Skip to content

Commit a45dea3

Browse files
authored
[1.3][CVE-2023-0842] Bump xml2js from 0.4.22 to 0.6.2 (#5024)
* [1.3][CVE-2023-0842] Bump xml2js from 0.4.22 to 0.6.2 * force xml2js to 0.6.2 and fix PR comment --------- Signed-off-by: ananzh <ananzh@amazon.com> Signed-off-by: Anan Zhuang <ananzh@amazon.com>
1 parent 2a386b8 commit a45dea3

File tree

4 files changed

+9
-16
lines changed

4 files changed

+9
-16
lines changed

CHANGELOG.md

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -12,6 +12,7 @@ Inspired from [Keep a Changelog](https://keepachangelog.com/en/1.0.0/)
1212
- [CVE-2022-21670] Bump `markdown-it` from `10.0.0` to `12.3.2` ([#5016](https://github.com/opensearch-project/OpenSearch-Dashboards/pull/5016))
1313
- [CVE-2022-33987] Partially fix security issues for `got` by bumping `@elastic/makelogs` from `6.0.0` to `6.1.1` and updating yarn.lock ([#5006](https://github.com/opensearch-project/OpenSearch-Dashboards/pull/5006))
1414
- Bump `yo` from `2.0.6` to `3.1.1` ([#5005]( https://github.com/opensearch-project/OpenSearch-Dashboards/pull/5005))
15+
- [CVE-2023-0842] Bump `xml2js` from `0.4.22` to `0.6.2` ([#5024](https://github.com/opensearch-project/OpenSearch-Dashboards/pull/5024))
1516

1617
### 📈 Features/Enhancements
1718

package.json

Lines changed: 3 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -128,7 +128,8 @@
128128
"**/tough-cookie": "^4.1.3",
129129
"**/typescript": "4.0.2",
130130
"**/url-parse": "^1.5.8",
131-
"**/unset-value": "^2.0.1"
131+
"**/unset-value": "^2.0.1",
132+
"**/xml2js": "^0.6.2"
132133
},
133134
"workspaces": {
134135
"packages": [
@@ -498,7 +499,7 @@
498499
"vega-schema-url-parser": "^2.1.0",
499500
"vega-tooltip": "^0.24.2",
500501
"vinyl-fs": "^3.0.3",
501-
"xml2js": "^0.4.22",
502+
"xml2js": "^0.6.2",
502503
"xmlbuilder": "13.0.2",
503504
"zlib": "^1.0.5"
504505
},

packages/osd-test/package.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -37,7 +37,7 @@
3737
"rxjs": "^6.5.5",
3838
"strip-ansi": "^6.0.0",
3939
"tar-fs": "^2.1.0",
40-
"xml2js": "^0.4.22",
40+
"xml2js": "^0.6.2",
4141
"zlib": "^1.0.5"
4242
}
4343
}

yarn.lock

Lines changed: 4 additions & 13 deletions
Original file line numberDiff line numberDiff line change
@@ -20931,14 +20931,6 @@ util-extend@^1.0.1:
2093120931
resolved "https://registry.yarnpkg.com/util-extend/-/util-extend-1.0.3.tgz#a7c216d267545169637b3b6edc6ca9119e2ff93f"
2093220932
integrity sha1-p8IW0mdUUWljeztu3GypEZ4v+T8=
2093320933

20934-
util.promisify@~1.0.0:
20935-
version "1.0.0"
20936-
resolved "https://registry.yarnpkg.com/util.promisify/-/util.promisify-1.0.0.tgz#440f7165a459c9a16dc145eb8e72f35687097030"
20937-
integrity sha512-i+6qA2MPhvoKLuxnJNpXAGhg7HphQOSUq2LKMZD0m15EiskXUkMvKdF4Uui0WYeCUGea+o2cw/ZuwehtfsrNkA==
20938-
dependencies:
20939-
define-properties "^1.1.2"
20940-
object.getownpropertydescriptors "^2.0.3"
20941-
2094220934
util@0.10.3, util@^0.10.3:
2094320935
version "0.10.3"
2094420936
resolved "https://registry.yarnpkg.com/util/-/util-0.10.3.tgz#7afb1afe50805246489e3db7fe0ed379336ac0f9"
@@ -22183,13 +22175,12 @@ xml-parse-from-string@^1.0.0:
2218322175
resolved "https://registry.yarnpkg.com/xml-parse-from-string/-/xml-parse-from-string-1.0.1.tgz#a9029e929d3dbcded169f3c6e28238d95a5d5a28"
2218422176
integrity sha1-qQKekp09vN7RafPG4oI42VpdWig=
2218522177

22186-
xml2js@^0.4.22, xml2js@^0.4.5:
22187-
version "0.4.22"
22188-
resolved "https://registry.yarnpkg.com/xml2js/-/xml2js-0.4.22.tgz#4fa2d846ec803237de86f30aa9b5f70b6600de02"
22189-
integrity sha512-MWTbxAQqclRSTnehWWe5nMKzI3VmJ8ltiJEco8akcC6j3miOhjjfzKum5sId+CWhfxdOs/1xauYr8/ZDBtQiRw==
22178+
xml2js@^0.4.5, xml2js@^0.6.2:
22179+
version "0.6.2"
22180+
resolved "https://registry.yarnpkg.com/xml2js/-/xml2js-0.6.2.tgz#dd0b630083aa09c161e25a4d0901e2b2a929b499"
22181+
integrity sha512-T4rieHaC1EXcES0Kxxj4JWgaUQHDk+qwHcYOCFHfiwKz7tOVPLq7Hjq9dM1WCMhylqMEfP7hMcOIChvotiZegA==
2219022182
dependencies:
2219122183
sax ">=0.6.0"
22192-
util.promisify "~1.0.0"
2219322184
xmlbuilder "~11.0.0"
2219422185

2219522186
xmlbuilder@13.0.2:

0 commit comments

Comments
 (0)