Skip to content

feat: add jQuery Validation and GSAP library entries - #19

Open
tmendo wants to merge 1 commit into
mainfrom
feat/kb-jquery-validation-gsap
Open

tmendo wants to merge 1 commit into
mainfrom
feat/kb-jquery-validation-gsap

Conversation

@tmendo

@tmendo tmendo commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

Summary

The app reports both libraries, but the knowledge base had no entry for either:

File OVI Source of the definition
jquery-validation-library-with-known-vulnerabilities.md OVI-339 engine conf/taxonomy.csv + conf/cvss.json; severity/CVSS also in backend data migration 0297
gsap-library-with-known-vulnerabilities.md OVI-352 backend data migration 0340_add_retire_ovi_352.py
  • Severity low, CVSS 4.8 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N), CWE-1395, same as the other library entries.
  • Description and fix text are the standard outdated-library wording used by every other library entry (e.g. Lodash), as confirmed for jQuery Validation.
  • Compliance mirrors the engine's standard lists for both OVIs (HIPAA 164.306(a), ISO 27001 A.8.9, OWASP A5/A6, PCI 6.2, PCI DSS v4.0.1 6.2.4/6.3.3), identical to Lodash's. OWASP 2025 A03 is in those lists too, but no KB entry carries an OWASP 2025 key yet, so it is left out here as well.

Swiper, Quill, MooTools, Marked, protobuf.js and Video.js (OVI-346 to 351) are tracked separately in FAW-1573; markdown-it and highlight.js in FAW-1229.

Test plan

  • Header fields and body structure match lodash-library-with-known-vulnerabilities.md line for line (only the library name differs)
  • gitleaks pre-commit hook passed

🤖 Generated with Claude Code

The app detects both (OVI-339 jQuery Validation, OVI-352 GSAP) but the
knowledge base had no entry for either. Severity, CVSS vector, CWE and
fix text follow the backend definitions (data migration 0340 for GSAP)
and the other library entries; compliance mirrors the engine's standard
lists for both OVIs, which match Lodash's.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@tmendo
tmendo requested a review from a team as a code owner October 6, 2026 22:39
@tmendo tmendo assigned tmendo and pavkam and unassigned pavkam Oct 6, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants