Skip to content

NIFI-15643: Addressing dependabot issues.#10933

Merged
rfellows merged 1 commit intoapache:mainfrom
mcgilman:NIFI-15643
Feb 24, 2026
Merged

NIFI-15643: Addressing dependabot issues.#10933
rfellows merged 1 commit intoapache:mainfrom
mcgilman:NIFI-15643

Conversation

@mcgilman
Copy link
Contributor

@mcgilman mcgilman commented Feb 24, 2026

  • Bumped @angular-devkit/build-angular, @angular-devkit/core, @angular-devkit/schematics, @angular/build, and @schematics/angular from 20.3.12 to 20.3.17 (patch-level). This pulls in webpack 5.105.0, fixing GHSA-8fgc-7cc6-rx7x and GHSA-38r7-794h-5758 (SSRF via buildHttp).
  • Added npm overrides for ajv to resolve GHSA-2g4f-4pwh-qvx6 (ReDoS with $data option):
    • 8.17.1 -> 8.18.0 globally (used by @angular-devkit/core, ng-packagr, etc.)
    • 6.12.6 -> 6.14.0 scoped to eslint, @eslint/eslintrc, and fork-ts-checker-webpack-plugin
  • Ran npm audit fix to resolve transitive vulnerabilities in tar (GHSA-83g3-92jg-28cx), qs (GHSA-w7fw-mjwx-w883), and hono (GHSA-gq3j-xvxp-8hrf).

@rfellows
Copy link
Contributor

will review

@rfellows rfellows merged commit 7199bdf into apache:main Feb 24, 2026
7 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file ui Pull requests for work relating to the user interface

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants