Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[1.3] Bump debug and browserify-sign dependencies #1674

Merged
merged 1 commit into from
Nov 29, 2023

Conversation

derek-ho
Copy link
Collaborator

@derek-ho derek-ho commented Nov 28, 2023

Description

Bumps vulnerable dependency versions of browserify-sign and debug to fix:
CVE-2017-16137, CVE-2023-46234

Category

[Enhancement, New feature, Bug fix, Test fix, Refactoring, Maintenance, Documentation]

Why these changes are required?

What is the old behavior before changes and new behavior after changes?

Issues Resolved

[List any issues this PR will resolve (Is this a backport? If so, please add backport PR # and/or commits #)]

Testing

[Please provide details of testing done: unit testing, integration testing and manual testing]

Check List

  • New functionality includes testing
  • New functionality has been documented
  • Commits are signed per the DCO using --signoff

By submitting this pull request, I confirm that my contribution is made under the terms of the Apache 2.0 license.
For more information on following Developer Certificate of Origin and signing off your commits, please check here.

@derek-ho derek-ho changed the title Bump debug and browserify-sign dependencies [1.3] Bump debug and browserify-sign dependencies Nov 28, 2023
Copy link

codecov bot commented Nov 28, 2023

Codecov Report

All modified and coverable lines are covered by tests ✅

Comparison is base (e2b1424) 72.48% compared to head (ca46843) 72.48%.

Additional details and impacted files
@@           Coverage Diff           @@
##              1.3    #1674   +/-   ##
=======================================
  Coverage   72.48%   72.48%           
=======================================
  Files          88       88           
  Lines        1926     1926           
  Branches      246      246           
=======================================
  Hits         1396     1396           
  Misses        474      474           
  Partials       56       56           

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

@cwperks cwperks merged commit f861f46 into opensearch-project:1.3 Nov 29, 2023
8 checks passed
@leanneeliatra leanneeliatra mentioned this pull request Dec 8, 2023
3 tasks
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants