Skip to content

[Snyk] Security upgrade @pulumi/kubernetes from 3.30.2 to 4.9.0#589

Open
riddopic wants to merge 1 commit intomasterfrom
snyk-fix-f925785870c65f78b5f7951d0563f7fc
Open

[Snyk] Security upgrade @pulumi/kubernetes from 3.30.2 to 4.9.0#589
riddopic wants to merge 1 commit intomasterfrom
snyk-fix-f925785870c65f78b5f7951d0563f7fc

Conversation

@riddopic
Copy link
Copy Markdown
Owner

@riddopic riddopic commented Mar 6, 2024

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • digitalocean-ts-k8s/package.json

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
medium severity 631/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 6.2
Missing Release of Resource after Effective Lifetime
SNYK-JS-INFLIGHT-6095116
Yes Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: @pulumi/kubernetes The new version differs by 152 commits.
  • 0b393b1 Prepare for v4.9.0 release
  • 9015392 Update glob options for nodejs SDK to be backwards compatible
  • e74728b Link to the how-to-guide from Chart and Releaseï��
  • 652829a Update version of 'glob' dependency and remove '@ types/glob' to resolve imports conflict (#2858)
  • 6579e48 Bump the go_modules group across 2 directories with 1 update
  • 53f0563 Enhance SSA ignoreChanges by having better field manager path comparisons (#2828)
  • 2edaad8 Prepare for v4.8.1 release (#2848)
  • 99fd994 skip normalization in preview w/ computed fields (#2846)
  • 68e2242 Prepare for v4.8.0 release (#2841)
  • 0c1bfda Update GitHub Actions workflows. (#2838)
  • aea60a1 Handle unknowns in Helm Release (#2822)
  • b337259 Update GitHub Actions workflows. (#2821)
  • 6370a3b Fix unmarshalling of Helm values yaml file (#2815)
  • 257ebcb Automated Pulumi/Pulumi upgrade (#2816)
  • 22663e6 Update GitHub Actions workflows. (#2811)
  • cc3c25d Support for metadata.generateName (CSA) (#2808)
  • 33c84f9 Use output properties for await logic (#2790)
  • ef6b07b Replacement has incorrect status messages (#2810)
  • 4a5bfcc Unit tests for Await logic (Creation) (#2797)
  • 6f1e306 Automated Pulumi/Pulumi upgrade (#2805)
  • d2a0c57 Update GitHub Actions workflows. (#2804)
  • a7876ac Bump the github_actions group across 1 directories with 1 update
  • 3c6513e Fix: DiffConfig fails when provider's kubeconfig is set to file path (#2771)
  • df718a6 Provider Unit Tests (Provider Lifecycle) (#2768)

See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Learn about vulnerability in an interactive lesson of Snyk Learn.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants