Skip to content

Comments

SK-2573: update outdated package ajv#675

Open
skyflow-himanshu wants to merge 1 commit intomainfrom
himanshu/SK-2573-policy-violation-policy-update-outdated-packages-js-sdk
Open

SK-2573: update outdated package ajv#675
skyflow-himanshu wants to merge 1 commit intomainfrom
himanshu/SK-2573-policy-violation-policy-update-outdated-packages-js-sdk

Conversation

@skyflow-himanshu
Copy link
Collaborator

Why:
The automated security alerting policy flagged a High severity vulnerability in an outdated version of the ajv package.
ajv has ReDoS when using $data option. This vulnerability was fixed in version 8.18.0

Goal:
Upgrade the transitive ajv dependency version 8.17.1 to 8.18.0, using npm overrides.

@github-actions
Copy link

Gitleaks Findings: No secrets detected. Safe to proceed!

@github-actions
Copy link

Semgrep Findings: Issues with Error level severity are found (Error is Highest severity in Semgrep), Please resolve the issues before merging.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant