Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Backport 2.x][Manual] Bump node version from 14.20.0 to 14.20.1 to resolve CVE-2022-35256 (#3166) #3188

Merged

Conversation

manasvinibs
Copy link
Member

Signed-off-by: Zilong Xia zilongx@amazon.com

  • Update the PR number in CHANGELOG

Signed-off-by: Zilong Xia zilongx@amazon.com

Signed-off-by: Zilong Xia zilongx@amazon.com
(cherry picked from commit 90b34f3)
Signed-off-by: Manasvini B Suryanarayana manasvis@amazon.com

Description

[Describe what this change achieves]

Issues Resolved

[List any issues this PR will resolve]

Check List

  • All tests pass
    • yarn test:jest
    • yarn test:jest_integration
    • yarn test:ftr
  • New functionality includes testing.
  • New functionality has been documented.
  • Update CHANGELOG.md
  • Commits are signed per the DCO using --signoff

@manasvinibs manasvinibs requested a review from a team as a code owner January 6, 2023 01:46
@manasvinibs manasvinibs added the v2.5.0 'Issues and PRs related to version v2.5.0' label Jan 6, 2023
@manasvinibs
Copy link
Member Author

@ZilongX Please take a look as I had to manually resolve conflicts in yarn.lock file related to loader-utils@^2.0.3 changes. Updated yarn.lock file after doing osd bootstrap.

@ZilongX
Copy link
Collaborator

ZilongX commented Jan 6, 2023

@manasvinibs some test checking is failing and we will need a re-rerun, code-wise it looks good to me :)

@codecov-commenter
Copy link

codecov-commenter commented Jan 6, 2023

Codecov Report

Merging #3188 (89bc90e) into 2.x (99353ea) will decrease coverage by 0.00%.
The diff coverage is n/a.

@@            Coverage Diff             @@
##              2.x    #3188      +/-   ##
==========================================
- Coverage   66.66%   66.65%   -0.01%     
==========================================
  Files        3219     3219              
  Lines       61531    61531              
  Branches     9431     9431              
==========================================
- Hits        41018    41012       -6     
- Misses      18275    18280       +5     
- Partials     2238     2239       +1     
Flag Coverage Δ
Linux 66.59% <ø> (-0.01%) ⬇️
Windows 66.60% <ø> (ø)

Flags with carried forward coverage won't be shown. Click here to find out more.

Impacted Files Coverage Δ
...s/osd-optimizer/src/node/node_auto_tranpilation.ts 83.67% <0.00%> (-4.09%) ⬇️
packages/osd-optimizer/src/node/cache.ts 51.31% <0.00%> (-2.64%) ⬇️
...ared/static/forms/hook_form_lib/hooks/use_field.ts 65.70% <0.00%> (-0.97%) ⬇️

Help us with your feedback. Take ten seconds to tell us how you rate us. Have a feature suggestion? Share it here.

…pensearch-project#3166)

* Bump node version from 14.20.0 to 14.20.1 to resolve CVE-2022-35256

Signed-off-by: Zilong Xia <zilongx@amazon.com>

* Update the PR number in CHANGELOG

Signed-off-by: Zilong Xia <zilongx@amazon.com>

Signed-off-by: Zilong Xia <zilongx@amazon.com>
(cherry picked from commit 90b34f3)
Signed-off-by: Manasvini B Suryanarayana <manasvis@amazon.com>
@abbyhu2000 abbyhu2000 merged commit cec8d1d into opensearch-project:2.x Jan 6, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
v2.5.0 'Issues and PRs related to version v2.5.0'
Projects
None yet
Development

Successfully merging this pull request may close these issues.

5 participants