diff --git a/.snyk b/.snyk index da1097a2c..1824c017c 100644 --- a/.snyk +++ b/.snyk @@ -1,7 +1,12 @@ # Snyk (https://snyk.io) policy file, patches or ignores known vulnerabilities. version: v1.25.0 # ignores vulnerabilities until expiry date; change duration by modifying expiry date -ignore: +ignore: + SNYK-JS-FORMDATA-10841150: + - '*': + reason: Waiting for @kubernetes/client-node upgrade to 1.0.0 + expires: 2025-12-01T12:00:00.000Z + created: 2025-07-31T12:00:00.000Z SNYK-JS-BRACES-6838727: - '*': reason: devDependency @@ -26,16 +31,4 @@ ignore: https://github.com/kubernetes-client/javascript/blob/master/FETCH_MIGRATION.md expires: 2025-01-10T12:00:00.000Z created: 2024-10-23T12:00:00.000Z - SNYK-JS-CROSSSPAWN-8303230: - - '*': - reason: >- - No upstream fix available - expires: 2024-12-08T12:00:00.000Z - created: 2024-11-08T12:00:00.000Z - SNYK-JS-JSONPATHPLUS-7945884: - - '*': - reason: >- - Waiting for @kubernetes/client-node upgrade - expires: 2024-12-08T12:00:00.000Z - created: 2024-11-20T12:00:00.000Z patch: {} diff --git a/package-lock.json b/package-lock.json index cd86d9632..51b5dbb2e 100644 --- a/package-lock.json +++ b/package-lock.json @@ -20,7 +20,7 @@ "packageurl-js": "^1.2.1", "sleep-promise": "^9.1.0", "snyk-config": "5.3.0", - "snyk-docker-plugin": "^8.4.1", + "snyk-docker-plugin": "8.4.2", "source-map-support": "^0.5.21", "tunnel": "0.0.6", "typescript": "4.9.5", @@ -9552,6 +9552,19 @@ "node": ">=8" } }, + "node_modules/shescape": { + "version": "1.7.4", + "resolved": "https://registry.npmjs.org/shescape/-/shescape-1.7.4.tgz", + "integrity": "sha512-6eaKkGvkiR86VmRfFaT1RYP0DtYnOj3u3WR41ItGqADBZMtr0lI4iTnqakE65gnRwHIF7XNvqA9oaE31EZsB7Q==", + "deprecated": "v1 is deprecated and will no longer be supported after 2023-12-06", + "license": "MPL-2.0", + "dependencies": { + "which": "^2.0.0" + }, + "engines": { + "node": "^10.13.0 || ^12 || ^14 || ^16 || ^18 || ^19 || ^20" + } + }, "node_modules/signal-exit": { "version": "3.0.7", "resolved": "https://registry.npmjs.org/signal-exit/-/signal-exit-3.0.7.tgz", @@ -9607,9 +9620,9 @@ } }, "node_modules/snyk-docker-plugin": { - "version": "8.4.1", - "resolved": "https://registry.npmjs.org/snyk-docker-plugin/-/snyk-docker-plugin-8.4.1.tgz", - "integrity": "sha512-n9kmo0Kei7vnOLSXvHqtDnV3DwgLMP0+hwG4ptg/y+53i0Meyac7Fi+jh8srtFlvtpqjWXkO2JiRJqYkzG+OFQ==", + "version": "8.4.2", + "resolved": "https://registry.npmjs.org/snyk-docker-plugin/-/snyk-docker-plugin-8.4.2.tgz", + "integrity": "sha512-gPHqyvKp5K5DpUJmWL/gosWI+GIfx9o+oZCgm+fmCGE1zTjUTKBzeVZ0kJipe2gAzUtWr3LrKw9PvuxXWSPAAQ==", "license": "Apache-2.0", "dependencies": { "@snyk/composer-lockfile-parser": "^1.4.1", @@ -9629,6 +9642,7 @@ "mkdirp": "^1.0.4", "packageurl-js": "1.2.0", "semver": "^7.6.3", + "shescape": "^1.7.4", "snyk-nodejs-lockfile-parser": "^2.0.0", "snyk-poetry-lockfile-parser": "^1.4.0", "snyk-resolve-deps": "^4.7.1", diff --git a/package.json b/package.json index dad97961e..27322301a 100644 --- a/package.json +++ b/package.json @@ -47,7 +47,7 @@ "packageurl-js": "^1.2.1", "sleep-promise": "^9.1.0", "snyk-config": "5.3.0", - "snyk-docker-plugin": "8.4.1", + "snyk-docker-plugin": "8.4.2", "source-map-support": "^0.5.21", "tunnel": "0.0.6", "typescript": "4.9.5",