[
https://issues.apache.org/jira/browse/HBASE-30379?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=18115629#comment-18115629
]
Hudson commented on HBASE-30379:
--------------------------------
Results for branch master
[build #172 on
builds.a.o|https://ci-hbase.apache.org/job/HBase-Integration-Test/job/master/172/]:
(/) *{color:green}+1 overall{color}*
----
details (if available):
(/) {color:green}+1 client integration test for 3.3.5 {color}
(/) {color:green}+1 client integration test for 3.3.5 with shaded hadoop
client{color}
(/) {color:green}+1 client integration test for 3.3.6 {color}
(/) {color:green}+1 client integration test for 3.3.6 with shaded hadoop
client{color}
(/) {color:green}+1 client integration test for 3.4.0 {color}
(/) {color:green}+1 client integration test for 3.4.0 with shaded hadoop
client{color}
(/) {color:green}+1 client integration test for 3.4.1 {color}
(/) {color:green}+1 client integration test for 3.4.1 with shaded hadoop
client{color}
(/) {color:green}+1 client integration test for 3.4.2 {color}
(/) {color:green}+1 client integration test for 3.4.2 with shaded hadoop
client{color}
(/) {color:green}+1 client integration test for 3.4.3 {color}
(/) {color:green}+1 client integration test for 3.4.3 with shaded hadoop
client{color}
> Update vulnerable website dependencies
> --------------------------------------
>
> Key: HBASE-30379
> URL: https://issues.apache.org/jira/browse/HBASE-30379
> Project: HBase
> Issue Type: Task
> Components: dependabot, dependencies, security
> Reporter: Dávid Paksy
> Assignee: Dávid Paksy
> Priority: Major
> Labels: pull-request-available
> Fix For: 4.0.0-alpha-1
>
>
> {noformat}
> # npm audit report
> @vitest/mocker 2.1.0 - 4.1.10
> Severity: moderate
> Vitest: Path Traversal / Arbitrary File Read via @vitest/mocker Redirect Mock
> - https://github.com/advisories/GHSA-82fw-gwwq-j7x9
> fix available via `npm audit fix`
> node_modules/@vitest/mocker
> vitest 2.1.0-beta.1 - 4.1.10
> Depends on vulnerable versions of @vitest/mocker
> node_modules/vitest
> js-yaml 4.0.0 - 4.3.1
> Severity: high
> js-yaml: maxTotalMergeKeys does not limit CPU use for empty merge sources -
> https://github.com/advisories/GHSA-2883-xcg3-v3hh
> fix available via `npm audit fix`
> node_modules/js-yaml
> morgan <1.12.0
> Severity: moderate
> morgan vulnerable to Log Forging via unescaped Unicode line separators -
> https://github.com/advisories/GHSA-jxfw-x594-9x9m
> fix available via `npm audit fix`
> node_modules/morgan
> 4 vulnerabilities (3 moderate, 1 high)
> {noformat}
--
This message was sent by Atlassian Jira
(v8.20.10#820010)