[
https://issues.apache.org/jira/browse/NIFI-13958?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17895050#comment-17895050
]
ASF subversion and git services commented on NIFI-13958:
--------------------------------------------------------
Commit 1f0fe2567d4961224dee68f22549d5147e693bf7 in nifi's branch
refs/heads/main from dependabot[bot]
[ https://gitbox.apache.org/repos/asf?p=nifi.git;h=1f0fe2567d ]
NIFI-13958 Upgraded elliptic from 6.5.7 to 6.6.0 for Registry (#9474)
Signed-off-by: David Handermann <[email protected]>
> Upgrade elliptic to 6.6.0 for Registry
> --------------------------------------
>
> Key: NIFI-13958
> URL: https://issues.apache.org/jira/browse/NIFI-13958
> Project: Apache NiFi
> Issue Type: Improvement
> Components: NiFi Registry
> Reporter: David Handermann
> Assignee: David Handermann
> Priority: Minor
> Time Spent: 10m
> Remaining Estimate: 0h
>
> The [elliptic|https://github.com/indutny/elliptic] library is a transitive
> dependency of Webpack for NiFi Registry, used during development builds, and
> should be upgraded to 6.6.0 to mitigate CVE-2024-48948 related to signature
> verification. As this is a development build dependency, it does not impact
> any runtime behavior.
--
This message was sent by Atlassian Jira
(v8.20.10#820010)