Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Backport 2.0] [CVE] Bumps Chromedriver to v100 and axios to v0.27.2 #1557

Merged
merged 1 commit into from
May 6, 2022

Conversation

opensearch-trigger-bot[bot]
Copy link
Contributor

Backport cba0764 from #1552

* Addresses CVE-2022-1214
* Bumps and resolves `axios` to ^0.27.2 to address CVE
  * [CHANGELOG](https://github.com/axios/axios/blob/master/CHANGELOG.md)
* Bumps `chromedriver` to v100 to match GitHub actions

Signed-off-by: Bishoy Boktor <boktorbb@amazon.com>
(cherry picked from commit cba0764)
@opensearch-trigger-bot opensearch-trigger-bot bot requested a review from a team as a code owner May 6, 2022 15:13
@tmarkley tmarkley added v2.0.0 backport cve Security vulnerabilities detected by Dependabot or Mend labels May 6, 2022
@tmarkley tmarkley merged commit ee0812a into 2.0 May 6, 2022
@github-actions github-actions bot deleted the backport/backport-1552-to-2.0 branch May 6, 2022 21:06
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
cve Security vulnerabilities detected by Dependabot or Mend v2.0.0
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants