Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

WIP: add gh action for semgrep #18

Closed
wants to merge 6 commits into from
Closed

WIP: add gh action for semgrep #18

wants to merge 6 commits into from

Conversation

yen-tt
Copy link
Collaborator

@yen-tt yen-tt commented Jul 10, 2023

wip

@yen-tt yen-tt requested a review from a team as a code owner July 10, 2023 14:59
Comment on lines 2790 to 2735
"node_modules/@microsoft/api-extractor/node_modules/lru-cache": {
"version": "6.0.0",
Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Legal Risk:
lru-cache 6.0.0 was released under the ISC license, a license currently prohibited by your organization. Merging is blocked until this is resolved

Recommendation:
Reach out to your security team or Semgrep admin to address this issue. In special cases, exceptions may be made for dependencies with violating licenses, however, the general recommendation is to avoid using a dependency under such a license

Comment on lines 2817 to 2775
"node_modules/@microsoft/api-extractor/node_modules/yallist": {
"version": "4.0.0",
Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Legal Risk:
yallist 4.0.0 was released under the ISC license, a license currently prohibited by your organization. Merging is blocked until this is resolved

Recommendation:
Reach out to your security team or Semgrep admin to address this issue. In special cases, exceptions may be made for dependencies with violating licenses, however, the general recommendation is to avoid using a dependency under such a license

@@ -3756,7 +3799,6 @@
"version": "4.7.2",
Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Legal Risk:
axe-core 4.7.2 was released under the MPL-2.0 license, a license currently prohibited by your organization. Merging is blocked until this is resolved

Recommendation:
Reach out to your security team or Semgrep admin to address this issue. In special cases, exceptions may be made for dependencies with violating licenses, however, the general recommendation is to avoid using a dependency under such a license

@@ -3756,7 +3799,6 @@
"version": "4.7.2",
Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Legal Risk:
axe-core 4.7.2 was released under the MPL-2.0 license, a license currently prohibited by your organization. Merging is blocked until this is resolved

Recommendation:
Reach out to your security team or Semgrep admin to address this issue. In special cases, exceptions may be made for dependencies with violating licenses, however, the general recommendation is to avoid using a dependency under such a license

@yen-tt yen-tt closed this Jul 12, 2023
@yen-tt
Copy link
Collaborator Author

yen-tt commented Jul 12, 2023

During meeting with Semgrep agent, a GH action yml file was pushed to main already for full scan of the codebase.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant