Skip to content

Commit 734f8ed

Browse files
authored
fix(sec): resolve Dependabot security alerts (apache#32274)
1 parent dcc9628 commit 734f8ed

File tree

6 files changed

+58
-82
lines changed

6 files changed

+58
-82
lines changed

docs/yarn.lock

Lines changed: 31 additions & 57 deletions
Original file line numberDiff line numberDiff line change
@@ -4227,10 +4227,10 @@ [email protected]:
42274227
resolved "https://registry.yarnpkg.com/cookie-signature/-/cookie-signature-1.0.6.tgz#e303a882b342cc3ee8ca513a79999734dab3ae2c"
42284228
integrity sha512-QADzlaHc8icV8I7vbaJXJwod9HWYp8uCqf1xa4OfNu1T7JVxQIrUgOWtHdNDtPiywmFbiS12VjotIXLrKM3orQ==
42294229

4230-
cookie@0.6.0:
4231-
version "0.6.0"
4232-
resolved "https://registry.yarnpkg.com/cookie/-/cookie-0.6.0.tgz#2798b04b071b0ecbff0dbb62a505a8efa4e19051"
4233-
integrity sha512-U71cyTamuh1CRNCfpGY6to28lxvNwPG4Guz/EVjgf3Jmzv0vlDp1atT9eS5dDjMYHucpHbWns6Lwf3BKz6svdw==
4230+
cookie@0.7.1:
4231+
version "0.7.1"
4232+
resolved "https://registry.yarnpkg.com/cookie/-/cookie-0.7.1.tgz#2f73c42142d5d5cf71310a74fc4ae61670e5dbc9"
4233+
integrity sha512-6DnInpx7SJ2AK3+CTUE/ZM0vWTUboZCegxhC2xiIydHR9jNuTAASBrfEpHhiGOZw/nX51bHt6YQl8jsGo4y/0w==
42344234

42354235
cookie@~0.7.2:
42364236
version "0.7.2"
@@ -5027,36 +5027,36 @@ execa@^5.0.0:
50275027
strip-final-newline "^2.0.0"
50285028

50295029
express@^4.17.3:
5030-
version "4.20.0"
5031-
resolved "https://registry.yarnpkg.com/express/-/express-4.20.0.tgz#f1d08e591fcec770c07be4767af8eb9bcfd67c48"
5032-
integrity sha512-pLdae7I6QqShF5PnNTCVn4hI91Dx0Grkn2+IAsMTgMIKuQVte2dN9PeGSSAME2FR8anOhVA62QDIUaWVfEXVLw==
5030+
version "4.21.2"
5031+
resolved "https://registry.yarnpkg.com/express/-/express-4.21.2.tgz#cf250e48362174ead6cea4a566abef0162c1ec32"
5032+
integrity sha512-28HqgMZAmih1Czt9ny7qr6ek2qddF4FclbMzwhCREB6OFfH+rXAnuNCwo1/wFvrtbgsQDb4kSbX9de9lFbrXnA==
50335033
dependencies:
50345034
accepts "~1.3.8"
50355035
array-flatten "1.1.1"
50365036
body-parser "1.20.3"
50375037
content-disposition "0.5.4"
50385038
content-type "~1.0.4"
5039-
cookie "0.6.0"
5039+
cookie "0.7.1"
50405040
cookie-signature "1.0.6"
50415041
debug "2.6.9"
50425042
depd "2.0.0"
50435043
encodeurl "~2.0.0"
50445044
escape-html "~1.0.3"
50455045
etag "~1.8.1"
5046-
finalhandler "1.2.0"
5046+
finalhandler "1.3.1"
50475047
fresh "0.5.2"
50485048
http-errors "2.0.0"
50495049
merge-descriptors "1.0.3"
50505050
methods "~1.1.2"
50515051
on-finished "2.4.1"
50525052
parseurl "~1.3.3"
5053-
path-to-regexp "0.1.10"
5053+
path-to-regexp "0.1.12"
50545054
proxy-addr "~2.0.7"
5055-
qs "6.11.0"
5055+
qs "6.13.0"
50565056
range-parser "~1.2.1"
50575057
safe-buffer "5.2.1"
50585058
send "0.19.0"
5059-
serve-static "1.16.0"
5059+
serve-static "1.16.2"
50605060
setprototypeof "1.2.0"
50615061
statuses "2.0.1"
50625062
type-is "~1.6.18"
@@ -5163,13 +5163,13 @@ fill-range@^7.1.1:
51635163
dependencies:
51645164
to-regex-range "^5.0.1"
51655165

5166-
finalhandler@1.2.0:
5167-
version "1.2.0"
5168-
resolved "https://registry.yarnpkg.com/finalhandler/-/finalhandler-1.2.0.tgz#7d23fe5731b207b4640e4fcd00aec1f9207a7b32"
5169-
integrity sha512-5uXcUVftlQMFnWC9qu/svkWv3GTd2PfUhK/3PLkYNAe7FbqJMt3515HaxE6eRL74GdsriiwujiawdaB1BpEISg==
5166+
finalhandler@1.3.1:
5167+
version "1.3.1"
5168+
resolved "https://registry.yarnpkg.com/finalhandler/-/finalhandler-1.3.1.tgz#0c575f1d1d324ddd1da35ad7ece3df7d19088019"
5169+
integrity sha512-6BN9trH7bp3qvnrRyzsBz+g3lZxTNZTbVO2EV1CS0WIcDbawYVdYvGflME/9QP0h0pYlCDBCTjYa9nZzMDpyxQ==
51705170
dependencies:
51715171
debug "2.6.9"
5172-
encodeurl "~1.0.2"
5172+
encodeurl "~2.0.0"
51735173
escape-html "~1.0.3"
51745174
on-finished "2.4.1"
51755175
parseurl "~1.3.3"
@@ -7713,20 +7713,20 @@ path-parse@^1.0.7:
77137713
resolved "https://registry.yarnpkg.com/path-parse/-/path-parse-1.0.7.tgz#fbc114b60ca42b30d9daf5858e4bd68bbedb6735"
77147714
integrity sha512-LDJzPVEEEPR+y48z93A0Ed0yXb8pAByGWo/k5YYdYgpY2/2EsOsksJrq7lOHxryrVOn1ejG6oAp8ahvOIQD8sw==
77157715

7716-
7717-
version "0.1.10"
7718-
resolved "https://registry.yarnpkg.com/path-to-regexp/-/path-to-regexp-0.1.10.tgz#67e9108c5c0551b9e5326064387de4763c4d5f8b"
7719-
integrity sha512-7lf7qcQidTku0Gu3YDPc8DJ1q7OOucfa/BSsIwjuh56VU7katFvuM8hULfkwB3Fns/rsVF7PwPKVw1sl5KQS9w==
7716+
7717+
version "0.1.12"
7718+
resolved "https://registry.yarnpkg.com/path-to-regexp/-/path-to-regexp-0.1.12.tgz#d5e1a12e478a976d432ef3c58d534b9923164bb7"
7719+
integrity sha512-RA1GjUVMnvYFxuqovrEqZoxxW5NUZqbwKtYz/Tt7nXerk0LbLblQmrsgdeOxV5SFHf0UDggjS/bSeOZwt1pmEQ==
77207720

77217721
77227722
version "2.2.1"
77237723
resolved "https://registry.yarnpkg.com/path-to-regexp/-/path-to-regexp-2.2.1.tgz#90b617025a16381a879bc82a38d4e8bdeb2bcf45"
77247724
integrity sha512-gu9bD6Ta5bwGrrU8muHzVOBFFREpp2iRkVfhBJahwJ6p6Xw20SjT0MxLnwkjOibQmGSYhiUnf2FLe7k+jcFmGQ==
77257725

77267726
path-to-regexp@^1.7.0:
7727-
version "1.8.0"
7728-
resolved "https://registry.yarnpkg.com/path-to-regexp/-/path-to-regexp-1.8.0.tgz#887b3ba9d84393e87a0a0b9f4cb756198b53548a"
7729-
integrity sha512-n43JRhlUKUAlibEJhPeir1ncUID16QnEjNpwzNdO3Lm4ywrBpBZ5oLD0I6br9evr1Y9JTqwRtAh7JLoOzAQdVA==
7727+
version "1.9.0"
7728+
resolved "https://registry.yarnpkg.com/path-to-regexp/-/path-to-regexp-1.9.0.tgz#5dc0753acbf8521ca2e0f137b4578b917b10cf24"
7729+
integrity sha512-xIp7/apCFJuUHdDLWe8O1HIkb0kQrOMb/0u6FXQjemHn/ii5LrIzU6bdECnsiTF/GjZkMEKg1xdiZwNqDYlZ6g==
77307730
dependencies:
77317731
isarray "0.0.1"
77327732

@@ -8177,13 +8177,6 @@ pupa@^3.1.0:
81778177
dependencies:
81788178
escape-goat "^4.0.0"
81798179

8180-
8181-
version "6.11.0"
8182-
resolved "https://registry.yarnpkg.com/qs/-/qs-6.11.0.tgz#fd0d963446f7a65e1367e01abd85429453f0c37a"
8183-
integrity sha512-MvjoMCJwEarSbUYk5O+nmoSzSutSsTwF85zcHPQ9OrlFoZOYIjaqBAJIqIXjptyD5vThxGq52Xu/MaJzRkIk4Q==
8184-
dependencies:
8185-
side-channel "^1.0.4"
8186-
81878180
81888181
version "6.13.0"
81898182
resolved "https://registry.yarnpkg.com/qs/-/qs-6.13.0.tgz#6ca3bd58439f7e245655798997787b0d88a51906"
@@ -9289,25 +9282,6 @@ semver@^7.3.2, semver@^7.3.5, semver@^7.3.7, semver@^7.5.4:
92899282
dependencies:
92909283
lru-cache "^6.0.0"
92919284

9292-
9293-
version "0.18.0"
9294-
resolved "https://registry.yarnpkg.com/send/-/send-0.18.0.tgz#670167cc654b05f5aa4a767f9113bb371bc706be"
9295-
integrity sha512-qqWzuOjSFOuqPjFe4NOsMLafToQQwBSOEpS+FwEt3A2V3vKubTquT3vmLTQpFgMXp8AlFWFuP1qKaJZOtPpVXg==
9296-
dependencies:
9297-
debug "2.6.9"
9298-
depd "2.0.0"
9299-
destroy "1.2.0"
9300-
encodeurl "~1.0.2"
9301-
escape-html "~1.0.3"
9302-
etag "~1.8.1"
9303-
fresh "0.5.2"
9304-
http-errors "2.0.0"
9305-
mime "1.6.0"
9306-
ms "2.1.3"
9307-
on-finished "2.4.1"
9308-
range-parser "~1.2.1"
9309-
statuses "2.0.1"
9310-
93119285
93129286
version "0.19.0"
93139287
resolved "https://registry.yarnpkg.com/send/-/send-0.19.0.tgz#bbc5a388c8ea6c048967049dbeac0e4a3f09d7f8"
@@ -9368,15 +9342,15 @@ serve-index@^1.9.1:
93689342
mime-types "~2.1.17"
93699343
parseurl "~1.3.2"
93709344

9371-
9372-
version "1.16.0"
9373-
resolved "https://registry.yarnpkg.com/serve-static/-/serve-static-1.16.0.tgz#2bf4ed49f8af311b519c46f272bf6ac3baf38a92"
9374-
integrity sha512-pDLK8zwl2eKaYrs8mrPZBJua4hMplRWJ1tIFksVC3FtBEBnl8dxgeHtsaMS8DhS9i4fLObaon6ABoc4/hQGdPA==
9345+
9346+
version "1.16.2"
9347+
resolved "https://registry.yarnpkg.com/serve-static/-/serve-static-1.16.2.tgz#b6a5343da47f6bdd2673848bf45754941e803296"
9348+
integrity sha512-VqpjJZKadQB/PEbEwvFdO43Ax5dFBZ2UECszz8bQ7pi7wt//PWe1P6MN7eCnjsatYtBT6EuiClbjSWP2WrIoTw==
93759349
dependencies:
9376-
encodeurl "~1.0.2"
9350+
encodeurl "~2.0.0"
93779351
escape-html "~1.0.3"
93789352
parseurl "~1.3.3"
9379-
send "0.18.0"
9353+
send "0.19.0"
93809354

93819355
set-function-length@^1.2.1:
93829356
version "1.2.2"
@@ -9451,7 +9425,7 @@ short-unique-id@^5.0.2:
94519425
resolved "https://registry.yarnpkg.com/short-unique-id/-/short-unique-id-5.2.0.tgz#a7e0668e0a8998d3151f27a36cf046055b1f270b"
94529426
integrity sha512-cMGfwNyfDZ/nzJ2k2M+ClthBIh//GlZl1JEf47Uoa9XR11bz8Pa2T2wQO4bVrRdH48LrIDWJahQziKo3MjhsWg==
94539427

9454-
side-channel@^1.0.4, side-channel@^1.0.6:
9428+
side-channel@^1.0.6:
94559429
version "1.0.6"
94569430
resolved "https://registry.yarnpkg.com/side-channel/-/side-channel-1.0.6.tgz#abd25fb7cd24baf45466406b1096b7831c9215f2"
94579431
integrity sha512-fDW/EZ6Q9RiO8eFG8Hj+7u/oW+XrPTIChwCOM2+th2A6OblDtYYIpve9m+KvI9Z4C9qSEXlaGR6bTEYHReuglA==

pyproject.toml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -113,7 +113,7 @@ bigquery = [
113113
]
114114
clickhouse = ["clickhouse-connect>=0.5.14, <1.0"]
115115
cockroachdb = ["cockroachdb>=0.3.5, <0.4"]
116-
cors = ["flask-cors>=2.0.0"]
116+
cors = ["flask-cors>=4.0.2, <5.0"]
117117
crate = ["sqlalchemy-cratedb>=0.40.1, <1"]
118118
databend = ["databend-sqlalchemy>=0.3.2, <1.0"]
119119
databricks = [

requirements/base.in

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -16,7 +16,7 @@
1616
# specific language governing permissions and limitations
1717
# under the License.
1818
#
19-
urllib3>=1.26.18
19+
urllib3>=1.26.19, <2.0.0
2020
werkzeug>=3.0.1
2121
numexpr>=2.9.0
2222

requirements/base.txt

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -173,7 +173,7 @@ itsdangerous==2.2.0
173173
# via
174174
# flask
175175
# flask-wtf
176-
jinja2==3.1.4
176+
jinja2==3.1.5
177177
# via
178178
# flask
179179
# flask-babel
@@ -252,7 +252,7 @@ parsedatetime==2.6
252252
# via apache-superset (pyproject.toml)
253253
pgsanity==0.2.9
254254
# via apache-superset (pyproject.toml)
255-
platformdirs==3.8.1
255+
platformdirs==3.9.1
256256
# via requests-cache
257257
ply==3.11
258258
# via jsonpath-ng
@@ -385,7 +385,7 @@ tzdata==2024.2
385385
# pandas
386386
url-normalize==1.4.3
387387
# via requests-cache
388-
urllib3==1.26.18
388+
urllib3==1.26.20
389389
# via
390390
# -r requirements/base.in
391391
# requests

requirements/development.txt

Lines changed: 6 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -206,7 +206,7 @@ flask-compress==1.17
206206
# via
207207
# -c requirements/base.txt
208208
# apache-superset
209-
flask-cors==4.0.0
209+
flask-cors==4.0.2
210210
# via apache-superset
211211
flask-jwt-extended==4.7.1
212212
# via
@@ -362,7 +362,7 @@ itsdangerous==2.2.0
362362
# -c requirements/base.txt
363363
# flask
364364
# flask-wtf
365-
jinja2==3.1.4
365+
jinja2==3.1.5
366366
# via
367367
# -c requirements/base.txt
368368
# flask
@@ -530,7 +530,7 @@ pillow==10.3.0
530530
# via
531531
# apache-superset
532532
# matplotlib
533-
platformdirs==3.8.1
533+
platformdirs==3.9.1
534534
# via
535535
# -c requirements/base.txt
536536
# requests-cache
@@ -545,7 +545,7 @@ polyline==2.0.2
545545
# via
546546
# -c requirements/base.txt
547547
# apache-superset
548-
pre-commit==4.0.1
548+
pre-commit==4.1.0
549549
# via apache-superset
550550
prison==0.2.1
551551
# via
@@ -836,7 +836,7 @@ url-normalize==1.4.3
836836
# via
837837
# -c requirements/base.txt
838838
# requests-cache
839-
urllib3==1.26.18
839+
urllib3==1.26.20
840840
# via
841841
# -c requirements/base.txt
842842
# docker
@@ -849,7 +849,7 @@ vine==5.1.0
849849
# amqp
850850
# celery
851851
# kombu
852-
virtualenv==20.23.1
852+
virtualenv==20.29.2
853853
# via pre-commit
854854
wcwidth==0.2.13
855855
# via

superset-frontend/cypress-base/package-lock.json

Lines changed: 16 additions & 14 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

0 commit comments

Comments
 (0)