Skip to content

Conversation

masontikhonov
Copy link
Contributor

@masontikhonov masontikhonov commented Nov 24, 2024

What

This PR reapplies #866 that was previously reverted in #869.

It contains upgrade for multiple dependencies to address critical- and high-level CVE.

In addition to #866, it:

  • upgrades npm to address CVE-2024-21538.
  • Sets NODE_NO_WARNINGS=1 env in Dockerfile (ref) in order to suppress Node.js deprecation warnings, that may interrupt end-user automations, that rely on exact CLi output.
  • Migrates from pkg, which is no longer maintained, to its fork @yao-pkg/pkg.

@masontikhonov masontikhonov self-assigned this Nov 24, 2024
@masontikhonov masontikhonov force-pushed the CR-25970--security-fix-critical-and-high-in-codefresh-cli branch from 90ca146 to 8e9dd96 Compare November 24, 2024 15:08
@masontikhonov masontikhonov marked this pull request as ready for review November 24, 2024 15:24
@masontikhonov masontikhonov merged commit f0a514c into master Nov 27, 2024
1 check passed
@masontikhonov masontikhonov deleted the CR-25970--security-fix-critical-and-high-in-codefresh-cli branch November 27, 2024 08:01
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants