monthly update of vulnerability report Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
diff --git a/VULNERABILITY.md b/VULNERABILITY.md index 0025521..4529f99 100644 --- a/VULNERABILITY.md +++ b/VULNERABILITY.md
@@ -1,11 +1,63 @@ -<!--\n ~ Licensed to the Apache Software Foundation (ASF) under one or more\n ~ contributor license agreements. See the NOTICE file distributed with\n ~ this work for additional information regarding copyright ownership.\n ~ The ASF licenses this file to You under the Apache License, Version 2.0\n ~ (the "License"); you may not use this file except in compliance with\n ~ the License. You may obtain a copy of the License at\n ~\n ~ http://www.apache.org/licenses/LICENSE-2.0\n ~\n ~ Unless required by applicable law or agreed to in writing, software\n ~ distributed under the License is distributed on an "AS IS" BASIS,\n ~ WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.\n ~ See the License for the specific language governing permissions and\n ~ limitations under the License.\n ~\n --> -| OSV URL | CVSS | Ecosystem | Package | Version | Source | -| --- | --- | --- | --- | --- | --- | -| https://osv.dev/GHSA-6mjq-h674-j845 | 6.5 | Maven | io.netty:netty-handler | 4.1.72.Final | pom.xml | -| https://osv.dev/GHSA-w596-4wvx-j9j6<br/>https://osv.dev/PYSEC-2022-42969 | 7.5 | PyPI | py | 1.11.0 | streampipes-client-python/poetry.lock | -| https://osv.dev/GHSA-269g-pwp5-87pp | 4.4 | Maven | junit:junit (dev) | 4.8.2 | streampipes-maven-plugin/pom.xml | -| https://osv.dev/GHSA-4943-9vgg-gr5r | 6.1 | npm | quill | 1.3.7 | ui/package-lock.json | -| https://osv.dev/GHSA-f5x3-32g6-xq36 | 6.5 | npm | tar (dev) | 6.2.0 | ui/package-lock.json | -| https://osv.dev/GHSA-9qxr-qj54-h672 | 2.6 | npm | undici (dev) | 6.7.1 | ui/package-lock.json | -| https://osv.dev/GHSA-m4v8-wqvr-p9f7 | 3.9 | npm | undici (dev) | 6.7.1 | ui/package-lock.json | -| https://osv.dev/GHSA-8jhw-289h-jh2g | 5.9 | npm | vite (dev) | 5.1.5 | ui/package-lock.json | +<!-- + ~ Licensed to the Apache Software Foundation (ASF) under one or more + ~ contributor license agreements. See the NOTICE file distributed with + ~ this work for additional information regarding copyright ownership. + ~ The ASF licenses this file to You under the Apache License, Version 2.0 + ~ (the "License"); you may not use this file except in compliance with + ~ the License. You may obtain a copy of the License at + ~ + ~ http://www.apache.org/licenses/LICENSE-2.0 + ~ + ~ Unless required by applicable law or agreed to in writing, software + ~ distributed under the License is distributed on an "AS IS" BASIS, + ~ WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. + ~ See the License for the specific language governing permissions and + ~ limitations under the License. + ~ + --> +Starting filesystem walk for root: / +End status: 2772 dirs visited, 7881 inodes visited, 107 Extract calls, 11.554972498s elapsed, 11.554972648s wall time +Filtered 9 local/unscannable package/s from the scan. +Total 22 packages affected by 37 known vulnerabilities (1 Critical, 10 High, 11 Medium, 6 Low, 9 Unknown) from 4 ecosystems. +36 vulnerabilities can be fixed. + + +| OSV URL | CVSS | Ecosystem | Package | Version | Fixed Version | Source | +| --- | --- | --- | --- | --- | --- | --- | +| https://osv.dev/GO-2024-2687 | | Go | stdlib | 1.21.6 | 1.21.9 | streampipes-client-e2e/go-client-e2e/go.mod | +| https://osv.dev/GO-2025-3373 | | Go | stdlib | 1.21.6 | 1.22.11 | streampipes-client-e2e/go-client-e2e/go.mod | +| https://osv.dev/GO-2025-3750 | | Go | stdlib | 1.21.6 | 1.23.10 | streampipes-client-e2e/go-client-e2e/go.mod | +| https://osv.dev/GO-2025-3373 | | Go | stdlib | 1.21.99 | 1.22.11 | streampipes-client-go/go.mod | +| https://osv.dev/GO-2025-3420 | | Go | stdlib | 1.21.99 | 1.22.11 | streampipes-client-go/go.mod | +| https://osv.dev/GO-2025-3563 | | Go | stdlib | 1.21.99 | 1.23.8 | streampipes-client-go/go.mod | +| https://osv.dev/GO-2025-3750 | | Go | stdlib | 1.21.99 | 1.23.10 | streampipes-client-go/go.mod | +| https://osv.dev/GO-2025-3751 | | Go | stdlib | 1.21.99 | 1.23.10 | streampipes-client-go/go.mod | +| https://osv.dev/GHSA-wxr5-93ph-8wr9 | 8.8 | Maven | commons-beanutils:commons-beanutils | 1.9.4 | 1.11.0 | archetypes/streampipes-archetype-pe-sinks-flink/src/main/resources/archetype-resources/pom.xml | +| https://osv.dev/GHSA-cx7f-g6mp-7hqm | 7.5 | Maven | org.springframework:spring-webmvc | 5.3.32 | 6.1.13 | streampipes-data-explorer-export/pom.xml | +| https://osv.dev/GHSA-g5vr-rgqm-vf78 | 7.5 | Maven | org.springframework:spring-webmvc | 5.3.32 | 6.1.14 | streampipes-data-explorer-export/pom.xml | +| https://osv.dev/GHSA-r936-gwx5-v52f | 5.9 | Maven | org.springframework:spring-webmvc | 5.3.32 | 6.2.10 | streampipes-data-explorer-export/pom.xml | +| https://osv.dev/GHSA-w3c8-7r8f-9jp8 | 5.3 | Maven | org.springframework:spring-webmvc | 5.3.32 | 5.3.42 | streampipes-data-explorer-export/pom.xml | +| https://osv.dev/GHSA-2c59-37c4-qrx5 | 10.0 | Maven | org.apache.parquet:parquet-avro | 1.12.0 | 1.15.1 | streampipes-extensions/streampipes-sinks-databases-jvm/pom.xml | +| https://osv.dev/GHSA-53wx-pr6q-m3j5 | 7.1 | Maven | org.apache.parquet:parquet-avro | 1.12.0 | 1.15.2 | streampipes-extensions/streampipes-sinks-databases-jvm/pom.xml | +| https://osv.dev/GHSA-vgq5-3255-v292 | 7.5 | Maven | org.apache.kafka:kafka-clients | 3.7.1 | 3.9.1 | streampipes-messaging-kafka/pom.xml | +| https://osv.dev/GHSA-vgq5-3255-v292 | 7.5 | Maven | org.apache.kafka:kafka-clients | 3.7.1 | 3.9.1 | streampipes-wrapper-kafka-streams/pom.xml | +| https://osv.dev/GHSA-33p9-3p43-82vq | 7.3 | PyPI | jupyter-core | 5.7.2 | 5.8.1 | streampipes-client-python/poetry.lock | +| https://osv.dev/PYSEC-2022-42969 | | PyPI | py (dev) | 1.11.0 | -- | streampipes-client-python/poetry.lock | +| https://osv.dev/GHSA-9hjg-9r4m-mvj7 | 5.3 | PyPI | requests | 2.32.3 | 2.32.4 | streampipes-client-python/poetry.lock | +| https://osv.dev/GHSA-7cx3-6m66-7c5m | 7.5 | PyPI | tornado | 6.4.2 | 6.5 | streampipes-client-python/poetry.lock | +| https://osv.dev/GHSA-48p4-8xcf-vxj5 | 5.3 | PyPI | urllib3 | 2.4.0 | 2.5.0 | streampipes-client-python/poetry.lock | +| https://osv.dev/GHSA-pq67-6m6q-mj2v | 5.3 | PyPI | urllib3 | 2.4.0 | 2.5.0 | streampipes-client-python/poetry.lock | +| https://osv.dev/GHSA-3xgq-45jj-v275 | 7.7 | npm | cross-spawn (dev) | 7.0.3 | 7.0.5 | streampipes-client-go/docs/package-lock.json | +| https://osv.dev/GHSA-952p-6rrq-rcjv | 5.3 | npm | micromatch (dev) | 4.0.7 | 4.0.8 | streampipes-client-go/docs/package-lock.json | +| https://osv.dev/GHSA-mwcw-c2x4-8c55 | 4.3 | npm | nanoid (dev) | 3.3.7 | 3.3.8 | streampipes-client-go/docs/package-lock.json | +| https://osv.dev/GHSA-4hjh-wcwx-xvwj | 7.5 | npm | axios (dev) | 1.11.0 | 1.12.0 | ui/package-lock.json | +| https://osv.dev/GHSA-7rqq-prvp-x9jh | 5.3 | npm | mermaid | 11.4.1 | 11.10.0 | ui/package-lock.json | +| https://osv.dev/GHSA-8gwm-58g9-j8pw | 5.1 | npm | mermaid | 11.4.1 | 11.10.0 | ui/package-lock.json | +| https://osv.dev/GHSA-52f5-9888-hmc6 | 2.5 | npm | tmp (dev) | 0.0.33 | 0.2.4 | ui/package-lock.json | +| https://osv.dev/GHSA-52f5-9888-hmc6 | 2.5 | npm | tmp (dev) | 0.2.3 | 0.2.4 | ui/package-lock.json | +| https://osv.dev/GHSA-g4jq-h2w9-997c | 2.3 | npm | vite (dev) | 6.2.7 | 6.3.6 | ui/package-lock.json | +| https://osv.dev/GHSA-jqfw-vq24-v9c3 | 2.3 | npm | vite (dev) | 6.2.7 | 6.3.6 | ui/package-lock.json | +| https://osv.dev/GHSA-g4jq-h2w9-997c | 2.3 | npm | vite (dev) | 6.3.5 | 6.3.6 | ui/package-lock.json | +| https://osv.dev/GHSA-jqfw-vq24-v9c3 | 2.3 | npm | vite (dev) | 6.3.5 | 6.3.6 | ui/package-lock.json | +| https://osv.dev/GHSA-4v9v-hfq4-rm2v | 5.3 | npm | webpack-dev-server (dev) | 5.2.0 | 5.2.1 | ui/package-lock.json | +| https://osv.dev/GHSA-9jgg-88mc-972h | 6.5 | npm | webpack-dev-server (dev) | 5.2.0 | 5.2.1 | ui/package-lock.json |