Fix security vulnerabilities detected by Trivy
- CVE-2025-64756: glob CLI command injection - added override to use glob ^11.1.0 - CVE-2025-13466: body-parser DoS - added override to use body-parser ^2.2.1 - CVE-2025-64718: js-yaml prototype pollution - updated to js-yaml ^4.1.1 - BusyBox vulnerabilities (netstat, tar) - added apk upgrade to all Dockerfiles Changes: - backend/package.json: Updated js-yaml, added overrides for glob, body-parser - frontend/package.json: Added overrides for glob, js-yaml - All Dockerfiles: Added 'apk upgrade --no-cache' to get latest security patches - backend/Dockerfile.dev: Updated from node:18-alpine to node:20-alpine
This commit is contained in:
@@ -33,7 +33,7 @@
|
||||
"i18next-browser-languagedetector": "^8.2.0",
|
||||
"i18next-http-backend": "^3.0.2",
|
||||
"joi": "^17.9.1",
|
||||
"js-yaml": "^4.1.0",
|
||||
"js-yaml": "^4.1.1",
|
||||
"jsonwebtoken": "^9.0.0",
|
||||
"knex": "^2.4.2",
|
||||
"mime-types": "^3.0.1",
|
||||
@@ -59,6 +59,9 @@
|
||||
"overrides": {
|
||||
"prebuild-install": {
|
||||
"tar-fs": "2.1.4"
|
||||
}
|
||||
},
|
||||
"glob": "^11.1.0",
|
||||
"body-parser": "^2.2.1",
|
||||
"js-yaml": "^4.1.1"
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user