fecgov / openFEC

The first RESTful API for the Federal Election Commission. We're aiming to make campaign finance more accessible for journalists, academics, developers, and other transparency seekers.
https://api.open.fec.gov/developers
Other
480 stars 106 forks source link

Check logs Sprint 25.i Week 3 #5923

Closed tmpayton closed 2 months ago

tmpayton commented 3 months ago

Log review needs to be completed per the Security Event Review Checklist (https://github.com/fecgov/FEC/wiki/Security-Event-Review-Checklist)

Ref: https://github.com/fecgov/openFEC/issues/5922

pkfec commented 2 months ago

Note: The following issues were logged viasnyk cli only

FEC-CMS: 1 package.json: 0 requirements.txt: 1 [Snyk Medium - wagtail@5.2.6 Improper Handling of Insufficient Permissions or Privileges]-(new issue)

Screenshot 2024-08-20 at 4 51 31 PM

OpenFEC: 3 package.json: 0 data/flyway/build.gradle: 0

requirements.txt: 3 [Snyk: Medium - Certifi Insufficient Verification of Data Authenticity] -(https://github.com/fecgov/openFEC/issues/5914) [Snyk: High/Low - flask core] -(https://github.com/fecgov/openFEC/issues/5935)

Screenshot 2024-08-20 at 5 37 07 PM

Pattern-Library: 0

Search logs: "User changes" not found in the past week. Deployer accounts from cloud.gov dashboard: 10