apache / apache/druid

Security: update NPMs in website/package-lock.json due to security issues

Open
#12,423 0 comments 0 reactions 0 assignees View on GitHub
Area - Dependencies Security
Dominant language
Java
Stars
14.1k
Forks
3.8k
Avg merge
2d 58m
Merged PRs (30d)
233

Description

### Description

There are a large number of NPMs with security issues in use - lodash, postcss, inmer, url-parse are ones that pop up a lot in dependabot anayses.

### Motivation

Please provide the following for the desired feature or change:
- A detailed description of the intended use case, if applicable
- Rationale for why the desired feature/change would be beneficial

Contributor guide

Open the contributing guide

Research direction

Start by inspecting website/package-lock.json and the lodash, postcss, inmer, and url-parse entries mentioned in the issue, then review the related Dependabot security findings. Done means the reported vulnerable NPM dependencies are updated in the lockfile and the resulting dependency state is checked.

Written by the indexing model from the issue text.

Assessment

Tech stack
javascript
Domain
build-system, frontend, security
Issue type
Bug
Difficulty
3/5
Estimated time
1-2 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
45/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.