[ 
https://issues.apache.org/jira/browse/NIFI-13958?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17895050#comment-17895050
 ] 

ASF subversion and git services commented on NIFI-13958:
--------------------------------------------------------

Commit 1f0fe2567d4961224dee68f22549d5147e693bf7 in nifi's branch 
refs/heads/main from dependabot[bot]
[ https://gitbox.apache.org/repos/asf?p=nifi.git;h=1f0fe2567d ]

NIFI-13958 Upgraded elliptic from 6.5.7 to 6.6.0 for Registry (#9474)

Signed-off-by: David Handermann <[email protected]>

> Upgrade elliptic to 6.6.0 for Registry
> --------------------------------------
>
>                 Key: NIFI-13958
>                 URL: https://issues.apache.org/jira/browse/NIFI-13958
>             Project: Apache NiFi
>          Issue Type: Improvement
>          Components: NiFi Registry
>            Reporter: David Handermann
>            Assignee: David Handermann
>            Priority: Minor
>          Time Spent: 10m
>  Remaining Estimate: 0h
>
> The [elliptic|https://github.com/indutny/elliptic] library is a transitive 
> dependency of Webpack for NiFi Registry, used during development builds, and 
> should be upgraded to 6.6.0 to mitigate CVE-2024-48948 related to signature 
> verification. As this is a development build dependency, it does not impact 
> any runtime behavior.



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to