Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

fix(deps): Upgrade swagger-ui-react to v5.17.12. Fixes CVE-2024-45801 #13626

Merged
merged 5 commits into from
Sep 19, 2024

Conversation

terrytangyuan
Copy link
Member

@terrytangyuan terrytangyuan commented Sep 19, 2024

This fixes the following issue detected by Snyk https://security.snyk.io/vuln/SNYK-JS-DOMPURIFY-7984421:

  ✗ Prototype Pollution (new) [High Severity][https://security.snyk.io/vuln/SNYK-JS-DOMPURIFY-7984421] in dompurify@3.1.2
    introduced by swagger-ui-react@5.17.10 > dompurify@3.1.2

@terrytangyuan terrytangyuan enabled auto-merge (squash) September 19, 2024 13:10
Signed-off-by: Yuan Tang <terrytangyuan@gmail.com>
@agilgur5 agilgur5 changed the title fix(security): Upgrade swagger-ui-react to v5.17.12. Fixes CVE-2024-45801 fix(deps): Upgrade swagger-ui-react to v5.17.12. Fixes CVE-2024-45801 Sep 19, 2024
@agilgur5 agilgur5 added type/dependencies PRs and issues specific to updating dependencies javascript Pull requests that update Javascript dependencies labels Sep 19, 2024
Copy link
Member

@agilgur5 agilgur5 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@terrytangyuan your first commit is missing DCO. There's also an extraneous file here

yarn.lock Outdated Show resolved Hide resolved
@agilgur5 agilgur5 enabled auto-merge (squash) September 19, 2024 15:00
@agilgur5 agilgur5 added the type/security Security related label Sep 19, 2024
@agilgur5 agilgur5 merged commit dc731d0 into argoproj:main Sep 19, 2024
15 checks passed
@terrytangyuan terrytangyuan deleted the fix-swagger branch September 19, 2024 15:56
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
javascript Pull requests that update Javascript dependencies type/dependencies PRs and issues specific to updating dependencies type/security Security related
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants