smartystreets / goconvey

Go testing in the browser. Integrates with `go test`. Write behavioral tests in Go.
http://smartystreets.github.io/goconvey/
Other
8.23k stars 554 forks source link

Vulnerabilities in WebUI #653

Open ogomozov-godaddy opened 2 years ago

ogomozov-godaddy commented 2 years ago

GoConvey has many vulnerabilities, mainly in WebUI, cause it is 5 years old and is not updated While WebUI many not be used widely , may just use core GoConvey, it affects security reports as if GoConvey is vulnerable See list of High and medium concerns

image

tarihub commented 1 year ago

I meet this problem while using WhiteSource too

tarihub commented 1 year ago

Any official suggest for this?

tarihub commented 1 year ago

GoConvey has many vulnerabilities, mainly in WebUI, cause it is 5 years old and is not updated While WebUI many not be used widely , may just use core GoConvey, it affects security reports as if GoConvey is vulnerable See list of High and medium concerns

image

Hey, what tool did you use to scan for this