Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

tileserver-gl/GHSA-rmvr-2pp2-xj38/GHSA-xx4v-prfh-6cgc/GHSA-h5c3-5r3r-rr8q advisory updates #13443

Merged
merged 2 commits into from
Feb 26, 2025
Merged
Changes from 1 commit
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
12 changes: 12 additions & 0 deletions tileserver-gl.advisories.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -69,6 +69,10 @@ advisories:
componentType: npm
componentLocation: /usr/src/app/node_modules/@octokit/plugin-paginate-rest/package.json
scanner: grype
- timestamp: 2025-02-26T18:50:59Z
type: pending-upstream-fix
data:
note: 'This CVE is a multi layered transitive dependency ultimately caused by the dependency @maplibre/maplibre-gl-native which tileserver-gl is on the latest version of. Further, the most recent version of the intermediary dependency node-pre-gyp-github, which @octokit/plugin-paginate-rest is a direct dependency of, also contains these old versions major versions (v2.x.x) the fix versions of this dependency are several major versions higher (v9.2.2 or v11.4.1) and will require upstream maintainers to implement. '

- id: CGA-cq9h-6cjg-vw9m
aliases:
Expand All @@ -87,6 +91,10 @@ advisories:
componentType: npm
componentLocation: /usr/src/app/node_modules/@octokit/request/package.json
scanner: grype
- timestamp: 2025-02-26T18:52:36Z
type: pending-upstream-fix
data:
note: 'This CVE is a multi layered transitive dependency ultimately caused by the dependency express 5.0.1 which tileserver-gl is on the latest version of. Further, the most recent version of the intermediary dependency Once 1.4.0 which @octokit/request is a direct dependency of, also contains these old versions major versions (v5.x.x) the fix versions of this dependency are several major versions higher (8.4.1or v9.2.1) and will require upstream maintainers to implement. '

- id: CGA-wm64-q84f-2hhv
aliases:
Expand All @@ -105,3 +113,7 @@ advisories:
componentType: npm
componentLocation: /usr/src/app/node_modules/@octokit/request-error/package.json
scanner: grype
- timestamp: 2025-02-26T18:52:08Z
type: pending-upstream-fix
data:
note: 'This CVE is a multi layered transitive dependency ultimately caused by the dependency @maplibre/maplibre-gl-native which tileserver-gl is on the latest version of. Further, the most recent version of the intermediary dependency node-pre-gyp-github, which @octokit/request-error is a direct dependency of, also contains these old versions major versions (v2.x.x) the fix versions of this dependency are several major versions higher (v5.1.1 or v6.1.7) and will require upstream maintainers to implement. '
Loading