Dávid Paksy created HBASE-30310:
-----------------------------------

             Summary: Upgrade vulnerable website dependencies
                 Key: HBASE-30310
                 URL: https://issues.apache.org/jira/browse/HBASE-30310
             Project: HBase
          Issue Type: Bug
          Components: dependabot, security, website
            Reporter: Dávid Paksy


Dependabot identified some website dependencies with known CVE-s and opened 
automated security update PR-s for them:

[https://github.com/apache/hbase/pulls?q=is%3Aopen+is%3Apr+author%3Aapp%2Fdependabot+label%3Ajavascript]

 

The React router CVE seems to have the biggest impact as it may require major 
version upgrade which probably requires more work than just change the version 
number.



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to