Hacktoberfest 2026: los issues que los mantenedores marcaron para octubre, abiertos y aptos para principiantes. Explorar issues de Hacktoberfest

[Docs]: list of false-postive CVEs (handlebars, etc)

Abierto
#6,332 8 comentarios 1 reacción 0 asignados Ver en GitHub

Nadie ha tomado este issue todavía.

Evaluación

Dificultad
3/5
Tiempo estimado
1-2 días
Aptitud para principiantes
42/100
Tipo de issue
Documentación
Claridad
Bastante claro
Estado de actividad
Estancado
Stack tecnológico
handlebars, vscode

Línea de trabajo

Comienza revisando code-server/lib/code-server-4.13.0/lib/vscode/extensions/handlebars/package.json y las CVE reportadas cve-2019-19919, cve-2021-23369 y cve-2021-23383. Compara el componente identificado por Trivy con el paquete npm handlebars y determina si los hallazgos se aplican al plugin de VS Code. Se considera terminado cuando se haya confirmado el estado de falso positivo y las CVE afectadas estén documentadas para los equipos de seguridad.

Escrito por el modelo de indexación a partir del texto del issue.

Descripción

docs

What is your suggestion?

We evaluate coder in a high security offline environment. For that, we scanned our workspace image with code-server preinstalled with trivy. There were crititcal CVEs found but we think that they are false positives. Can you please confirm that? This could be added to the docs too.

We found the handlebars CVEs cve-2019-19919, cve-2021-23369, cve-2021-23383 in code-server/lib/code-server-4.13.0/lib/vscode/extensions/handlebars/package.json
We think that Trivy is misled by the name of this component and thinks that it refers to handlebars on npm and not to the vs-code plugin with the same name.

How will this improve the docs?

Security-oriented teams like us will benefit from that because they can forward the false-positive list to their security team to still get the permission to use the software.

Can you confirm that CVEs are false-positives, so that we can forward that to the security team responsible for us?

Lenguaje dominante
TypeScript
Estrellas
79.4k
Forks
6.9k
Merge medio
2 d 13 h
PR fusionados (30 d)
39

Guía de contribución

Abrir la guía de contribución

Primeros pasos

  1. Lee el issue completo y luego la guía de contribución del proyecto.
  2. Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
  3. Haz un fork del repositorio y trabaja en una rama.
  4. Abre un pull request que haga referencia al número del issue.

Más de coder/code-server

Todos los issues de coder/code-server

Issues similares

Más issues de TypeScript

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.