Only look for moderate and above vulnerabilities #201
Merged
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
There's currently a low-level vulnerability that's blocking all builds. This will allow us to unblock the pipeline whilst still stopping at moderate, high and severe vulnerabilities.
NB: The node-sass vulnerability is a potential Denial of Service which can only occur with specially crafted input. This would require an attacker to change our or a dependency's CSS, and would crash our build pipeline not the application. Also, this vulnerability has not been disclosed to the node-sass team and there is no CVE, so there is very little understanding of the actual issue.
I'll add a note to the risk board to discuss long-term plans for this situation next week.