Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Backport 1.3] [CVE-2022-48285][1.x] Bump jszip from 3.7.1 to 3.10.1 #4011

Merged
merged 1 commit into from
May 12, 2023

Conversation

opensearch-trigger-bot[bot]
Copy link
Contributor

Backport 364832d from #3740.

* [CVE-2022-48285][1.x] Bump jszip from 3.7.1 to 3.10.1

loadAsync in JSZip before 3.8.0 allows Directory Traversal
via a crafted ZIP archive. This CVE requires to bump jszip to
3.8.0+.

Signed-off-by: Anan Zhuang <[email protected]>

* remove unecessary resolution

remove yarn.lock entry, clean and bootstrap

Signed-off-by: Josh Romero <[email protected]>

---------

Signed-off-by: Anan Zhuang <[email protected]>
Signed-off-by: Josh Romero <[email protected]>
Co-authored-by: Josh Romero <[email protected]>
Co-authored-by: Sean Neumann <[email protected]>
(cherry picked from commit 364832d)
Signed-off-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>

# Conflicts:
#	CHANGELOG.md
@codecov
Copy link

codecov bot commented May 11, 2023

Codecov Report

Merging #4011 (fb657c2) into 1.3 (1253c47) will increase coverage by 0.00%.
The diff coverage is n/a.

@@           Coverage Diff           @@
##              1.3    #4011   +/-   ##
=======================================
  Coverage   67.49%   67.50%           
=======================================
  Files        3044     3044           
  Lines       58692    58692           
  Branches     8902     8902           
=======================================
+ Hits        39617    39619    +2     
+ Misses      16926    16925    -1     
+ Partials     2149     2148    -1     
Flag Coverage Δ
Linux 67.45% <ø> (+<0.01%) ⬆️
Windows 67.45% <ø> (+<0.01%) ⬆️

Flags with carried forward coverage won't be shown. Click here to find out more.

see 1 file with indirect coverage changes

@joshuarrrr joshuarrrr added v1.3.10 autocut Skip the changelog verification check on backports labels May 12, 2023
@kavilla kavilla merged commit 97a1ec1 into 1.3 May 12, 2023
@github-actions github-actions bot deleted the backport/backport-3740-to-1.3 branch May 12, 2023 19:50
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
autocut Skip the changelog verification check on backports v1.3.10
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants