apache / apache/druid

Security: update NPMs in web-console/package-lock.json due to security issues

Open
#12,424 0 comments 0 reactions 0 assignees View on GitHub
Area - Dependencies Security
Dominant language
Java
Stars
14.1k
Forks
3.8k
Avg merge
2d 58m
Merged PRs (30d)
233

Description

### Description

large number of NPMs in use that have security issues - similar to #12423 but different module

### Motivation

Please provide the following for the desired feature or change:
- A detailed description of the intended use case, if applicable
- Rationale for why the desired feature/change would be beneficial

Contributor guide

Open the contributing guide

Research direction

Begin with web-console/package-lock.json and identify the NPM dependencies associated with the reported security issues; compare the scope with issue #12423 if that context is available. Done means the vulnerable dependencies are updated in that lockfile and the resulting dependency tree no longer contains the reported issues.

Written by the indexing model from the issue text.

Assessment

Tech stack
javascript
Domain
frontend, security
Issue type
Bug
Difficulty
3/5
Estimated time
1-2 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
38/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.