Join GitHub today
GitHub is home to over 31 million developers working together to host and review code, manage projects, and build software together.
Sign upPrometheus third-party javascript is stale and vulnerable #4563
Comments
simonpasquier
added
component/ui
help wanted
labels
Aug 29, 2018
brian-brazil
closed this
in
#4679
Oct 10, 2018
This comment has been minimized.
This comment has been minimized.
|
Thanks a lot ! |
lock
bot
locked and limited conversation to collaborators
Apr 8, 2019
Sign up for free
to subscribe to this conversation on GitHub.
Already have an account?
Sign in.
nim-nim commentedAug 29, 2018
For example
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-18214
(prometheus bundles 2.16.0)
The javascript vendoring needs a refresh, and probably a switch to a build process that uses npm or yarn (like grafana)