Security concerns around snyk being packaged with sfcc-ci and snyk forcing us to register and pass a auth token #504
Unanswered
srinumanthena
asked this question in
Q&A
Replies: 0 comments
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
Hello,
we are using sfcc-ci and build suite for quite some time to deploy our code to salesforce commerce cloud. This week we encountered a issue where snyk is forcing us to register and use a auth token when we try to download sfcc-ci via npm as it looks like sfcc-ci has dependency on snyk npm module. See below error message we encountered. It is concerning that snyk can collect data from our code and forcing us to register with snyk. Is there a way to remove disable snyk during sfcc-ci npm installation? we have become aware of snyk only when we saw the below error, which started recently. We are using sfcc-ci version 2.5.1
Thank you
Beta Was this translation helpful? Give feedback.
All reactions