Skip to content

Conversation

@kamilmadejek
Copy link
Collaborator

Fixes:

This PR overrides @kubernetes/client-node version to a one that does not depend on a jsonpath-plus package vulnerable to Remote Code Execution.

The library change does not appear to have an effect on application's functionality.

Copy link
Member

@liamfallon liamfallon left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

/approve

Thanks so much @kamilmadejek for rushing this out

@nephio-prow nephio-prow bot added the approved label Feb 13, 2025
@efiacor
Copy link
Collaborator

efiacor commented Feb 13, 2025

/approve
/lgtm

@nephio-prow
Copy link

nephio-prow bot commented Feb 13, 2025

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: efiacor, kamilmadejek, liamfallon

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@nephio-prow nephio-prow bot merged commit 456e4cf into nephio-project:main Feb 13, 2025
9 checks passed
@efiacor
Copy link
Collaborator

efiacor commented Feb 13, 2025

@kamilmadejek
Look like the vuln is still getting flagged for some reason.
https://github.com/nephio-project/kpt-backstage-plugins/security/dependabot/45

@kamilmadejek kamilmadejek deleted the 2025-02-13-dependency-fix branch February 13, 2025 16:52
@kamilmadejek
Copy link
Collaborator Author

@efiacor It's quite a coincidence because this is an unrelated new issue concerning an old dependency:

Published to the GitHub Advisory Database yesterday

It's actually so new that the local audit tool (built-in in npm/yarn) still does not report it. Fix for this one shouldn't be complicated, I will publish PR tomorrow first thing in the morning.

@efiacor
Copy link
Collaborator

efiacor commented Feb 13, 2025

@efiacor It's quite a coincidence because this is an unrelated new issue concerning an old dependency:

Published to the GitHub Advisory Database yesterday

It's actually so new that the local audit tool (built-in in npm/yarn) still does not report it. Fix for this one shouldn't be complicated, I will publish PR tomorrow first thing in the morning.

Perfect. Thank you sir!

@kamilmadejek
Copy link
Collaborator Author

kamilmadejek commented Feb 14, 2025

@efiacor New PR: #78

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants