Skip to content

sailor-nodejs nightly builds fail due to the high vulnerabilities - need to fix #48

@HannaTrotsenko

Description

@HannaTrotsenko
> [email protected] audit /home/circleci/elasticio-rest-node
> better-npm-audit audit --level high --production

╔═══════════════════════════════════════════════════════════════════════════════════════════════════════════════════════════════════════════════╗
║                                                          === list of exceptions ===                                                           ║
║                                                                                                                                               ║
║ ID                  │ Status │ Expiry │ Notes                                                                                                 ║
║ GHSA-f8q6-p94x-37v3 │ active │        │ braceExpand is not used in rimraf                                                                     ║
║ GHSA-4hjh-wcwx-xvwj │ active │        │ should be removed when maester-client is fixed: https://github.com/elasticio/maester-client/issues/47 ║
╚═════════════════════╧════════╧════════╧═══════════════════════════════════════════════════════════════════════════════════════════════════════╝

╔════════════════════════════════════════════════════════════════════════════════════════════════════════════════════════════════════════════════════════════════════════════════════════════════╗
║                                                                               === npm audit security report ===                                                                                ║
║                                                                                                                                                                                                ║
║ ID      │ Module    │ Title                                              │ Paths                                              │ Sev. │ URL                                               │ Ex. ║
║ 1096485 │ minimatch │ minimatch ReDoS vulnerability                      │ bunyan>mv>rimraf>glob>minimatch                    │ high │ https://github.com/advisories/GHSA-f8q6-p94x-37v3 │ y   ║
║         │           │                                                    │ @elastic.io/maester-client>@elastic.io/bunyan-     │      │                                                   │     ║
║         │           │                                                    │ logger>bunyan>mv>rimraf>glob>minimatch             │      │                                                   │     ║
║ 1108263 │ axios     │ Axios is vulnerable to DoS attack through lack of  │ @elastic.io/maester-client>axios                   │ high │ https://github.com/advisories/GHSA-4hjh-wcwx-xvwj │ y   ║
║         │           │ data size check                                    │                                                    │      │                                                   │     ║
║ 1111244 │ jws       │ auth0/node-jws Improperly Verifies HMAC Signature  │ @elastic.io/maester-client>jsonwebtoken>jws        │ high │ https://github.com/advisories/GHSA-869p-cjfg-cm3x │ n   ║
╚═════════╧═══════════╧════════════════════════════════════════════════════╧════════════════════════════════════════════════════╧══════╧═══════════════════════════════════════════════════╧═════╝

1 vulnerabilities found. Node security advisories: 1111244
npm ERR! code ELIFECYCLE
npm ERR! errno 1
npm ERR! [email protected] audit: `better-npm-audit audit --level high --production`
npm ERR! Exit status 1
npm ERR! 
npm ERR! Failed at the [email protected] audit script.
npm ERR! This is probably not a problem with npm. There is likely additional logging output above.

npm ERR! A complete log of this run can be found in:
npm ERR!     /home/circleci/.npm/_logs/2025-12-05T00_02_28_231Z-debug.log

Exited with code exit status 1

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions