-
Notifications
You must be signed in to change notification settings - Fork 906
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[CVE-2024-37890] Bump ws from 8.5.0
to 8.17.1
and from 7.5.7
to 7.5.10
#7153
Conversation
Signed-off-by: Anan Zhuang <[email protected]>
Codecov ReportAll modified and coverable lines are covered by tests ✅
Additional details and impacted files@@ Coverage Diff @@
## main #7153 +/- ##
==========================================
+ Coverage 67.47% 67.49% +0.01%
==========================================
Files 3468 3468
Lines 68366 68366
Branches 11110 11110
==========================================
+ Hits 46133 46145 +12
+ Misses 19579 19522 -57
- Partials 2654 2699 +45
Flags with carried forward coverage won't be shown. Click here to find out more. ☔ View full report in Codecov by Sentry. |
… `7.5.10` (#7153) * Bump ws from 8.5.0 to 8.17.1 and from 7.5.7 to 7.5.10 Signed-off-by: Anan Zhuang <[email protected]> * Changeset file for PR #7153 created/updated --------- Signed-off-by: Anan Zhuang <[email protected]> Co-authored-by: opensearch-changeset-bot[bot] <154024398+opensearch-changeset-bot[bot]@users.noreply.github.com> Co-authored-by: ZilongX <[email protected]> (cherry picked from commit 5e19749) Signed-off-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
… `7.5.10` (#7153) (#7158) * Bump ws from 8.5.0 to 8.17.1 and from 7.5.7 to 7.5.10 * Changeset file for PR #7153 created/updated --------- (cherry picked from commit 5e19749) Signed-off-by: Anan Zhuang <[email protected]> Signed-off-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com> Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com> Co-authored-by: opensearch-changeset-bot[bot] <154024398+opensearch-changeset-bot[bot]@users.noreply.github.com> Co-authored-by: ZilongX <[email protected]>
Hello @ananzh, Will this fix be back-ported in 2.15? Thanks. |
Description
https://nvd.nist.gov/vuln/detail/CVE-2024-37890 requests to bump ws from
8.5.0
to8.17.1
and from7.5.7
to7.5.10
Screenshot
Changelog
8.5.0
to8.17.1
and from7.5.7
to7.5.10
Check List
yarn test:jest
yarn test:jest_integration