Feedback from my company security team after reviewing my request to approve use of openspec in our work.
"I ran the OpenSpec source code through trivy and opengrep with concerning results. Trivy identifies 8 high severity CVEs within the primary pnpm-lock.yaml file. More concerning, opengrep identified 226 findings. The majority of these findings are path traversal vulnerabilities, which appear systemic. Analysis of the project itself points to an immaturity of their security program: no SCA analysis, no static analysis, a lack of reported vulnerabilities or security defects"
Any plans on addressing the security concerns? I like openspec and would like to use it in my work, but this is not a good look.
Feedback from my company security team after reviewing my request to approve use of openspec in our work.
"I ran the OpenSpec source code through trivy and opengrep with concerning results. Trivy identifies 8 high severity CVEs within the primary pnpm-lock.yaml file. More concerning, opengrep identified 226 findings. The majority of these findings are path traversal vulnerabilities, which appear systemic. Analysis of the project itself points to an immaturity of their security program: no SCA analysis, no static analysis, a lack of reported vulnerabilities or security defects"
Any plans on addressing the security concerns? I like openspec and would like to use it in my work, but this is not a good look.