-
Notifications
You must be signed in to change notification settings - Fork 73
Open
Labels
help wantedDenotes an issue that needs help from a contributor. Must meet "help wanted" guidelines.Denotes an issue that needs help from a contributor. Must meet "help wanted" guidelines.
Description
What would you like to be added:
We need to update the dependencies version due to security concerns:
Dependencies in ui/apps/dashboard/pnpm-lock.yaml:
- Upgrade
cross-spawnto version 7.0.5 or later. - Upgrade
nanoidto version 3.3.8 or later. - Upgrade
rollupto version 4.22.4 or later. - Upgrade
axiosto version 1.7.4 or later. - Upgrade
viteto version 5.3.6 or later. - Upgrade
micromatchto version 4.0.8 or later.
Dependencies in go.mod
- Upgrade github.com/golang-jwt/jwt/v4 to version 4.5.1 or later. (@RainbowMango, [CVE-2024-51744] Bump jwt to v5.2.1 to address CVE concerns #158)
- Upgrade golang.org/x/crypto to version 0.31.0 or later. (@adwait-godbole, [CVE-2024-45337] [CVE-2024-45338] Bump
golang.org/x/cryptotov0.32.0andgolang.org/x/nettov0.34.0to address CVE concerns #185) - Upgrade golang.org/x/net to version 0.33.0 or later. (@adwait-godbole, [CVE-2024-45337] [CVE-2024-45338] Bump
golang.org/x/cryptotov0.32.0andgolang.org/x/nettov0.34.0to address CVE concerns #185)
Why is this needed:
Metadata
Metadata
Assignees
Labels
help wantedDenotes an issue that needs help from a contributor. Must meet "help wanted" guidelines.Denotes an issue that needs help from a contributor. Must meet "help wanted" guidelines.