[PPP-5351]-XSS Findings For Data-Access#1284
[PPP-5351]-XSS Findings For Data-Access#1284Rangashivani wants to merge 1 commit intopentaho:BACKLOG-41215from
Conversation
a6c46ee to
aa01183
Compare
This comment has been minimized.
This comment has been minimized.
|
Note:Frogbot also supports Contextual Analysis, Secret Detection, IaC and SAST Vulnerabilities Scanning. This features are included as part of the JFrog Advanced Security package, which isn't enabled on your system. |
✅ Build finished in 1m 39sBuild command: mvn clean verify -B -e -Daudit -Djs.no.sandbox -pl \
assemblies/data-access-plugin❗ No tests found!ℹ️ This is an automatic message |
dcleao
left a comment
There was a problem hiding this comment.
AFAIK, this JS code in the data-access plugin is not used. In fact, it was duplicated and converted to RequireJS and now lives in https://github.com/pentaho/pentaho-platform-plugin-common-ui/tree/930bf603641698c4352d26d5a002f0659c61b5f3/impl/client/src/main/javascript/web/dataapi.
My advice is to remove this code, simultaneously fixing the XSS findings.





PPP-5351-XSS Findings For Data-Access