Actions
Bug #22133
closedUpgrade dependencies to address current security advisories
Status:
Resolved
Priority:
Normal
Assigned To:
Category:
-
Target version:
Story points:
-
Release:
Release relationship:
Auto
Updated by Lucas Di Pentima over 1 year ago
- Status changed from New to In Progress
Updated by Brett Smith over 1 year ago
Please be careful not to re-revert 2f4fb1522c89c29a94854bf9f26fb6d13959f2d4. If dependabot identifies a specific security issue with the net-imap gem, please share details so we can figure out what we want to do about it.
Updated by Lucas Di Pentima over 1 year ago
Updates at a6da959 - branch 22133-dependency-upgrades
Test run: developer-run-tests: #4458
WB rerun: developer-run-tests-services-workbench2: #1171
- Go dependencies upgrade
github.com/docker/dockerfrom v26.1.3+incompatible to v26.1.5+incompatible to address CVE-2024-41110google.golang.org/grpcfrom v1.64.0 to v1.64.1 to mitigate a potential CWE-200
- Workbench dependencies upgrade
- Direct
webpackdompurifyellipticresolve-url-loaderwait-on
- Indirect
expressbracesmicromatchpostcss
- Direct
Updated by Lucas Di Pentima over 1 year ago
Update at 5617c02 - branch 22133-dependency-upgrades-part-deux
Test run: developer-run-tests-services-workbench2: #1179
Second pass of Workbench related dependency upgrades
- Upgrades
wsto address CVE-2024-37890 - Upgrades
socksto get a replacement for the vulnerableippackage - Upgrades
path-to-regexpwhere possible - Removes unused
lodash.template&lodash.mergewithpackages
Updated by Lucas Di Pentima over 1 year ago
- Status changed from In Progress to Resolved
Actions