Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Upgrade packages to fix npm audit vulnerabilities #3357

Merged
merged 1 commit into from
Oct 23, 2024

Conversation

dpanshug
Copy link
Contributor

This is not associated with any JIRA. This PR will address the CVEs reported by npm audit.

Description

This is a fix for vulnerabiliites reported by npm audit.

Frontend:

before
Screenshot 2024-10-22 at 1 40 14 PM

after
Screenshot 2024-10-22 at 1 40 32 PM

Backend:

before
Screenshot 2024-10-22 at 1 41 11 PM

after: (The remaining ones are the CVEs related to kubernetes/client-node)
Screenshot 2024-10-22 at 1 42 36 PM

How Has This Been Tested?

npm install
npm audit in both frontend and backend folder.

Test Impact

N/A

Request review criteria:

Self checklist (all need to be checked):

  • The developer has manually tested the changes and verified that the changes work
  • Testing instructions have been added in the PR body (for PRs involving changes that are not immediately obvious).
  • The developer has added tests or explained why testing cannot be added (unit or cypress tests for related changes)

If you have UI changes:

  • Included any necessary screenshots or gifs if it was a UI change.
  • Included tags to the UX team if it was a UI/UX change.

After the PR is posted & before it merges:

  • The developer has tested their solution on a cluster by using the image produced by the PR to main

Copy link
Contributor

openshift-ci bot commented Oct 22, 2024

Skipping CI for Draft Pull Request.
If you want CI signal for your change, please convert it to an actual PR.
You can still manually trigger a test run with /test all

@openshift-ci openshift-ci bot added the do-not-merge/work-in-progress This PR is in WIP state label Oct 22, 2024
@dpanshug dpanshug marked this pull request as ready for review October 22, 2024 08:21
@openshift-ci openshift-ci bot removed the do-not-merge/work-in-progress This PR is in WIP state label Oct 22, 2024
Copy link

codecov bot commented Oct 22, 2024

Codecov Report

All modified and coverable lines are covered by tests ✅

Project coverage is 85.04%. Comparing base (96e06a2) to head (65a992e).
Report is 10 commits behind head on main.

Additional details and impacted files

Impacted file tree graph

@@            Coverage Diff             @@
##             main    #3357      +/-   ##
==========================================
+ Coverage   85.01%   85.04%   +0.03%     
==========================================
  Files        1327     1327              
  Lines       29770    29770              
  Branches     8149     8149              
==========================================
+ Hits        25308    25319      +11     
+ Misses       4462     4451      -11     

see 4 files with indirect coverage changes


Continue to review full report in Codecov by Sentry.

Legend - Click here to learn more
Δ = absolute <relative> (impact), ø = not affected, ? = missing data
Powered by Codecov. Last update 96e06a2...65a992e. Read the comment docs.

Copy link
Member

@DaoDaoNoCode DaoDaoNoCode left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

/lgtm

@christianvogt
Copy link
Contributor

/approve

Copy link
Contributor

openshift-ci bot commented Oct 23, 2024

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: christianvogt, DaoDaoNoCode

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@openshift-merge-bot openshift-merge-bot bot merged commit b8ab455 into opendatahub-io:main Oct 23, 2024
8 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants