Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Bump dependency versions for azure-pipelines-tasks-azure-arm-rest package to fix vulnerability issues #338

Merged

Conversation

DenisNikulin5
Copy link
Contributor

In this PR I updated dependecies for azure-pipelines-tasks-azure-arm-rest package:

  1. typed-rest-client and azure-devops-node-api packages to fix https://nvd.nist.gov/vuln/detail/CVE-2022-24999
    See related PRs:
    Bump typed-rest-client to fix vulnerability issue with the qs package azure-devops-node-api#602
    Bump the qs version to fix vulnerability issue typed-rest-client#371

  2. jsonwebtoken package since there may be security issues associated with key encryption https://nvd.nist.gov/vuln/detail/CVE-2022-23541

azure-pipelines-tasks-azure-arm-rest version was bumped to 3.242.0

@DenisNikulin5 DenisNikulin5 requested review from manolerazvan and a team as code owners June 26, 2024 12:49
@DenisNikulin5 DenisNikulin5 merged commit 66ff442 into main Jun 26, 2024
6 checks passed
@DenisNikulin5 DenisNikulin5 deleted the users/v-denikulin/azure-arm-rest-vulnerability-issue-fix branch June 26, 2024 13:54
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

4 participants