0.11.2
3 months ago
3 months ago
Known vulnerabilities in the ciguard package. This does not include vulnerabilities belonging to this package’s dependencies.
Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.
Fix for free| Vulnerability | Vulnerable Version |
|---|---|
ciguard is a Static security auditor for CI/CD pipelines — now with a Model Context Protocol server ( Affected versions of this package are vulnerable to Improper Restriction of Rendered UI Layers or Frames due to missing HTTP security headers in the web interface. An attacker can compromise the integrity of the web application by exploiting the absence of headers such as How to fix Improper Restriction of Rendered UI Layers or Frames? Upgrade | [,0.8.2) |
ciguard is a Static security auditor for CI/CD pipelines — now with a Model Context Protocol server ( Affected versions of this package are vulnerable to Execution with Unnecessary Privileges due to the container image running as the root user by default, as the Dockerfile lacks a How to fix Execution with Unnecessary Privileges? Upgrade | [,0.8.2) |