Skip to content

Bump echarts to 6.1.0 to address CVE-2026-45249 - #527

Closed
dzane17 wants to merge 1 commit into
opensearch-project:mainfrom
dzane17:bump-echarts-cve-2026-45249
Closed

dzane17 wants to merge 1 commit into
opensearch-project:mainfrom
dzane17:bump-echarts-cve-2026-45249

Conversation

@dzane17

@dzane17 dzane17 commented May 27, 2026

Copy link
Copy Markdown
Member

Description

Bumps echarts from 6.0.0 to 6.1.0 to resolve CVE-2026-45249.

Issues Resolved

List any issues this PR will resolve, e.g. Closes [...].

By submitting this pull request, I confirm that my contribution is made under the terms of the Apache 2.0 license.
For more information on following Developer Certificate of Origin and signing off your commits, please check here.

Signed-off-by: David Zane <davizane@amazon.com>
@dzane17

dzane17 commented May 27, 2026

Copy link
Copy Markdown
Member Author

This PR is blocked until OSD is fixed

@dzane17

dzane17 commented May 27, 2026

Copy link
Copy Markdown
Member Author

@github-actions

github-actions Bot commented Jul 7, 2026

Copy link
Copy Markdown
Contributor

PR Code Analyzer ❗

AI-powered 'Code-Diff-Analyzer' found issues on commit 5aebfff.

PathLineSeverityDescription
package.json34highDependency version change: 'echarts' pinned from '^6.0.0' to exact version '6.1.0'. Version upgrades introduce new artifact hashes that cannot be verified here — maintainers must confirm this version exists on the official registry and was not injected.
yarn.lock1939highyarn.lock resolved URL and integrity hash for 'echarts' updated to 6.1.0. The new SHA-512 integrity hash (sha512-q0ya...) must be independently verified against the official npm registry to rule out a tampered artifact.
yarn.lock5448highyarn.lock resolved URL and integrity hash for transitive dependency 'zrender' updated from 6.0.0 to 6.1.0. This indirect dependency change was not reflected in package.json and its new integrity hash must be verified against the official npm registry.

The table above displays the top 10 most important findings.

Total: 3 | Critical: 0 | High: 3 | Medium: 0 | Low: 0


Pull Requests Author(s): Please update your Pull Request according to the report above.

Repository Maintainer(s): You can bypass diff analyzer by adding label skip-diff-analyzer after reviewing the changes carefully, then re-run failed actions. To re-enable the analyzer, remove the label, then re-run all actions.


⚠️ Note: The Code-Diff-Analyzer helps protect against potentially harmful code patterns. Please ensure you have thoroughly reviewed the changes beforehand.

Thanks.

@dzane17 dzane17 closed this Jul 7, 2026
@dzane17
dzane17 deleted the bump-echarts-cve-2026-45249 branch July 7, 2026 23:57
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant