Dávid Paksy created HBASE-30379:
-----------------------------------
Summary: Update vulnerable website dependencies
Key: HBASE-30379
URL: https://issues.apache.org/jira/browse/HBASE-30379
Project: HBase
Issue Type: Task
Components: dependabot, dependencies, security
Reporter: Dávid Paksy
{noformat}
# npm audit report
@vitest/mocker 2.1.0 - 4.1.10
Severity: moderate
Vitest: Path Traversal / Arbitrary File Read via @vitest/mocker Redirect Mock -
https://github.com/advisories/GHSA-82fw-gwwq-j7x9
fix available via `npm audit fix`
node_modules/@vitest/mocker
vitest 2.1.0-beta.1 - 4.1.10
Depends on vulnerable versions of @vitest/mocker
node_modules/vitest
js-yaml 4.0.0 - 4.3.1
Severity: high
js-yaml: maxTotalMergeKeys does not limit CPU use for empty merge sources -
https://github.com/advisories/GHSA-2883-xcg3-v3hh
fix available via `npm audit fix`
node_modules/js-yaml
morgan <1.12.0
Severity: moderate
morgan vulnerable to Log Forging via unescaped Unicode line separators -
https://github.com/advisories/GHSA-jxfw-x594-9x9m
fix available via `npm audit fix`
node_modules/morgan
4 vulnerabilities (3 moderate, 1 high)
{noformat}
--
This message was sent by Atlassian Jira
(v8.20.10#820010)