Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Upgrade y18n package to v4.0.1 #3634

Closed
kyoto opened this issue Dec 17, 2020 · 3 comments
Closed

Upgrade y18n package to v4.0.1 #3634

kyoto opened this issue Dec 17, 2020 · 3 comments

Comments

@kyoto
Copy link
Contributor

kyoto commented Dec 17, 2020

Upgrade y18n package (used by the React UI) from v4.0.0 to v4.0.1, which fixes CVE-2020-7774.

See https://github.com/yargs/y18n/blob/v4/CHANGELOG.md#401-2020-11-30

(Issue is also fixed in y18n v5.0.5)

This is the same issue as prometheus/prometheus#8282

@kakkoyun
Copy link
Member

@kyoto Thanks for opening this. We should take care of it. Help wanted.
Also, it's curious that we haven't alerted by the dependabot?

@stale
Copy link

stale bot commented Feb 15, 2021

Hello 👋 Looks like there was no activity on this issue for the last two months.
Do you mind updating us on the status? Is this still reproducible or needed? If yes, just comment on this PR or push a commit. Thanks! 🤗
If there will be no activity in the next two weeks, this issue will be closed (we can always reopen an issue if we need!). Alternatively, use remind command if you wish to be reminded at some point in future.

@stale stale bot added the stale label Feb 15, 2021
@onprem onprem removed the stale label Feb 18, 2021
@kyoto
Copy link
Contributor Author

kyoto commented Mar 16, 2021

This was fixed by #3813

@kyoto kyoto closed this as completed Mar 16, 2021
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

3 participants