Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[CVE] Upgrade JSON5 to 2.2.2 #166

Closed
seanneumann opened this issue Dec 29, 2022 · 1 comment · Fixed by #179
Closed

[CVE] Upgrade JSON5 to 2.2.2 #166

seanneumann opened this issue Dec 29, 2022 · 1 comment · Fixed by #179
Assignees
Labels
bug Something isn't working Mend: dependency security vulnerability Security vulnerability detected by Mend

Comments

@seanneumann
Copy link
Contributor

Please upgrade json5 to 2.2.2 to address a HIGH security vulnerability.

https://github.com/opensearch-project/oui/blob/main/yarn.lock#L74

See similar issue in OpenSearch Dashboards repo for more details:

opensearch-project/OpenSearch-Dashboards#3148

@seanneumann seanneumann added bug Something isn't working Mend: dependency security vulnerability Security vulnerability detected by Mend v2.5.0 labels Dec 29, 2022
@BSFishy BSFishy self-assigned this Dec 30, 2022
@BSFishy BSFishy linked a pull request Dec 30, 2022 that will close this issue
6 tasks
@seanneumann
Copy link
Contributor Author

Thanks @BSFishy

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Something isn't working Mend: dependency security vulnerability Security vulnerability detected by Mend
Projects
None yet
Development

Successfully merging a pull request may close this issue.

2 participants