Dávid Paksy created HBASE-30310:
-----------------------------------
Summary: Upgrade vulnerable website dependencies
Key: HBASE-30310
URL: https://issues.apache.org/jira/browse/HBASE-30310
Project: HBase
Issue Type: Bug
Components: dependabot, security, website
Reporter: Dávid Paksy
Dependabot identified some website dependencies with known CVE-s and opened
automated security update PR-s for them:
[https://github.com/apache/hbase/pulls?q=is%3Aopen+is%3Apr+author%3Aapp%2Fdependabot+label%3Ajavascript]
The React router CVE seems to have the biggest impact as it may require major
version upgrade which probably requires more work than just change the version
number.
--
This message was sent by Atlassian Jira
(v8.20.10#820010)