[ 
https://issues.apache.org/jira/browse/HBASE-30442?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=18121717#comment-18121717
 ] 

Hudson commented on HBASE-30442:
--------------------------------

Results for branch master
        [build #115 on 
builds.a.o|https://ci-hbase.apache.org/job/HBase-Backwards-Compatibility-Test/job/master/115/]:
 (/) *{color:green}+1 overall{color}*
----
Backwards compatibility checks:
(/) {color:green}+1 jdk17 hadoop 3.3.5 backward compatibility checks{color}
-- For more information [see jdk17 
report|https://ci-hbase.apache.org/job/HBase-Backwards-Compatibility-Test/job/master/115/console]


(/) {color:green}+1 jdk17 hadoop 3.3.6 backward compatibility checks{color}
-- For more information [see jdk17 
report|https://ci-hbase.apache.org/job/HBase-Backwards-Compatibility-Test/job/master/115/console]


(/) {color:green}+1 jdk17 hadoop 3.4.0 backward compatibility checks{color}
-- For more information [see jdk17 
report|https://ci-hbase.apache.org/job/HBase-Backwards-Compatibility-Test/job/master/115/console]


(/) {color:green}+1 jdk17 hadoop 3.4.1 backward compatibility checks{color}
-- For more information [see jdk17 
report|https://ci-hbase.apache.org/job/HBase-Backwards-Compatibility-Test/job/master/115/console]


(/) {color:green}+1 jdk17 hadoop 3.4.2 backward compatibility checks{color}
-- For more information [see jdk17 
report|https://ci-hbase.apache.org/job/HBase-Backwards-Compatibility-Test/job/master/115/console]


> Upgrade brace-expansion and fast-uri in website to fix known security 
> vulnerabilities
> -------------------------------------------------------------------------------------
>
>                 Key: HBASE-30442
>                 URL: https://issues.apache.org/jira/browse/HBASE-30442
>             Project: HBase
>          Issue Type: Task
>          Components: dependencies, security, website
>            Reporter: Dávid Paksy
>            Assignee: Dávid Paksy
>            Priority: Major
>              Labels: pull-request-available
>             Fix For: 4.0.0-alpha-1
>
>
> npm audit report before:
>  
> {noformat}
> # npm audit report
> brace-expansion  <=1.1.20 || 4.0.0 - 5.0.11
> Severity: high
> brace-expansion: Quadratic-time expansion of the `{a},b}` rewrite causes CPU 
> denial of service - https://github.com/advisories/GHSA-q2hr-2g5m-vwhr
> brace-expansion: Quadratic-time expansion of the `{a},b}` rewrite causes CPU 
> denial of service - https://github.com/advisories/GHSA-q2hr-2g5m-vwhr
> brace-expansion: DoS via uncontrolled recursion on nested brace groups 
> causing stack exhaustion - https://github.com/advisories/GHSA-qhr7-859c-m2p7
> brace-expansion: DoS via uncontrolled recursion on nested brace groups 
> causing stack exhaustion - https://github.com/advisories/GHSA-qhr7-859c-m2p7
> brace-expansion: DoS via uncontrolled recursion in parseCommaParts causing 
> stack exhaustion - https://github.com/advisories/GHSA-6j4f-fj2g-mc7p
> brace-expansion: DoS via uncontrolled recursion in parseCommaParts causing 
> stack exhaustion - https://github.com/advisories/GHSA-6j4f-fj2g-mc7p
> fix available via `npm audit fix`
> node_modules/brace-expansion
> node_modules/serve-handler/node_modules/brace-expansion
> fast-uri  3.0.0 - 3.1.7
> Severity: moderate
> fast-uri vulnerable to inconsistent host case normalization via 
> percent-encoded octets - https://github.com/advisories/GHSA-hrr3-gc8f-f4qj
> fix available via `npm audit fix`
> node_modules/fast-uri
> 2 vulnerabilities (1 moderate, 1 high)
> To address all issues, run:
>   npm audit fix
> {noformat}



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to