Web SDK vulnerability issues for the cloned cockpit


Customer is running a security scanner in the github for cloned cockpit application, and getting critical dependabot gives multiple alerts from the c8y library. where dependabot suggest updating the c8y library to 10.18 but the latest c8y available is 10.15 for enterprise customer.Please refer attached screenshot

We would like to know how to handle these vulnerability cases.

Hi Divya, a fix for the mentioned vulnerability will be available in 1015.0.431, so then dependabot should not need to upgrade the ng1-modules package up to 10.18.

