Dávid Paksy created HBASE-30379:
-----------------------------------

             Summary: Update vulnerable website dependencies
                 Key: HBASE-30379
                 URL: https://issues.apache.org/jira/browse/HBASE-30379
             Project: HBase
          Issue Type: Task
          Components: dependabot, dependencies, security
            Reporter: Dávid Paksy


{noformat}
# npm audit report

@vitest/mocker  2.1.0 - 4.1.10
Severity: moderate
Vitest: Path Traversal / Arbitrary File Read via @vitest/mocker Redirect Mock - 
https://github.com/advisories/GHSA-82fw-gwwq-j7x9
fix available via `npm audit fix`
node_modules/@vitest/mocker
  vitest  2.1.0-beta.1 - 4.1.10
  Depends on vulnerable versions of @vitest/mocker
  node_modules/vitest

js-yaml  4.0.0 - 4.3.1
Severity: high
js-yaml: maxTotalMergeKeys does not limit CPU use for empty merge sources - 
https://github.com/advisories/GHSA-2883-xcg3-v3hh
fix available via `npm audit fix`
node_modules/js-yaml

morgan  <1.12.0
Severity: moderate
morgan vulnerable to Log Forging via unescaped Unicode line separators - 
https://github.com/advisories/GHSA-jxfw-x594-9x9m
fix available via `npm audit fix`
node_modules/morgan


4 vulnerabilities (3 moderate, 1 high)

{noformat}



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to