[ 
https://issues.apache.org/jira/browse/HBASE-30379?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=18116178#comment-18116178
 ] 

Hudson commented on HBASE-30379:
--------------------------------

Results for branch master
        [build #1501 on 
builds.a.o|https://ci-hbase.apache.org/job/HBase%20Nightly/job/master/1501/]: 
(/) *{color:green}+1 overall{color}*
----
details (if available):

(/) {color:green}+1 general checks{color}
-- For more information [see general 
report|https://ci-hbase.apache.org/job/HBase%20Nightly/job/master/1501/General_20Nightly_20Build_20Report/]








(/) {color:green}+1 jdk17 hadoop3 checks{color}
-- For more information [see jdk17 
report|https://ci-hbase.apache.org/job/HBase%20Nightly/job/master/1501/JDK17_20Nightly_20Build_20Report_20_28Hadoop3_29/]


> Update vulnerable website dependencies
> --------------------------------------
>
>                 Key: HBASE-30379
>                 URL: https://issues.apache.org/jira/browse/HBASE-30379
>             Project: HBase
>          Issue Type: Task
>          Components: dependabot, dependencies, security
>            Reporter: Dávid Paksy
>            Assignee: Dávid Paksy
>            Priority: Major
>              Labels: pull-request-available
>             Fix For: 4.0.0-alpha-1
>
>
> {noformat}
> # npm audit report
> @vitest/mocker  2.1.0 - 4.1.10
> Severity: moderate
> Vitest: Path Traversal / Arbitrary File Read via @vitest/mocker Redirect Mock 
> - https://github.com/advisories/GHSA-82fw-gwwq-j7x9
> fix available via `npm audit fix`
> node_modules/@vitest/mocker
>   vitest  2.1.0-beta.1 - 4.1.10
>   Depends on vulnerable versions of @vitest/mocker
>   node_modules/vitest
> js-yaml  4.0.0 - 4.3.1
> Severity: high
> js-yaml: maxTotalMergeKeys does not limit CPU use for empty merge sources - 
> https://github.com/advisories/GHSA-2883-xcg3-v3hh
> fix available via `npm audit fix`
> node_modules/js-yaml
> morgan  <1.12.0
> Severity: moderate
> morgan vulnerable to Log Forging via unescaped Unicode line separators - 
> https://github.com/advisories/GHSA-jxfw-x594-9x9m
> fix available via `npm audit fix`
> node_modules/morgan
> 4 vulnerabilities (3 moderate, 1 high)
> {noformat}



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to