-
Notifications
You must be signed in to change notification settings - Fork 920
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[CVE-2024-28863] Bump node-tar from 6.1.11 to 6.2.1 #6876
Conversation
Signed-off-by: aggarwalShivani <[email protected]>
ℹ️ Manual Changeset Creation ReminderPlease ensure manual commit for changeset file 6876.yml under folder changelogs/fragments to complete this PR. If you want to use the available OpenSearch Changeset Bot App to avoid manual creation of changeset file you can install it in your forked repository following this link. For more information about formatting of changeset files, please visit OpenSearch Auto Changeset and Release Notes Tool. |
❌ Changeset File Not Added YetPlease ensure manual commit for changeset file 6876.yml under folder changelogs/fragments to complete this PR. File still missing. |
Signed-off-by: aggarwalShivani <[email protected]>
Codecov ReportAll modified and coverable lines are covered by tests ✅
Additional details and impacted files@@ Coverage Diff @@
## main #6876 +/- ##
==========================================
- Coverage 67.43% 67.36% -0.08%
==========================================
Files 3444 3444
Lines 67847 67847
Branches 11035 11035
==========================================
- Hits 45755 45706 -49
- Misses 19426 19469 +43
- Partials 2666 2672 +6
Flags with carried forward coverage won't be shown. Click here to find out more. ☔ View full report in Codecov by Sentry. |
❌ Changeset File Not Added YetPlease ensure manual commit for changeset file 6876.yml under folder changelogs/fragments to complete this PR. File still missing. |
❌ Changeset File Not Added YetPlease ensure manual commit for changeset file 6876.yml under folder changelogs/fragments to complete this PR. File still missing. |
❌ Invalid Prefix For Manual Changeset CreationInvalid description prefix. Found "security". Only "skip" entry option is permitted for manual commit of changeset files. If you were trying to skip the changelog entry, please use the "skip" entry option in the ##Changelog section of your PR description. |
Signed-off-by: aggarwalShivani <[email protected]>
❌ Changeset File Not Added YetPlease ensure manual commit for changeset file 6876.yml under folder changelogs/fragments to complete this PR. File still missing. |
@virajsanghvi Thanks for the approval previously. But i was getting errors related to Manual Changeset Creation, and as prompted, I have created the file now and repushed. Request you for approval :) |
Just FYI, looks like this was addressed independently in #6492 |
Description
This is to fix CVE-2024-28863 in main branch by bumping the version of node-tar dependency.
Issues Resolved
GHSA-f5x3-32g6-xq36
Changelog
Check List
yarn test:jest
yarn test:jest_integration