[ 
https://issues.apache.org/jira/browse/NIFI-14773?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=18008868#comment-18008868
 ] 

ASF subversion and git services commented on NIFI-14773:
--------------------------------------------------------

Commit 484e9cc5e0efddf2a858ef0c7fc4cc7748312b1b in nifi's branch 
refs/heads/main from dependabot[bot]
[ https://gitbox.apache.org/repos/asf?p=nifi.git;h=484e9cc5e0 ]

NIFI-14773 Upgraded on-headers to 1.1.0 for NiFi Registry (#10103)

Bumps [on-headers](https://github.com/jshttp/on-headers) and 
[compression](https://github.com/expressjs/compression). These dependencies 
needed to be updated together.

Updates `on-headers` from 1.0.2 to 1.1.0
- [Release notes](https://github.com/jshttp/on-headers/releases)
- [Changelog](https://github.com/jshttp/on-headers/blob/master/HISTORY.md)
- [Commits](https://github.com/jshttp/on-headers/compare/v1.0.2...v1.1.0)

Updates `compression` from 1.7.4 to 1.8.1
- [Release notes](https://github.com/expressjs/compression/releases)
- [Changelog](https://github.com/expressjs/compression/blob/master/HISTORY.md)
- [Commits](https://github.com/expressjs/compression/compare/1.7.4...v1.8.1)

---
updated-dependencies:
- dependency-name: on-headers
  dependency-version: 1.1.0
  dependency-type: indirect
- dependency-name: compression
  dependency-version: 1.8.1
  dependency-type: indirect
...

Signed-off-by: David Handermann <[email protected]>

> Upgrade on-headers library to 1.1.0 for NiFi Registry
> -----------------------------------------------------
>
>                 Key: NIFI-14773
>                 URL: https://issues.apache.org/jira/browse/NIFI-14773
>             Project: Apache NiFi
>          Issue Type: Improvement
>            Reporter: David Handermann
>            Assignee: David Handermann
>            Priority: Minor
>          Time Spent: 10m
>  Remaining Estimate: 0h
>
> The JavaScript on-headers library for NiFi Registry UI development should be 
> upgraded to [1.1.0|https://github.com/jshttp/on-headers/releases/tag/v1.1.0] 
> to address CVE-2025-7339.



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to