Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Manual backport 2.x][CVE-2022-25881] Resolve http-cache-semantics to 4.1.1 (#3409) #3436

Merged

Conversation

zhongnansu
Copy link
Member

@zhongnansu zhongnansu commented Feb 16, 2023

Manual backport #3409 to 2.x

Check List

  • All tests pass
    • yarn test:jest
    • yarn test:jest_integration
    • yarn test:ftr
  • New functionality includes testing.
  • New functionality has been documented.
  • Update CHANGELOG.md
  • Commits are signed per the DCO using --signoff

@zhongnansu zhongnansu requested a review from a team as a code owner February 16, 2023 23:36
@codecov-commenter
Copy link

Codecov Report

Merging #3436 (4ac1f7b) into 2.x (4a7c97e) will not change coverage.
The diff coverage is n/a.

📣 This organization is not using Codecov’s GitHub App Integration. We recommend you install it so Codecov can continue to function properly for your repositories. Learn more

@@           Coverage Diff           @@
##              2.x    #3436   +/-   ##
=======================================
  Coverage   66.50%   66.50%           
=======================================
  Files        3203     3203           
  Lines       61331    61331           
  Branches     9453     9453           
=======================================
  Hits        40789    40789           
+ Misses      18282    18281    -1     
- Partials     2260     2261    +1     
Flag Coverage Δ
Linux 66.50% <ø> (ø)

Flags with carried forward coverage won't be shown. Click here to find out more.

Impacted Files Coverage Δ
...ic/application/models/sense_editor/sense_editor.ts 64.00% <0.00%> (-1.78%) ⬇️
packages/osd-optimizer/src/node/cache.ts 52.63% <0.00%> (+2.63%) ⬆️
...s/osd-optimizer/src/node/node_auto_tranpilation.ts 87.75% <0.00%> (+4.08%) ⬆️

Help us with your feedback. Take ten seconds to tell us how you rate us. Have a feature suggestion? Share it here.

@joshuarrrr joshuarrrr added v2.6.0 cve Security vulnerabilities detected by Dependabot or Mend labels Feb 17, 2023
@ananzh ananzh requested a review from abbyhu2000 February 17, 2023 18:59
@kristenTian kristenTian merged commit f63e339 into opensearch-project:2.x Feb 17, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
cve Security vulnerabilities detected by Dependabot or Mend v2.6.0
Projects
None yet
Development

Successfully merging this pull request may close these issues.

6 participants