-
Notifications
You must be signed in to change notification settings - Fork 539
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Fix CVE in jsonpath-plus dep #1926
Comments
@brendanburns I've tried to run the release but the workflow isn't successful. The error message is:
Do you know what's wrong? Here is the log for the |
This is due to the npm token expiring, I will generate a new one and re-add it to the gh actions. |
@mstruebing this should now work. |
can we get also a release of the 1.x branch? |
And what's the ETA on the release of the 0.x line? |
@brendandburns thanks, npm release worked fine. I also released |
Describe the bug
The
jsonpath-plus
dependency contains a critical CVE:CVE-2024-21534
It is fixed (as least as far as "Snyk" scans are concerned) in
10.0.0
The request is to update the dependency in
@kubernetes/client-node
Client Version
0.22.0
(and earlier)Environment (please complete the following information):
The text was updated successfully, but these errors were encountered: