Skip to content

[Report] Website Security & Quality Findings #1100

Description

@eddie-knight

Situation

Maintainers have access to view the Security and quality tab on GitHub. Currently there are 200+ findings related to npm code, likely due to the large volume of AI-generated code currently in the website directory. The curse of rapid progress.

Risk

While this is not a threat to our catalog-users, it may be a reputational risk for the project if any of these issues can result in a compromise of the website. There is additional reputational risk associated with the perception of an apparently insecure asset produced by the project (even logging this issue is adding to that particular risk).

Due to the high volume of reports, I haven't managed to assess the actual risk beyond "something bad might be hiding in these alerts."

Proposed Mitigation

As we are improving the website, it would be prudent to (1) reduce the size of the codebase and (2) assess the overall security posture.

Because alerts in this tool do not always self-clear in all scenarios, this may involve clearing and re-triggering the alerts to determine the latest posture.

Metadata

Metadata

Labels

websiteWork related to the Website WG

Type

No type
No fields configured for issues without a type.

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions