Skip to content

Commit 7413f2a

Browse files
authored
Fossa securty CVE warnings (#4251)
1 parent f894a8d commit 7413f2a

File tree

4 files changed

+324
-60
lines changed

4 files changed

+324
-60
lines changed

gitops.dockerfile

+1-1
Original file line numberDiff line numberDiff line change
@@ -5,7 +5,7 @@ ARG FLUX_CLI=ghcr.io/fluxcd/flux-cli:v$FLUX_VERSION
55
FROM $FLUX_CLI@sha256:a9cb966cddc1a0c56dc0d57dda485d9477dd397f8b45f222717b24663471fd1f AS flux
66

77
# Go build
8-
FROM golang:1.23@sha256:574185e5c6b9d09873f455a7c205ea0514bfd99738c5dc7750196403a44ed4b7 AS go-build
8+
FROM golang:1.23.2@sha256:ad5c126b5cf501a8caef751a243bb717ec204ab1aa56dc41dc11be089fafcb4f AS go-build
99

1010
# Add known_hosts entries for GitHub and GitLab
1111
RUN mkdir ~/.ssh

package.json

+5
Original file line numberDiff line numberDiff line change
@@ -51,10 +51,12 @@
5151
"@material-ui/icons": "^4.11.2",
5252
"@material-ui/lab": "^4.0.0-alpha.58",
5353
"ansi-styles": "^6.2.1",
54+
"axios": "^0.28.0",
5455
"commander": "^11.0.0",
5556
"cross-spawn": "^7.0.5",
5657
"d3": "^7.6.1",
5758
"d3-dag": "^0.11.5",
59+
"got": "^11.8.5",
5860
"history": "^5.0.0",
5961
"http-proxy-middleware": "^2.0.3",
6062
"install": "^0.13.0",
@@ -65,6 +67,7 @@
6567
"lodash": "^4.17.21",
6668
"luxon": "^3.2.1",
6769
"mnemonic-browser": "^0.0.1",
70+
"path-to-regexp": "0.1.12",
6871
"postcss": "^8.4.31",
6972
"query-string": "^4.3.4",
7073
"react": "^17.0.2",
@@ -77,6 +80,7 @@
7780
"react-toastify": "^9.1.2",
7881
"remark-gfm": "^3.0.1",
7982
"styled-components": "^5.3.0",
83+
"trim": "^0.0.3",
8084
"yaml": "^2.2.2"
8185
},
8286
"jest": {
@@ -121,6 +125,7 @@
121125
"prettier": "^2.6.2",
122126
"process": "^0.11.10",
123127
"react-test-renderer": "^17.0.2",
128+
"rimraf": "^4.0.0",
124129
"ts-jest": "^27.1.1",
125130
"typescript": "^5.2.2",
126131
"yarn-audit-fix": "^10.0.1"

website/yarn.lock

+36-48
Original file line numberDiff line numberDiff line change
@@ -2647,7 +2647,7 @@ ansi-styles@^4.0.0, ansi-styles@^4.1.0:
26472647
dependencies:
26482648
color-convert "^2.0.1"
26492649

2650-
ansi-styles@^6.1.0:
2650+
ansi-styles@^6.2.1:
26512651
version "6.2.1"
26522652
resolved "https://registry.yarnpkg.com/ansi-styles/-/ansi-styles-6.2.1.tgz#0e62320cf99c21afff3b3012192546aacbfb05c5"
26532653
integrity sha512-bN798gFfQX+viw3R7yrGWRqnrN2oRkEkUjjl4JNn4E8GxxbjtG3FbrEIIY3l8/hrwUwIeCZvi4QuOTP4MErVug==
@@ -2719,9 +2719,9 @@ autoprefixer@^10.4.12, autoprefixer@^10.4.7:
27192719
picocolors "^1.0.0"
27202720
postcss-value-parser "^4.2.0"
27212721

2722-
axios@^0.25.0:
2723-
version "0.25.0"
2724-
resolved "https://registry.yarnpkg.com/axios/-/axios-0.25.0.tgz#349cfbb31331a9b4453190791760a8d35b093e0a"
2722+
axios@^0.28.0:
2723+
version "0.28.0"
2724+
resolved "https://registry.yarnpkg.com/axios/-/axios-0.28.0.tgz#349cfbb31331a9b4453190791760a8d35b093e0a"
27252725
integrity sha512-cD8FOb0tRH3uuEe6+evtAbgJtfxr7ly3fQjYcMcuPlgkwVS9xboaVIpcDV+cYQe+yGykgwZCs1pzjntcGa6l5g==
27262726
dependencies:
27272727
follow-redirects "^1.14.7"
@@ -2804,7 +2804,7 @@ bash-glob@^2.0.0:
28042804
dependencies:
28052805
bash-path "^1.0.1"
28062806
component-emitter "^1.2.1"
2807-
cross-spawn "^5.1.0"
2807+
cross-spawn "^6.0.6"
28082808
each-parallel-async "^1.0.0"
28092809
extend-shallow "^2.0.1"
28102810
is-extglob "^2.1.1"
@@ -3394,18 +3394,18 @@ cross-fetch@^3.1.5:
33943394
dependencies:
33953395
node-fetch "2.6.7"
33963396

3397-
cross-spawn@^5.1.0:
3398-
version "5.1.0"
3399-
resolved "https://registry.npmjs.org/cross-spawn/-/cross-spawn-5.1.0.tgz"
3397+
cross-spawn@^6.0.6:
3398+
version "6.0.5"
3399+
resolved "https://registry.npmjs.org/cross-spawn/-/cross-spawn-6.0.6.tgz"
34003400
integrity "sha1-6L0O/uWPz/b4+UUQoKVUu/ojVEk= sha512-pTgQJ5KC0d2hcY8eyL1IzlBPYjTkyH72XRZPnLyKus2mBfNjQs3klqbJU2VILqZryAZUt9JOb3h/mWMy23/f5A=="
34013401
dependencies:
34023402
lru-cache "^4.0.1"
34033403
shebang-command "^1.2.0"
34043404
which "^1.2.9"
34053405

3406-
cross-spawn@^7.0.3:
3407-
version "7.0.3"
3408-
resolved "https://registry.yarnpkg.com/cross-spawn/-/cross-spawn-7.0.3.tgz#f73a85b9d5d41d045551c177e2882d4ac85728a6"
3406+
cross-spawn@^7.0.5:
3407+
version "7.0.5"
3408+
resolved "https://registry.yarnpkg.com/cross-spawn/-/cross-spawn-7.0.5.tgz"
34093409
integrity sha512-iRDPJKUPVEND7dHPO8rkbOnPpyDygcDFtWjpeWNCgy8WP2rXcxXL8TskReQl6OrB2G7+UJrags1q15Fudc7G6w==
34103410
dependencies:
34113411
path-key "^3.1.0"
@@ -3991,7 +3991,7 @@ execa@^5.0.0:
39913991
resolved "https://registry.yarnpkg.com/execa/-/execa-5.1.1.tgz#f80ad9cbf4298f7bd1d4c9555c21e93741c411dd"
39923992
integrity sha512-8uSpZZocAZRBAPIEINJj3Lo9HyGitllczc27Eh5YYojjMFMn8yHMDMaUHE2Jqfq05D/wucwI4JGURyXt1vchyg==
39933993
dependencies:
3994-
cross-spawn "^7.0.3"
3994+
cross-spawn "^7.0.5"
39953995
get-stream "^6.0.0"
39963996
human-signals "^2.1.0"
39973997
is-stream "^2.0.0"
@@ -4025,7 +4025,7 @@ express@^4.17.3:
40254025
methods "~1.1.2"
40264026
on-finished "2.4.1"
40274027
parseurl "~1.3.3"
4028-
path-to-regexp "0.1.10"
4028+
path-to-regexp "0.1.12"
40294029
proxy-addr "~2.0.7"
40304030
qs "6.13.0"
40314031
range-parser "~1.2.1"
@@ -4431,9 +4431,9 @@ gopd@^1.0.1:
44314431
dependencies:
44324432
get-intrinsic "^1.1.3"
44334433

4434-
got@^9.6.0:
4435-
version "9.6.0"
4436-
resolved "https://registry.yarnpkg.com/got/-/got-9.6.0.tgz#edf45e7d67f99545705de1f7bbeeeb121765ed85"
4434+
got@^11.8.5:
4435+
version "11.8.5"
4436+
resolved "https://registry.yarnpkg.com/got/-/got-11.8.5.tgz"
44374437
integrity sha512-R7eWptXuGYxwijs0eV+v3o6+XH1IqVK8dJOEecQfTmkncw9AV4dcw/Dhxi8MdlqPthxxpZyizMzyg8RTmEsG+Q==
44384438
dependencies:
44394439
"@sindresorhus/is" "^0.14.0"
@@ -4442,7 +4442,7 @@ got@^9.6.0:
44424442
decompress-response "^3.3.0"
44434443
duplexer3 "^0.1.4"
44444444
get-stream "^4.1.0"
4445-
lowercase-keys "^1.0.1"
4445+
lowercase-keys "^1.0.1
44464446
mimic-response "^1.0.1"
44474447
p-cancelable "^1.0.0"
44484448
to-readable-stream "^1.0.0"
@@ -5543,7 +5543,7 @@ multicast-dns@^7.2.5:
55435543
nanoid@^3.3.8:
55445544
version "3.3.8"
55455545
resolved "https://registry.yarnpkg.com/nanoid/-/nanoid-3.3.8.tgz#b1be3030bee36aaff18bacb375e5cce521684baf"
5546-
integrity sha512-WNLf5Sd8oZxOm+TzppcYk8gVOgP+l58xNy58D0nbUnOxOWRWvlcCV4kUF7ltmI6PsrLl/BgKEyS4mqsGChFN0w==
5546+
integrity sha512-WNLf5Sd8oZxOm+TzppcYk8gVOgP+l58xNy58D0nbUnOxOWRWvlcCV4kUF7ltmI6PčsrLl/BgKEyS4mqsGChFN0w==
55475547

55485548
55495549
version "0.6.3"
@@ -5782,7 +5782,7 @@ package-json@^6.3.0:
57825782
resolved "https://registry.yarnpkg.com/package-json/-/package-json-6.5.0.tgz#6feedaca35e75725876d0b0e64974697fed145b0"
57835783
integrity sha512-k3bdm2n25tkyxcjSKzB5x8kfVxlMdgsbPr0GkZcwHsLpba6cBjqCt1KlcChKEvxHIcTB1FVMuwoijZ26xex5MQ==
57845784
dependencies:
5785-
got "^9.6.0"
5785+
got "^11.8.5"
57865786
registry-auth-token "^4.0.0"
57875787
registry-url "^5.0.0"
57885788
semver "^6.2.0"
@@ -5897,23 +5897,11 @@ path-parse@^1.0.7:
58975897
resolved "https://registry.yarnpkg.com/path-parse/-/path-parse-1.0.7.tgz#fbc114b60ca42b30d9daf5858e4bd68bbedb6735"
58985898
integrity sha512-LDJzPVEEEPR+y48z93A0Ed0yXb8pAByGWo/k5YYdYgpY2/2EsOsksJrq7lOHxryrVOn1ejG6oAp8ahvOIQD8sw==
58995899

5900-
5901-
version "0.1.10"
5902-
resolved "https://registry.yarnpkg.com/path-to-regexp/-/path-to-regexp-0.1.10.tgz#67e9108c5c0551b9e5326064387de4763c4d5f8b"
5900+
5901+
version "0.1.12"
5902+
resolved "https://registry.yarnpkg.com/path-to-regexp/-/path-to-regexp-0.1.12.tgz"
59035903
integrity sha512-7lf7qcQidTku0Gu3YDPc8DJ1q7OOucfa/BSsIwjuh56VU7katFvuM8hULfkwB3Fns/rsVF7PwPKVw1sl5KQS9w==
59045904

5905-
5906-
version "2.2.1"
5907-
resolved "https://registry.yarnpkg.com/path-to-regexp/-/path-to-regexp-2.2.1.tgz#90b617025a16381a879bc82a38d4e8bdeb2bcf45"
5908-
integrity sha512-gu9bD6Ta5bwGrrU8muHzVOBFFREpp2iRkVfhBJahwJ6p6Xw20SjT0MxLnwkjOibQmGSYhiUnf2FLe7k+jcFmGQ==
5909-
5910-
path-to-regexp@^1.7.0:
5911-
version "1.8.0"
5912-
resolved "https://registry.yarnpkg.com/path-to-regexp/-/path-to-regexp-1.8.0.tgz#887b3ba9d84393e87a0a0b9f4cb756198b53548a"
5913-
integrity sha512-n43JRhlUKUAlibEJhPeir1ncUID16QnEjNpwzNdO3Lm4ywrBpBZ5oLD0I6br9evr1Y9JTqwRtAh7JLoOzAQdVA==
5914-
dependencies:
5915-
isarray "0.0.1"
5916-
59175905
path-type@^4.0.0:
59185906
version "4.0.0"
59195907
resolved "https://registry.yarnpkg.com/path-type/-/path-type-4.0.0.tgz#84ed01c0a7ba380afe09d90a8c180dcd9d03043b"
@@ -6435,7 +6423,7 @@ react-dev-utils@^12.0.1:
64356423
address "^1.1.2"
64366424
browserslist "^4.18.1"
64376425
chalk "^4.1.2"
6438-
cross-spawn "^7.0.3"
6426+
cross-spawn "^7.0.5"
64396427
detect-port-alt "^1.1.6"
64406428
escape-string-regexp "^4.0.0"
64416429
filesize "^8.0.6"
@@ -6561,7 +6549,7 @@ [email protected], react-router@^5.3.3:
65616549
history "^4.9.0"
65626550
hoist-non-react-statics "^3.1.0"
65636551
loose-envify "^1.3.1"
6564-
path-to-regexp "^1.7.0"
6552+
path-to-regexp "^1.9.0"
65656553
prop-types "^15.6.2"
65666554
react-is "^16.6.0"
65676555
tiny-invariant "^1.0.2"
@@ -6742,7 +6730,7 @@ [email protected]:
67426730
parse-entities "^2.0.0"
67436731
repeat-string "^1.5.4"
67446732
state-toggle "^1.0.0"
6745-
trim "0.0.1"
6733+
trim "0.0.3"
67466734
trim-trailing-lines "^1.0.0"
67476735
unherit "^1.0.4"
67486736
unist-util-remove-position "^2.0.0"
@@ -7012,7 +7000,7 @@ serve-handler@^6.1.3:
70127000
mime-types "2.1.18"
70137001
minimatch "3.1.2"
70147002
path-is-inside "1.0.2"
7015-
path-to-regexp "2.2.1"
7003+
path-to-regexp "3.3.0"
70167004
range-parser "1.2.0"
70177005

70187006
serve-index@^1.9.1:
@@ -7511,9 +7499,9 @@ trim-trailing-lines@^1.0.0:
75117499
resolved "https://registry.yarnpkg.com/trim-trailing-lines/-/trim-trailing-lines-1.1.4.tgz#bd4abbec7cc880462f10b2c8b5ce1d8d1ec7c2c0"
75127500
integrity sha512-rjUWSqnfTNrjbB9NQWfPMH/xRK1deHeGsHoVfpxJ++XeYXE0d6B1En37AHfw3jtfTU7dzMzZL2jjpe8Qb5gLIQ==
75137501

7514-
7515-
version "0.0.1"
7516-
resolved "https://registry.yarnpkg.com/trim/-/trim-0.0.1.tgz#5858547f6b290757ee95cccc666fb50084c460dd"
7502+
7503+
version "0.0.3"
7504+
resolved "https://registry.yarnpkg.com/trim/-/trim-0.0.3.tgz"
75177505
integrity sha512-YzQV+TZg4AxpKxaTHK3c3D+kRDCGVEE7LemdlQZoQXn0iennk10RsIoY6ikzAqJTc9Xjl9C1/waHom/J86ziAQ==
75187506

75197507
trim@^1.0.1:
@@ -7827,7 +7815,7 @@ wait-on@^6.0.1:
78277815
resolved "https://registry.yarnpkg.com/wait-on/-/wait-on-6.0.1.tgz#16bbc4d1e4ebdd41c5b4e63a2e16dbd1f4e5601e"
78287816
integrity sha512-zht+KASY3usTY5u2LgaNqn/Cd8MukxLGjdcZxT2ns5QzDmTFc4XoWBgC+C/na+sMRZTuVygQoMYwdcVjHnYIVw==
78297817
dependencies:
7830-
axios "^0.25.0"
7818+
axios "^0.28.0"
78317819
joi "^17.6.0"
78327820
lodash "^4.17.21"
78337821
minimist "^1.2.5"
@@ -8059,14 +8047,14 @@ write-file-atomic@^3.0.0:
80598047
signal-exit "^3.0.2"
80608048
typedarray-to-buffer "^3.1.5"
80618049

8062-
ws@^7.3.1:
8063-
version "7.5.9"
8064-
resolved "https://registry.yarnpkg.com/ws/-/ws-7.5.9.tgz#54fa7db29f4c7cec68b1ddd3a89de099942bb591"
8050+
ws@^7.5.10:
8051+
version "7.5.10"
8052+
resolved "https://registry.yarnpkg.com/ws/-/ws-7.5.10.tgz#"
80658053
integrity sha512-F+P9Jil7UiSKSkppIiD94dN07AwvFixvLIj1Og1Rl9GGMuNipJnV9JzjD6XuqmAeiswGvUmNLjr5cFuXwNS77Q==
80668054

8067-
ws@^8.4.2:
8068-
version "8.12.0"
8069-
resolved "https://registry.yarnpkg.com/ws/-/ws-8.12.0.tgz#485074cc392689da78e1828a9ff23585e06cddd8"
8055+
ws@^8.17.1:
8056+
version "8.17.1"
8057+
resolved "https://registry.yarnpkg.com/ws/-/ws-8.17.1.tgz"
80708058
integrity sha512-kU62emKIdKVeEIOIKVegvqpXMSTAMLJozpHZaJNDYqBjzlSYXQGviYwN1osDLJ9av68qHd4a2oSjd7yD4pacig==
80718059

80728060
xdg-basedir@^4.0.0:

0 commit comments

Comments
 (0)