Skip to content

Commit f728d7c

Browse files
authored
Fixing CVE 2024-21538 (#1258)
* Fixing CVE 2024-21538 Signed-off-by: Kshitij Tandon <[email protected]> * Updating upload artifact to v4 Signed-off-by: Kshitij Tandon <[email protected]> --------- Signed-off-by: Kshitij Tandon <[email protected]>
1 parent 3eb1b24 commit f728d7c

File tree

3 files changed

+6
-50
lines changed

3 files changed

+6
-50
lines changed

.github/actions/run-cypress-tests/action.yaml

+2-2
Original file line numberDiff line numberDiff line change
@@ -139,13 +139,13 @@ runs:
139139
wait-on: 'http://localhost:5601'
140140
browser: chrome
141141
# Screenshots are only captured on failure, will change this once we do visual regression tests
142-
- uses: actions/upload-artifact@v3
142+
- uses: actions/upload-artifact@v4
143143
if: failure()
144144
with:
145145
name: cypress-screenshots
146146
path: OpenSearch-Dashboards/plugins/index-management-dashboards-plugin/cypress/screenshots
147147
# Test run video was always captured, so this action uses "always()" condition
148-
- uses: actions/upload-artifact@v3
148+
- uses: actions/upload-artifact@v4
149149
if: always()
150150
with:
151151
name: cypress-videos

package.json

+1-1
Original file line numberDiff line numberDiff line change
@@ -35,7 +35,7 @@
3535
"**/ansi-regex": "^5.0.1",
3636
"**/loader-utils": "^2.0.4",
3737
"**/typescript": "4.0.2",
38-
"**/eslint/cross-spawn": "^7.0.5"
38+
"cross-spawn": "^7.0.5"
3939
},
4040
"devDependencies": {
4141
"@elastic/elastic-eslint-config-kibana": "link:../../packages/opensearch-eslint-config-opensearch-dashboards",

yarn.lock

+3-47
Original file line numberDiff line numberDiff line change
@@ -1353,27 +1353,7 @@ create-hmac@^1.1.0, create-hmac@^1.1.4, create-hmac@^1.1.7:
13531353
safe-buffer "^5.0.1"
13541354
sha.js "^2.4.8"
13551355

1356-
cross-spawn@^6.0.0:
1357-
version "6.0.5"
1358-
resolved "https://registry.yarnpkg.com/cross-spawn/-/cross-spawn-6.0.5.tgz#4a5ec7c64dfae22c3a14124dbacdee846d80cbc4"
1359-
integrity sha512-eTVLrBSt7fjbDygz805pMnstIs2VTBNkRm0qxZd+M7A5XDdxVRWO5MxGBXZhjY4cqLYLdtrGqRf8mBPmzwSpWQ==
1360-
dependencies:
1361-
nice-try "^1.0.4"
1362-
path-key "^2.0.1"
1363-
semver "^5.5.0"
1364-
shebang-command "^1.2.0"
1365-
which "^1.2.9"
1366-
1367-
cross-spawn@^7.0.0:
1368-
version "7.0.3"
1369-
resolved "https://registry.yarnpkg.com/cross-spawn/-/cross-spawn-7.0.3.tgz#f73a85b9d5d41d045551c177e2882d4ac85728a6"
1370-
integrity sha512-iRDPJKUPVEND7dHPO8rkbOnPpyDygcDFtWjpeWNCgy8WP2rXcxXL8TskReQl6OrB2G7+UJrags1q15Fudc7G6w==
1371-
dependencies:
1372-
path-key "^3.1.0"
1373-
shebang-command "^2.0.0"
1374-
which "^2.0.1"
1375-
1376-
cross-spawn@^7.0.5:
1356+
cross-spawn@^6.0.0, cross-spawn@^7.0.0, cross-spawn@^7.0.5:
13771357
version "7.0.6"
13781358
resolved "https://registry.yarnpkg.com/cross-spawn/-/cross-spawn-7.0.6.tgz#8a58fe78f00dcd70c370451759dfbfaf03e8ee9f"
13791359
integrity sha512-uV2QOWP2nWzsy2aMp8aRibhi9dlzF5Hgh5SHaB9OiTGEyDTiJJyx0uy51QXdyWbtAHNua4XJzUKca3OzKUd3vA==
@@ -3350,11 +3330,6 @@ neo-async@^2.5.0, neo-async@^2.6.1:
33503330
resolved "https://registry.yarnpkg.com/neo-async/-/neo-async-2.6.2.tgz#b4aafb93e3aeb2d8174ca53cf163ab7d7308305f"
33513331
integrity sha512-Yd3UES5mWCSqR+qNT93S3UoYUkqAZ9lLg8a7g9rimsWmYGK8cVToA4/sF3RrshdyV3sAGMXVUmpMYOw+dLpOuw==
33523332

3353-
nice-try@^1.0.4:
3354-
version "1.0.5"
3355-
resolved "https://registry.yarnpkg.com/nice-try/-/nice-try-1.0.5.tgz#a3378a7696ce7d223e88fc9b764bd7ef1089e366"
3356-
integrity sha512-1nh45deeb5olNY7eX82BkPO7SSxR5SSYJiPTrTdFUVYwAl8CKMA5N9PjTYkHiRjisVcxcQ1HXdLhx2qxxJzLNQ==
3357-
33583333
node-libs-browser@^2.2.1:
33593334
version "2.2.1"
33603335
resolved "https://registry.yarnpkg.com/node-libs-browser/-/node-libs-browser-2.2.1.tgz#b64f513d18338625f90346d27b0d235e631f6425"
@@ -3616,7 +3591,7 @@ path-is-absolute@^1.0.0:
36163591
resolved "https://registry.yarnpkg.com/path-is-absolute/-/path-is-absolute-1.0.1.tgz#174b9268735534ffbc7ace6bf53a5a9e1b5c5f5f"
36173592
integrity sha1-F0uSaHNVNP+8es5r9TpanhtcX18=
36183593

3619-
path-key@^2.0.0, path-key@^2.0.1:
3594+
path-key@^2.0.0:
36203595
version "2.0.1"
36213596
resolved "https://registry.yarnpkg.com/path-key/-/path-key-2.0.1.tgz#411cadb574c5a140d3a4b1910d40d80cc9f40b40"
36223597
integrity sha1-QRyttXTFoUDTpLGRDUDYDMn0C0A=
@@ -4119,7 +4094,7 @@ semver-compare@^1.0.0:
41194094
resolved "https://registry.yarnpkg.com/semver-compare/-/semver-compare-1.0.0.tgz#0dee216a1c941ab37e9efb1788f6afc5ff5537fc"
41204095
integrity sha512-YM3/ITh2MJ5MtzaM429anh+x2jiLVjqILF4m4oyQB18W7Ggea7BfqdH/wGMK7dDiMghv/6WG7znWMwUDzJiXow==
41214096

4122-
"semver@2 || 3 || 4 || 5", semver@^5.5.0, semver@^5.6.0, semver@^5.7.2, semver@^6.0.0, semver@^7.5.3:
4097+
"semver@2 || 3 || 4 || 5", semver@^5.6.0, semver@^5.7.2, semver@^6.0.0, semver@^7.5.3:
41234098
version "7.5.3"
41244099
resolved "https://registry.yarnpkg.com/semver/-/semver-7.5.3.tgz#161ce8c2c6b4b3bdca6caadc9fa3317a4c4fe88e"
41254100
integrity sha512-QBlUtyVk/5EeHbi7X0fw6liDZc7BBmEaSYn01fMU1OUYbf6GPsbTtd8WmnqbI20SeycoHSeiybkE/q1Q+qlThQ==
@@ -4193,25 +4168,13 @@ sha.js@^2.4.0, sha.js@^2.4.8:
41934168
inherits "^2.0.1"
41944169
safe-buffer "^5.0.1"
41954170

4196-
shebang-command@^1.2.0:
4197-
version "1.2.0"
4198-
resolved "https://registry.yarnpkg.com/shebang-command/-/shebang-command-1.2.0.tgz#44aac65b695b03398968c39f363fee5deafdf1ea"
4199-
integrity sha1-RKrGW2lbAzmJaMOfNj/uXer98eo=
4200-
dependencies:
4201-
shebang-regex "^1.0.0"
4202-
42034171
shebang-command@^2.0.0:
42044172
version "2.0.0"
42054173
resolved "https://registry.yarnpkg.com/shebang-command/-/shebang-command-2.0.0.tgz#ccd0af4f8835fbdc265b82461aaf0c36663f34ea"
42064174
integrity sha512-kHxr2zZpYtdmrN1qDjrrX/Z1rR1kG8Dx+gkpK1G4eXmvXswmcE1hTWBWYUzlraYw1/yZp6YuDY77YtvbN0dmDA==
42074175
dependencies:
42084176
shebang-regex "^3.0.0"
42094177

4210-
shebang-regex@^1.0.0:
4211-
version "1.0.0"
4212-
resolved "https://registry.yarnpkg.com/shebang-regex/-/shebang-regex-1.0.0.tgz#da42f49740c0b42db2ca9728571cb190c98efea3"
4213-
integrity sha1-2kL0l0DAtC2yypcoVxyxkMmO/qM=
4214-
42154178
shebang-regex@^3.0.0:
42164179
version "3.0.0"
42174180
resolved "https://registry.yarnpkg.com/shebang-regex/-/shebang-regex-3.0.0.tgz#ae16f1644d873ecad843b0307b143362d4c42172"
@@ -4981,13 +4944,6 @@ which-typed-array@^1.1.14, which-typed-array@^1.1.15:
49814944
gopd "^1.0.1"
49824945
has-tostringtag "^1.0.2"
49834946

4984-
which@^1.2.9:
4985-
version "1.3.1"
4986-
resolved "https://registry.yarnpkg.com/which/-/which-1.3.1.tgz#a45043d54f5805316da8d62f9f50918d3da70b0a"
4987-
integrity sha512-HxJdYWq1MTIQbJ3nw0cqssHoTNU267KlrDuGZ1WYlxDStUtKUhOaJmh112/TZmHxxUfuJqPXSOm7tDyas0OSIQ==
4988-
dependencies:
4989-
isexe "^2.0.0"
4990-
49914947
which@^2.0.1:
49924948
version "2.0.2"
49934949
resolved "https://registry.yarnpkg.com/which/-/which-2.0.2.tgz#7c6a8dd0a636a0327e10b59c9286eee93f3f51b1"

0 commit comments

Comments
 (0)