This version was rejected.
It did not pass GreenFlagged's security review and is not served by the registry.
The findings and risk dispositions below explain why.
Risk Dispositions
(1 applicable to this version, 0 other)
Accepted rules are downgraded to INFO on future analyses; rejected rules escalate to CRITICAL.
Rule
Source
Disposition
Author
Reason
osv:GHSA-qm9p-f9j5-w83w
osv
reject
AI
AI (osv): Origin validation error in Parcel dev server; affects all versions < 2.16.4. Fix is available. Verdict generalizes to all versions in the affected range.
SAST Findings (2)
CRITICALGHSA-qm9p-f9j5-w83w: Parcel has an Origin Validation Error vulnerabilityosv
[Always reject] CVSS 6.5 (MEDIUM) — CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
parcel versions 1.6.1 and above have an Origin Validation Error vulnerability. Malicious websites can send XMLHTTPRequests to the application's development server and read the response to steal source code when developers visit them. Version 2.16.4 supports a `--no-cors` option which disables CORS headers in the dev server.
LOWNo provenance attestationprovenance
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.