Conversation
|
Please split this into separate pull requests for the different features. The CLI fixes should be separate from the plugin rewrites. |
| working-directory: node | ||
| - run: node node_modules/eslint/bin/eslint.js . --ext .ts --ignore-path ../.gitignore | ||
| working-directory: node | ||
| - run: npm ci --no-audit --no-fund |
There was a problem hiding this comment.
why do you keep adding no-audit?
There was a problem hiding this comment.
I added the flag to suppress installation-time audit output; it was unnecessary for this change. In the replacement extension PR (#624), I removed --no-audit and --no-fund from CI and the build scripts, so npm's default audit behavior remains.
| # Browser extension development | ||
|
|
||
| To use the development version: | ||
| Run `build_chrome.bat` on Windows or `./build_chrome.sh` on Unix from the repository root. Node.js 18 or newer and npm are required. The build compiles the scanner and creates all three packages without relying on symlinks: |
There was a problem hiding this comment.
The development instructions in #624 now recommend Node 24 LTS. CI covers Node 24 and 26 on Linux and Windows. Users loading the committed prebuilt extensions do not need Node installed.
|
Prebuilt versions of the plugins were included to allow people to use the plugins without having node locally. |
|
For the changes to the plugin, please explain screen shots to explain what you mean by replacing the popup with a 600x600 analyst console. |
| .map((r) => | ||
| r.results | ||
| .map((dep) => { | ||
| dep.version = (dep.version.split('.').length >= 3 ? dep.version : dep.version + '.0').replace(/-/g, '.'); |
There was a problem hiding this comment.
There are cyclonedx parsers that only support 1-3 numbers and nothing more
There was a problem hiding this comment.
I removed the transformation because it changed detected versions and mutated shared findings. Given the parser compatibility requirement, the revised fix in #625 preserves the exact existing output transformation but applies it to a report-local copy. PURLs, component references, and identity evidence use that same formatted copy. Tests cover unchanged inputs, legacy output strings, and reference consistency. This retains the existing behavior rather than introducing a new numeric-only sanitizer.
|
I split this into three independent PRs targeting master:
#624 restores complete prebuilt packages in It also includes two Playwright screenshots of the actual 600×600 popup scanning Google's XSS training page with jQuery 2.1.1: the resource overview and the inspector scrolled to CVE-2020-11022. The description explains the search, settings, copying, and full-snapshot export behavior. Firefox shares the UI and was tested separately. The focused PRs include their validation results. I am closing this combined PR as superseded so review can continue there; the original branch and discussion are preserved. |
Summary
CLI scans could finish before asynchronous OSV results arrived, CycloneDX reports could alter detected versions or discard evidence from repeated components, and browser scans could lose or mix results across navigation and background restarts. This change fixes those paths and replaces the extension popup with a shared 600×600 analyst console for Chrome and a modern Firefox WebExtension.
The popup provides resource search, severity and advisory details, URL copying, JSON export, and persisted settings. Scan failures, pending resources, and unidentified libraries remain distinct from identified libraries with no known vulnerabilities.
Commit organization
Validation
node validateand the fullnode test-detection.jssuite pass.dist/chrome,dist/chrome-no-func, anddist/firefox.Compatibility and review notes
Firefox uses static and AST detection; sandbox function execution remains specific to the full Chrome package. Minimum browser versions are Chrome 116 and Firefox 140. Browser smoke scripts currently use Windows installation paths and are manual checks; CI runs the platform-independent unit tests and builds. Generated packages are ignored, and this PR does not publish store releases or change the vulnerability database.
This is an AI-assisted implementation. The old Firefox SDK sources remain archived and excluded from the new package; loading instructions describe the new builds.