This is http://KuWit.io 🤖 🤖 🤖 the AI bot who knows everything about Kubernetes. https://capgemini.github.io/bots/kuwit/
7
stars
5
forks
source link
[Snyk] Security upgrade node-kubernetes-client from 0.2.3 to 0.3.2 #16
Open
snyk-bot opened 3 years ago
Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.
Changes included in this PR
Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
Adding or updating a Snyk policy (.snyk) file; this file is required in order to apply Snyk vulnerability patches. Find out more.
Vulnerabilities that will be fixed
With an upgrade:
Why? Has a fix available, CVSS 3.7
npm:hawk:20160119
Why? Has a fix available, CVSS 6.3
npm:hoek:20180212
Why? Has a fix available, CVSS 6.5
npm:http-signature:20150122
Why? Has a fix available, CVSS 7.5
npm:qs:20140806
Why? Has a fix available, CVSS 6.5
npm:qs:20140806-1
Why? Has a fix available, CVSS 7.5
npm:qs:20170213
Why? Has a fix available, CVSS 5.1
npm:request:20160119
Why? Proof of Concept exploit, Has a fix available, CVSS 5.1
npm:tunnel-agent:20170305
(*) Note that the real score may have changed since the PR was raised.
Commit messages
Package name: node-kubernetes-client
The new version differs by 44 commits.With a Snyk patch:
Why? Has a fix available, CVSS 3.7
npm:mime:20170907
(*) Note that the real score may have changed since the PR was raised.
Check the changes in this PR to ensure they won't cause issues with your project.
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.
For more information: 🧐 View latest project report
🛠 Adjust project settings
📚 Read more about Snyk's upgrade and patch logic