jsPsych icon indicating copy to clipboard operation
jsPsych copied to clipboard

Vulnerabilities: Check if we have known vulnerabilities as published in Open Source Vulnerability

Open cherriechang opened this issue 1 year ago • 3 comments

Tracking issue for:

  • [ ] https://github.com/jspsych/jsPsych/security/code-scanning/23

Instructions Code Documentation

### Tasks
- [x] [GHSA-3xgq-45jj-v275](https://osv.dev/vulnerability/GHSA-3xgq-45jj-v275)
- [x] GHSA-952p-6rrq-rcjv
- [x] GHSA-mwcw-c2x4-8c55
- [ ] GHSA-gcx4-mw62-g8wm
- [x] GHSA-g3ch-rx76-35fx
- [x] GHSA-248v-346w-9cwc
- [x] GHSA-34jh-p97f-mpxf
- [ ] GHSA-gmj6-6f8f-6699
- [ ] GHSA-q2x7-8rv6-6q7h

cherriechang avatar Dec 21 '24 11:12 cherriechang

cherriechang avatar Dec 21 '24 11:12 cherriechang

@jodeleeuw Maybe we should figure out how to systematically test whether each fix introduces breaking changes?

cherriechang avatar Dec 21 '24 12:12 cherriechang

The PR seems stale (last commit Jan 8) - is there anything blocking it?

JWMB avatar May 27 '25 19:05 JWMB