Skip to content

Add alerts from docker API scripts#3649

Merged
thc202 merged 1 commit intozaproxy:mainfrom
psiinon:alerts-docker-scripts
Mar 11, 2026
Merged

Add alerts from docker API scripts#3649
thc202 merged 1 commit intozaproxy:mainfrom
psiinon:alerts-docker-scripts

Conversation

@psiinon
Copy link
Copy Markdown
Member

@psiinon psiinon commented Mar 9, 2026

@psiinon
Copy link
Copy Markdown
Member Author

psiinon commented Mar 9, 2026

Logo
Checkmarx One – Scan Summary & Details17430c08-73b6-44f9-8db0-0ca54e7520b0


New Issues (4) Checkmarx found the following issues in this Pull Request
# Severity Issue Source File / Package Checkmarx Insight
1 HIGH CVE-2026-26996 Npm-minimatch-3.1.2
detailsRecommended version: 3.1.4
Description: minimatch is a minimal matching utility for converting glob expressions into JavaScript RegExp objects. Versions prior to 3.1.3, 4.0.0 prior to 4.2...
Attack Vector: NETWORK
Attack Complexity: LOW
Vulnerable Package
2 HIGH CVE-2026-27903 Npm-minimatch-3.1.2
detailsRecommended version: 3.1.4
Description: minimatch is a minimal matching utility for converting glob expressions into JavaScript RegExp objects. All versions starting from 3.0.0 and prior ...
Attack Vector: NETWORK
Attack Complexity: LOW
Vulnerable Package
3 HIGH CVE-2026-27904 Npm-minimatch-3.1.2
detailsRecommended version: 3.1.4
Description: minimatch is a minimal matching utility for converting glob expressions into JavaScript RegExp objects. All versions starting from 3.0.0 and prior ...
Attack Vector: NETWORK
Attack Complexity: LOW
Vulnerable Package
4 HIGH Cxf5fb15b0-6576 Npm-serialize-javascript-6.0.2
detailsRecommended version: 7.0.3
Description: serialize-javascript through 7.0.2 contains a code injection vulnerability due to improper escaping of "RegExp.flags" during serialization. Althoug...
Attack Vector: NETWORK
Attack Complexity: HIGH
Vulnerable Package

Use @Checkmarx to interact with Checkmarx PR Assistant.
Examples:
@Checkmarx how are you able to help me?
@Checkmarx rescan this PR

@kingthorin
Copy link
Copy Markdown
Member

Update based on: zaproxy/zaproxy#9275 ?

@psiinon
Copy link
Copy Markdown
Member Author

psiinon commented Mar 10, 2026

Yeah, will do 😁

@psiinon psiinon force-pushed the alerts-docker-scripts branch from 2f1fdca to cb7cbfc Compare March 11, 2026 12:06
@psiinon
Copy link
Copy Markdown
Member Author

psiinon commented Mar 11, 2026

Updated

Comment thread site/content/docs/alerts/100001.md Outdated
@psiinon psiinon force-pushed the alerts-docker-scripts branch from cb7cbfc to d2bce9e Compare March 11, 2026 14:31
@psiinon psiinon force-pushed the alerts-docker-scripts branch from d2bce9e to fbb85a0 Compare March 11, 2026 14:32
@thc202 thc202 merged commit df88ff4 into zaproxy:main Mar 11, 2026
3 checks passed
@thc202
Copy link
Copy Markdown
Member

thc202 commented Mar 11, 2026

Thank you!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

3 participants