-23424 Npm-ansi-html-0.0.7 Vulnerable Package
HIGH CVE-2021-31597 Npm-xmlhttprequest-ssl-1.5.5 Vulnerable Package
HIGH CVE-2022-2421 Npm-socket.io-parser-3.2.0 Vulnerable Package
HIGH CVE-2022-24771 Npm-node-forge-0.10.0 Vulnerable Package
HIGH CVE-2022-24772 Npm-node-forge-0.10.0 Vulnerable Package
HIGH CVE-2022-25858 Npm-terser-3.17.0 Vulnerable Package
HIGH CVE-2022-25881 Npm-http-cache-semantics-3.8.1 Vulnerable Package
HIGH CVE-2022-25883 Npm-semver-6.3.0 Vulnerable Package
HIGH CVE-2022-25883 Npm-semver-6.0.0 Vulnerable Package
HIGH CVE-2022-37599 Npm-loader-utils-1.2.3 Vulnerable Package
HIGH CVE-2022-37601 Npm-loader-utils-1.2.3 Vulnerable Package
HIGH CVE-2022-37603 Npm-loader-utils-1.2.3 Vulnerable Package
HIGH CVE-2023-32695 Npm-socket.io-parser-3.2.0 Vulnerable Package
HIGH CVE-2023-45133 Npm-babel-traverse-6.26.0 Vulnerable Package
HIGH CVE-2024-29180 Npm-webpack-dev-middleware-3.6.2 Vulnerable Package
HIGH CVE-2024-38355 Npm-socket.io-2.1.1 Vulnerable Package
HIGH CVE-2024-4068 Npm-braces-2.3.2 Vulnerable Package
HIGH Cx347a3da7-ba99 Npm-node-forge-0.10.0 Vulnerable Package
MEDIUM CVE-2019-16769 Npm-serialize-javascript-1.9.1 Vulnerable Package
MEDIUM CVE-2020-15366 Npm-ajv-6.10.0 Vulnerable Package
MEDIUM CVE-2020-15366 Npm-ajv-5.5.2 Vulnerable Package
MEDIUM CVE-2020-28481 Npm-socket.io-2.1.1 Vulnerable Package
MEDIUM CVE-2020-7608 Npm-yargs-parser-11.1.1 Vulnerable Package
MEDIUM CVE-2020-7693 Npm-sockjs-0.3.19 Vulnerable Package
MEDIUM CVE-2021-23364 Npm-browserslist-4.5.5 Vulnerable Package
MEDIUM CVE-2021-23368 Npm-postcss-7.0.14 Vulnerable Package
MEDIUM CVE-2021-23495 Npm-karma-4.1.0 Vulnerable Package
MEDIUM CVE-2021-4231 Npm-@angular/core-8.2.14 Vulnerable Package
MEDIUM CVE-2022-0122 Npm-node-forge-0.10.0 Vulnerable Package
MEDIUM CVE-2022-0437 Npm-karma-4.1.0 Vulnerable Package
MEDIUM CVE-2022-21704 Npm-log4js-4.5.1 Vulnerable Package
MEDIUM CVE-2022-24773 Npm-node-forge-0.10.0 Vulnerable Package
MEDIUM CVE-2022-41940 Npm-engine.io-3.2.1 Vulnerable Package
MEDIUM CVE-2023-44270 Npm-postcss-7.0.14 Vulnerable Package
MEDIUM CVE-2024-28863 Npm-tar-4.4.19 Vulnerable Package
LOW CVE-2020-15262 Npm-webpack-subresource-integrity-1.1.0-rc.6 Vulnerable Package
LOW Cxda14f253-4e52 Npm-bluebird-3.7.2 Vulnerable Package
LOW Logging of Sensitive Data /ansible.cfg: 2 To keep sensitive values out of logs, tasks that expose them need to be marked defining 'no_log' and setting to True
LOW Logging of Sensitive Data /ansible.cfg: 2 To keep sensitive values out of logs, tasks that expose them need to be marked defining 'no_log' and setting to True
LOW Logging of Sensitive Data /ansible.cfg: 1 To keep sensitive values out of logs, tasks that expose them need to be marked defining 'no_log' and setting to True

Fixed Issues

Severity Issue Source File / Package
MEDIUM CVE-2024-39249 Npm-async-3.2.4
MEDIUM CVE-2024-39249 Npm-async-3.2.5

@bbenaissa bbenaissa force-pushed the story_12364_improve_saml_documentation branch from 315c01e to 859660c Compare July 14, 2024 13:19
@bbenaissa bbenaissa added bug Something isn't working documentation Improvements or additions to documentation enhancement New feature or request VAS VAS contribution labels Jul 15, 2024
@bbenaissa bbenaissa added this to the IT 138 milestone Jul 15, 2024
@bbenaissa bbenaissa marked this pull request as ready for review July 15, 2024 07:10
@bbenaissa bbenaissa changed the title Story#12364: improve saml integration documentation Story#12364: improve saml documentation & upgrade external providers Jul 15, 2024
@GiooDev GiooDev changed the title Story#12364: improve saml documentation & upgrade external providers Story #12364: improve saml documentation & #13112: upgrade external providers Jul 15, 2024
@bbenaissa bbenaissa merged commit 45954b5 into develop Jul 15, 2024
8 checks passed
@bbenaissa bbenaissa deleted the story_12364_improve_saml_documentation branch July 15, 2024 15:35
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Something isn't working documentation Improvements or additions to documentation enhancement New feature or request VAS VAS contribution
Projects
None yet
Development

Successfully merging this pull request may close these issues.

4 participants