Skip to content

Dependency confusion supply-chain vulnerability detected #271

Description

@ashishbijlani

Hi,

I'm a Cybersecurity researcher developing PackjGuard [1]. Our tool has detected a dependency confusion vulnerability in this repository.

The package @getnova/components mentioned in the README at line 19 does not exist on public NPM registry. A bad actor can hijack this package to propagate malicious code.

Not only your apps/service is vulnerable to this attack, but the users of your open-source Github repo are also vulnerable to this attack.

Please register a placeholder package for @getnova/components on public NPM soon to remediate.

Thanks!

  1. PackjGuard is a Github app that monitors repos for malicious/vulnerable dependencies and mitigates attacks by creating pull requests for automatic remediation https://github.com/marketplace/packjguard

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions