Skip to content

Commit a675b1c

Browse files
opensearch-trigger-bot[bot]github-actions[bot]joshuarrrrabbyhu2000
authored
[Backport 1.3] [1.x backport] Bump joi to v14 to avoid the possibility of prototype poisoning in a nested dependency (#4345)
* [1.x backport] Bump `joi` to v14 to avoid the possibility of prototype poisoning in a nested dependency (#4211) Backport PR #3952 Signed-off-by: Miki <miki@amazon.com> Co-authored-by: Miki <miki@amazon.com> (cherry picked from commit 4626066) Signed-off-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com> # Conflicts: # CHANGELOG.md * update changelog Signed-off-by: Josh Romero <rmerqg@amazon.com> --------- Signed-off-by: Josh Romero <rmerqg@amazon.com> Signed-off-by: Qingyang(Abby) Hu <abigailhu2000@gmail.com> Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com> Co-authored-by: Josh Romero <rmerqg@amazon.com> Co-authored-by: Qingyang(Abby) Hu <abigailhu2000@gmail.com>
1 parent b3c3fd7 commit a675b1c

File tree

5 files changed

+17
-7
lines changed

5 files changed

+17
-7
lines changed

CHANGELOG.md

+1
Original file line numberDiff line numberDiff line change
@@ -13,6 +13,7 @@ Inspired from [Keep a Changelog](https://keepachangelog.com/en/1.0.0/)
1313
- [CVE-2022-1537] Bump grunt from `1.5.2` to `1.5.3` ([#4276](https://github.com/opensearch-project/OpenSearch-Dashboards/pull/4276))
1414
- [CVE-2022-25858] Bump terser from `4.8.0` to `4.8.1` ([#3726](https://github.com/opensearch-project/OpenSearch-Dashboards/pull/3726))
1515
- [CVE-2021-3765] Update `@microsoft/api-documenter` and `@microsoft/api-extractor` versions to bump validator from `8.2.0` to `13.9.0` ([#3725](https://github.com/opensearch-project/OpenSearch-Dashboards/pull/3725))
16+
- Bump `joi` to v14 to avoid the possibility of prototype poisoning in a nested dependency ([#3952](https://github.com/opensearch-project/OpenSearch-Dashboards/pull/3952))
1617
- [CVE-2022-25883] Resolve `semver` to `7.5.3` and remove unused package ([#4411](https://github.com/opensearch-project/OpenSearch-Dashboards/pull/4411))
1718

1819
### 📈 Features/Enhancements

package.json

+1-1
Original file line numberDiff line numberDiff line change
@@ -206,7 +206,7 @@
206206
"inert": "^5.1.0",
207207
"inline-style": "^2.0.0",
208208
"ip-cidr": "^2.1.0",
209-
"joi": "^13.5.2",
209+
"joi": "^14.3.1",
210210
"js-yaml": "^3.14.0",
211211
"json-stable-stringify": "^1.0.1",
212212
"json-stringify-safe": "5.0.1",

packages/osd-config-schema/package.json

+1-1
Original file line numberDiff line numberDiff line change
@@ -16,7 +16,7 @@
1616
},
1717
"peerDependencies": {
1818
"lodash": "^4.17.21",
19-
"joi": "^13.5.2",
19+
"joi": "^14.3.1",
2020
"moment": "^2.24.0",
2121
"type-detect": "^4.0.8"
2222
}

packages/osd-test/package.json

+1-1
Original file line numberDiff line numberDiff line change
@@ -31,7 +31,7 @@
3131
"exit-hook": "^2.2.0",
3232
"getopts": "^2.2.5",
3333
"glob": "^7.1.7",
34-
"joi": "^13.5.2",
34+
"joi": "^14.3.1",
3535
"lodash": "^4.17.21",
3636
"parse-link-header": "^2.0.0",
3737
"rxjs": "^6.5.5",

yarn.lock

+13-4
Original file line numberDiff line numberDiff line change
@@ -10986,9 +10986,9 @@ hoek@5.x.x, hoek@^5.0.4:
1098610986
integrity sha512-Alr4ZQgoMlnere5FZJsIyfIjORBqZll5POhDsF4q64dPuJR6rNxXdDxtHSQq8OXRurhmx+PWYEE8bXRROY8h0w==
1098710987

1098810988
hoek@6.x.x:
10989-
version "6.0.3"
10990-
resolved "https://registry.yarnpkg.com/hoek/-/hoek-6.0.3.tgz#7884360426d927865a0a1251fc9c59313af5b798"
10991-
integrity sha512-TU6RyZ/XaQCTWRLrdqZZtZqwxUVr6PDMfi6MlWNURZ7A6czanQqX4pFE1mdOUQR9FdPCsZ0UzL8jI/izZ+eBSQ==
10989+
version "6.1.3"
10990+
resolved "https://registry.yarnpkg.com/hoek/-/hoek-6.1.3.tgz#73b7d33952e01fe27a38b0457294b79dd8da242c"
10991+
integrity sha512-YXXAAhmF9zpQbC7LEcREFtXfGq5K1fmd+4PHkBq8NUqmzW3G+Dq10bI/i0KucLRwss3YYFQ0fSfoxBZYiGUqtQ==
1099210992

1099310993
hoist-non-react-statics@^2.5.5, hoist-non-react-statics@^3.0.0, hoist-non-react-statics@^3.1.0, hoist-non-react-statics@^3.3.0, hoist-non-react-statics@^3.3.2:
1099410994
version "3.3.2"
@@ -13047,7 +13047,7 @@ jju@~1.4.0:
1304713047
resolved "https://registry.yarnpkg.com/jju/-/jju-1.4.0.tgz#a3abe2718af241a2b2904f84a625970f389ae32a"
1304813048
integrity sha1-o6vicYryQaKykE+EpiWXDzia4yo=
1304913049

13050-
joi@13.x.x, joi@^13.5.2:
13050+
joi@13.x.x:
1305113051
version "13.7.0"
1305213052
resolved "https://registry.yarnpkg.com/joi/-/joi-13.7.0.tgz#cfd85ebfe67e8a1900432400b4d03bbd93fb879f"
1305313053
integrity sha512-xuY5VkHfeOYK3Hdi91ulocfuFopwgbSORmIwzcwHKESQhC7w1kD5jaVSPnqDxS2I8t3RZ9omCKAxNwXN5zG1/Q==
@@ -13056,6 +13056,15 @@ joi@13.x.x, joi@^13.5.2:
1305613056
isemail "3.x.x"
1305713057
topo "3.x.x"
1305813058

13059+
joi@^14.3.1:
13060+
version "14.3.1"
13061+
resolved "https://registry.yarnpkg.com/joi/-/joi-14.3.1.tgz#164a262ec0b855466e0c35eea2a885ae8b6c703c"
13062+
integrity sha512-LQDdM+pkOrpAn4Lp+neNIFV3axv1Vna3j38bisbQhETPMANYRbFJFUyOZcOClYvM/hppMhGWuKSFEK9vjrB+bQ==
13063+
dependencies:
13064+
hoek "6.x.x"
13065+
isemail "3.x.x"
13066+
topo "3.x.x"
13067+
1305913068
jpeg-js@^0.4.0:
1306013069
version "0.4.4"
1306113070
resolved "https://registry.yarnpkg.com/jpeg-js/-/jpeg-js-0.4.4.tgz#a9f1c6f1f9f0fa80cdb3484ed9635054d28936aa"

0 commit comments

Comments
 (0)