Skip to content

Commit 24e9dd7

Browse files
authored
Merge pull request #228 from grafana/227-fix-cves
fix CVE-2025-7783
2 parents 1391326 + 161fd9c commit 24e9dd7

File tree

2 files changed

+30
-22
lines changed

2 files changed

+30
-22
lines changed

dashboard/assets/yarn.lock

Lines changed: 22 additions & 22 deletions
Original file line numberDiff line numberDiff line change
@@ -199,24 +199,24 @@
199199
"@babel/helper-validator-identifier" "^7.27.1"
200200

201201
"@emnapi/core@^1.1.0":
202-
version "1.4.4"
203-
resolved "https://registry.yarnpkg.com/@emnapi/core/-/core-1.4.4.tgz#76620673f3033626c6d79b1420d69f06a6bb153c"
204-
integrity sha512-A9CnAbC6ARNMKcIcrQwq6HeHCjpcBZ5wSx4U01WXCqEKlrzB9F9315WDNHkrs2xbx7YjjSxbUYxuN6EQzpcY2g==
202+
version "1.4.5"
203+
resolved "https://registry.yarnpkg.com/@emnapi/core/-/core-1.4.5.tgz#bfbb0cbbbb9f96ec4e2c4fd917b7bbe5495ceccb"
204+
integrity sha512-XsLw1dEOpkSX/WucdqUhPWP7hDxSvZiY+fsUC14h+FtQ2Ifni4znbBt8punRX+Uj2JG/uDb8nEHVKvrVlvdZ5Q==
205205
dependencies:
206-
"@emnapi/wasi-threads" "1.0.3"
206+
"@emnapi/wasi-threads" "1.0.4"
207207
tslib "^2.4.0"
208208

209209
"@emnapi/runtime@^1.1.0":
210-
version "1.4.4"
211-
resolved "https://registry.yarnpkg.com/@emnapi/runtime/-/runtime-1.4.4.tgz#19a8f00719c51124e2d0fbf4aaad3fa7b0c92524"
212-
integrity sha512-hHyapA4A3gPaDCNfiqyZUStTMqIkKRshqPIuDOXv1hcBnD4U3l8cP0T1HMCfGRxQ6V64TGCcoswChANyOAwbQg==
210+
version "1.4.5"
211+
resolved "https://registry.yarnpkg.com/@emnapi/runtime/-/runtime-1.4.5.tgz#c67710d0661070f38418b6474584f159de38aba9"
212+
integrity sha512-++LApOtY0pEEz1zrd9vy1/zXVaVJJ/EbAF3u0fXIzPJEDtnITsBGbbK0EkM72amhl/R5b+5xx0Y/QhcVOpuulg==
213213
dependencies:
214214
tslib "^2.4.0"
215215

216-
"@emnapi/[email protected].3":
217-
version "1.0.3"
218-
resolved "https://registry.yarnpkg.com/@emnapi/wasi-threads/-/wasi-threads-1.0.3.tgz#83fa228bde0e71668aad6db1af4937473d1d3ab1"
219-
integrity sha512-8K5IFFsQqF9wQNJptGbS6FNKgUTsSRYnTqNCG1vPP8jFdjSv18n2mQfJpkt2Oibo9iBEzcDnDxNwKTzC7svlJw==
216+
"@emnapi/[email protected].4":
217+
version "1.0.4"
218+
resolved "https://registry.yarnpkg.com/@emnapi/wasi-threads/-/wasi-threads-1.0.4.tgz#703fc094d969e273b1b71c292523b2f792862bf4"
219+
integrity sha512-PJR+bOmMOPH8AtcTGAyYNiuJ3/Fcoj2XN/gBEWzDIKh254XO+mM9XoXHk5GNEhodxeMznbg7BlRojVbKN+gC6g==
220220
dependencies:
221221
tslib "^2.4.0"
222222

@@ -2141,12 +2141,12 @@ available-typed-arrays@^1.0.7:
21412141
possible-typed-array-names "^1.0.0"
21422142

21432143
axios@^1.8.3:
2144-
version "1.10.0"
2145-
resolved "https://registry.yarnpkg.com/axios/-/axios-1.10.0.tgz#af320aee8632eaf2a400b6a1979fa75856f38d54"
2146-
integrity sha512-/1xYAC4MP/HEG+3duIhFr4ZQXR4sQXOIe+o6sdqzeykGLx6Upp/1p8MHqhINOvGeP7xyNHe7tsiJByc4SSVUxw==
2144+
version "1.11.0"
2145+
resolved "https://registry.yarnpkg.com/axios/-/axios-1.11.0.tgz#c2ec219e35e414c025b2095e8b8280278478fdb6"
2146+
integrity sha512-1Lx3WLFQWm3ooKDYZD1eXmoGO9fxYQjrycfHFC8P0sCfQVXyROp0p9PFWBehewBOdCwHc+f/b8I0fMto5eSfwA==
21472147
dependencies:
21482148
follow-redirects "^1.15.6"
2149-
form-data "^4.0.0"
2149+
form-data "^4.0.4"
21502150
proxy-from-env "^1.1.0"
21512151

21522152
babel-plugin-transform-hook-names@^1.0.2:
@@ -3765,10 +3765,10 @@ foreground-child@^3.1.0:
37653765
cross-spawn "^7.0.6"
37663766
signal-exit "^4.0.1"
37673767

3768-
form-data@^4.0.0:
3769-
version "4.0.3"
3770-
resolved "https://registry.yarnpkg.com/form-data/-/form-data-4.0.3.tgz#608b1b3f3e28be0fccf5901fc85fb3641e5cf0ae"
3771-
integrity sha512-qsITQPfmvMOSAdeyZ+12I1c+CKSstAFAwu+97zrnWAbIr5u8wfsExUzCesVLC8NgHuRUqNN4Zy6UPWUTRGslcA==
3768+
form-data@^4.0.4:
3769+
version "4.0.4"
3770+
resolved "https://registry.yarnpkg.com/form-data/-/form-data-4.0.4.tgz#784cdcce0669a9d68e94d11ac4eea98088edd2c4"
3771+
integrity sha512-KrGhL9Q4zjj0kiUt5OO4Mr/A/jlI2jDYs5eHBpYHPcBEVSiipAvn2Ko2HnPe20rmcuuvMHNdZFp+4IlGTMF0Ow==
37723772
dependencies:
37733773
asynckit "^0.4.0"
37743774
combined-stream "^1.0.8"
@@ -6021,9 +6021,9 @@ picomatch@^2.0.4, picomatch@^2.2.1, picomatch@^2.2.2, picomatch@^2.3.1:
60216021
integrity sha512-JU3teHTNjmE2VCGFzuY8EXzCDVwEqB2a8fsIvwaStHhAWJEeVd1o1QD80CU6+ZdEXXSLbSsuLwJjkCBWqRQUVA==
60226022

60236023
picomatch@^4.0.2:
6024-
version "4.0.2"
6025-
resolved "https://registry.yarnpkg.com/picomatch/-/picomatch-4.0.2.tgz#77c742931e8f3b8820946c76cd0c1f13730d1dab"
6026-
integrity sha512-M7BAV6Rlcy5u+m6oPhAPFgJTzAioX/6B0DxyvDlo9l8+T3nLKbrczg2WLUyzd45L8RqfUMyGPzekbMvX2Ldkwg==
6024+
version "4.0.3"
6025+
resolved "https://registry.yarnpkg.com/picomatch/-/picomatch-4.0.3.tgz#796c76136d1eead715db1e7bad785dedd695a042"
6026+
integrity sha512-5gTmgEY/sqK6gFXLIsQNH19lWb4ebPDLA4SdLP7dsWkIXHWlG66oPuVvXSGFPppYZz8ZDZq0dYYrbHfBCVUb1Q==
60276027

60286028
60296029
version "5.0.0"

releases/v0.7.11.md

Lines changed: 8 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,8 @@
1+
xk6-dashboard `v0.7.11` is here 🎉!
2+
3+
This patch release resolves one security vulnerability, through upgrading lerna to v8.2.4
4+
5+
The following vulnerability have been addressed:
6+
7+
- CVE-2025-7783
8+

0 commit comments

Comments
 (0)