-
Notifications
You must be signed in to change notification settings - Fork 3.5k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
OWASP vulnerabilities due to outdated dependency #9240
Comments
We were very out of date and this addresses several potential OWASP vulnerabilities. Fixes #9240
I am impressed by how soon you tackled this and I am thrilled by Cesium adding the dependency-checker to the release process. Great work! |
@mramato This new version of However the source map is not included in the Cesium codebase, so I'm getting a 404 warning during development:
Is this something you want a new issue ticket for? Thanks! |
A scan using the OWASP dependency-check reveals that Cesium uses
DOMPurify 1.0.8
which has several vulnerabilities that were patched on release 2.2.2.Could it be possible to update this dependency so that Cesium will not be vulnerable?
I also recommend adding a security policy on GitHub so that the contributors can get a chance to address this issues before making it public.
Thanks
AR
The text was updated successfully, but these errors were encountered: