Tuleap Community Edition development and releases are no longer public. You have until September 30th to download packages and sources in Tuleap project. You can contact the team if you need further assistance.

    •  
      request #47181 Temporarily ignore CVE-2026-30964 of web-auth/webauthn-lib
    Infos
    #47181
    Kevin Traini (ktraini)
    2026-03-11 16:37
    2026-03-11 15:47
    48933
    Details
    Temporarily ignore CVE-2026-30964 of web-auth/webauthn-lib

    https://osv.dev/vulnerability/GHSA-f7pm-6hr8-7ggm

    It does not impact Tuleap as we do not use the web-auth host check, instead we use a csrf token

    Empty
    Empty
    Empty
    • [ ] enhancement
    • [ ] internal improvement
    Empty
    Stage
    Kevin Traini (ktraini)
    Closed
    2026-03-11
    Attachments
    Empty
    References
    Referenced by request #47181

    Follow-ups

    User avatar
    Thomas Gerbet (tgerbet)2026-03-11 16:37
    • Summary
      -Temporarily ignore CVE-2026-30964 
      +Temporarily ignore CVE-2026-30964 of web-auth/webauthn-lib 
    • Connected artifacts