opensearch-project / opensearch-ci

Enables continuous integration across OpenSearch, OpenSearch Dashboards, and plugins.
Apache License 2.0
15 stars 25 forks source link

Update dependency npm-check-updates to v16.3.18 #469

Closed mend-for-github-com[bot] closed 1 month ago

mend-for-github-com[bot] commented 1 month ago

This PR contains the following updates:

Package Type Update Change
npm-check-updates dependencies patch 16.3.17 -> 16.3.18

By merging this PR, the issue #470 will be automatically resolved and closed:

Severity CVSS Score CVE
Medium Medium 5.3 CVE-2024-4067

Release Notes

raineorshine/npm-check-updates (npm-check-updates) ### [`v16.3.18`](https://togithub.com/raineorshine/npm-check-updates/compare/v16.3.17...v16.3.18) [Compare Source](https://togithub.com/raineorshine/npm-check-updates/compare/v16.3.17...v16.3.18)

zelinh commented 1 month ago

Seems like a new CVE reported for this dependency as well. https://github.com/opensearch-project/opensearch-ci/issues/473