Skip to content

fix: remediate Example TA dependency vulnerabilities - #48

Open
Sukupate wants to merge 1 commit into
mainfrom
fix/vulns-splunk-example-ta-batch-20260909T000000Z
Open

Sukupate wants to merge 1 commit into
mainfrom
fix/vulns-splunk-example-ta-batch-20260909T000000Z

Conversation

@Sukupate

@Sukupate Sukupate commented Sep 9, 2026

Copy link
Copy Markdown
Contributor

Summary

Remediates five dependency vulnerability tickets in the Example TA UI dependency graph.

Remediated tickets

  • VULN-108207: jsonata 2.0.6 → 2.2.0
  • VULN-108190: js-yaml 4.1.0 → 4.3.0
  • VULN-108187: js-yaml 3.14.1 → 3.15.0
  • VULN-108052: protocol-buffers-schema 3.6.0 → 3.6.1
  • VULN-108008: fast-uri 3.0.6 → 3.1.5

Validation

  • Clean npm install from ui/package-lock.json
  • Jest: 4 tests passed
  • ESLint and Prettier passed
  • Production webpack build passed

Jira closure

After merge and fresh FOSSA verification, close each ticket with VEX status resolved and justification upgraded_to_safe_version.

Upgrade jsonata to 2.2.0, js-yaml to 4.3.0 and 3.15.0, protocol-buffers-schema to 3.6.1, and fast-uri to 3.1.5.\n\nTickets: VULN-108207, VULN-108190, VULN-108187, VULN-108052, VULN-108008
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant