dashboard icon indicating copy to clipboard operation
dashboard copied to clipboard

Update dependencies version

Open RainbowMango opened this issue 11 months ago • 3 comments

What would you like to be added: We need to update the dependencies version due to security concerns:

Dependencies in ui/apps/dashboard/pnpm-lock.yaml:

  • [ ] Upgrade cross-spawn to version 7.0.5 or later.
  • [ ] Upgrade nanoid to version 3.3.8 or later.
  • [ ] Upgrade rollup to version 4.22.4 or later.
  • [ ] Upgrade axios to version 1.7.4 or later.
  • [ ] Upgrade vite to version 5.3.6 or later.
  • [ ] Upgrade micromatch to version 4.0.8 or later.

Dependencies in go.mod

  • [x] Upgrade github.com/golang-jwt/jwt/v4 to version 4.5.1 or later. (@RainbowMango, #158)
  • [x] Upgrade golang.org/x/crypto to version 0.31.0 or later. (@adwait-godbole, #185)
  • [x] Upgrade golang.org/x/net to version 0.33.0 or later. (@adwait-godbole, #185)

Why is this needed:

RainbowMango avatar Jan 09 '25 07:01 RainbowMango

/assign

warjiang avatar Jan 10 '25 03:01 warjiang

Hi @warjiang any update?

RainbowMango avatar Feb 07 '25 07:02 RainbowMango

  • cross-spawn is introduced by tsup, submited PR but no response: https://github.com/egoist/tsup/pull/1275
  • axios and vite are outdated:
    • axios: Image

    • vite: Image

warjiang avatar Feb 07 '25 08:02 warjiang