-
-
Notifications
You must be signed in to change notification settings - Fork 269
Open
Labels
enhancementNew feature or requestNew feature or request
Description
The lightning-flow-scanner (sfdx) package, used for scanning Salesforce Lightning Flows, has been deprecated and unpublished from the npm registry due to a critical remote code execution (RCE) vulnerability in its core dependency, lightning-flow-scanner-core. The vulnerability, caused by unsafe custom rule loading, has been addressed in the v5 release of the core.
I have prepared a PR:
[https://github.com//pull/6359)
Metadata
Metadata
Assignees
Labels
enhancementNew feature or requestNew feature or request