Skip to content

Commit 260f11d

Browse files
build: upgrade dependencies (#913)
## What This upgrades dependencies with security fixes. Relevant tickets: https://codefresh-io.atlassian.net/browse/CR-38262 https://codefresh-io.atlassian.net/browse/CR-39160 https://codefresh-io.atlassian.net/browse/CR-39186 https://codefresh-io.atlassian.net/browse/CR-39196 https://codefresh-io.atlassian.net/browse/CR-39198 https://codefresh-io.atlassian.net/browse/CR-39206 https://codefresh-io.atlassian.net/browse/CR-39209 https://codefresh-io.atlassian.net/browse/CR-39212 https://codefresh-io.atlassian.net/browse/CR-39424 https://codefresh-io.atlassian.net/browse/CR-39543 https://codefresh-io.atlassian.net/browse/CR-39664 https://codefresh-io.atlassian.net/browse/CR-39871 <!-- ⚠️ ↓↓↓ Auto-generated by Codefresh CI. Any edits may be overridden. ↓↓↓ ⚠️ --> ## Security Report > [!NOTE] > Compared security scans: > > **Current image**: [quay.io/codefresh/cli:cr-39206@sha256:88e56764d203964c161809909dbb3da70790b7c84a44cf35bb7fc17aee44caa0](https://app.prismacloud.io/compute?computeState=/monitor/vulnerabilities/images/ci?search%3Dsha256%253A88e56764d203964c161809909dbb3da70790b7c84a44cf35bb7fc17aee44caa0) > > **Baseline**: [quay.io/codefresh/cli:master@sha256:466e9fe022b15f8cf9ef70facf79dd52d8c88e79cdc5ef1bfb14fd00249d2291](https://app.prismacloud.io/compute?computeState=/monitor/vulnerabilities/images/ci?search%3Dsha256%253A466e9fe022b15f8cf9ef70facf79dd52d8c88e79cdc5ef1bfb14fd00249d2291) > [!IMPORTANT] > Current summary is in beta mode. > Please analyze [the full scan report](https://app.prismacloud.io/compute?computeState=/monitor/vulnerabilities/images/ci?search%3Dsha256%253A88e56764d203964c161809909dbb3da70790b7c84a44cf35bb7fc17aee44caa0) for comprehensive details. ### Fixed CVEs: 22 #### 🟣 Critical: 1 - CVE-2026-31789 in `openssl@3.5.5-r0` at `unknown path` #### 🔴 High: 11 - CVE-2026-28387 in `openssl@3.5.5-r0` at `unknown path` - CVE-2026-31790 in `openssl@3.5.5-r0` at `unknown path` - CVE-2026-29181 in `go.opentelemetry.io/otel@v1.36.0` at `/usr/local/bin/kubectl` - CVE-2026-28390 in `openssl@3.5.5-r0` at `unknown path` - CVE-2026-28389 in `openssl@3.5.5-r0` at `unknown path` - CVE-2026-28388 in `openssl@3.5.5-r0` at `unknown path` - CVE-2026-27137 in `crypto/x509@1.26.0` at `/usr/local/bin/yq` - CVE-2026-2673 in `openssl@3.5.5-r0` at `unknown path` - CVE-2026-25679 in `net/url@1.25.7` at `/usr/local/bin/kubectl` - CVE-2026-25679 in `net/url@1.26.0` at `/usr/local/bin/yq` - CVE-2026-35469 in `github.com/moby/spdystream@v0.5.0` at `/usr/local/bin/kubectl` #### 🟠 Medium: 5 - CVE-2026-41650 in `fast-xml-parser@5.5.8` at `/cf-cli/node_modules/fast-xml-parser` - CVE-2026-27138 in `crypto/x509@1.26.0` at `/usr/local/bin/yq` - CVE-2026-32288 in `archive/tar@1.25.7` at `/usr/local/bin/kubectl` - CVE-2026-27171 in `zlib@1.3.1-r2` at `unknown path` - CVE-2026-42338 in `ip-address@9.0.5` at `/cf-cli/node_modules/ip-address` #### 🟡 Low: 5 - CVE-2026-27139 in `os@1.25.7` at `/usr/local/bin/kubectl` - CVE-2026-27139 in `os@1.26.0` at `/usr/local/bin/yq` - CVE-2026-6042 in `musl@1.2.5-r21` at `unknown path` - CVE-2026-40200 in `musl@1.2.5-r21` at `unknown path` - CVE-2026-27135 in `nghttp2@1.68.0-r0` at `unknown path` [🔗 View all related Jira tickets](https://codefresh-io.atlassian.net/jira/software/c/projects/CR/issues?jql=project%20%3D%20CR%20AND%20%22security%20image%5Bshort%20text%5D%22%20~%20%22cli%22%20AND%20(%22security%20cve%5Bshort%20text%5D%22%20~%20%22CVE-2026-31789%22%20OR%20%22security%20cve%5Bshort%20text%5D%22%20~%20%22CVE-2026-28387%22%20OR%20%22security%20cve%5Bshort%20text%5D%22%20~%20%22CVE-2026-31790%22%20OR%20%22security%20cve%5Bshort%20text%5D%22%20~%20%22CVE-2026-29181%22%20OR%20%22security%20cve%5Bshort%20text%5D%22%20~%20%22CVE-2026-28390%22%20OR%20%22security%20cve%5Bshort%20text%5D%22%20~%20%22CVE-2026-28389%22%20OR%20%22security%20cve%5Bshort%20text%5D%22%20~%20%22CVE-2026-28388%22%20OR%20%22security%20cve%5Bshort%20text%5D%22%20~%20%22CVE-2026-27137%22%20OR%20%22security%20cve%5Bshort%20text%5D%22%20~%20%22CVE-2026-2673%22%20OR%20%22security%20cve%5Bshort%20text%5D%22%20~%20%22CVE-2026-25679%22%20OR%20%22security%20cve%5Bshort%20text%5D%22%20~%20%22CVE-2026-25679%22%20OR%20%22security%20cve%5Bshort%20text%5D%22%20~%20%22CVE-2026-35469%22%20OR%20%22security%20cve%5Bshort%20text%5D%22%20~%20%22CVE-2026-41650%22%20OR%20%22security%20cve%5Bshort%20text%5D%22%20~%20%22CVE-2026-27138%22%20OR%20%22security%20cve%5Bshort%20text%5D%22%20~%20%22CVE-2026-32288%22%20OR%20%22security%20cve%5Bshort%20text%5D%22%20~%20%22CVE-2026-27171%22%20OR%20%22security%20cve%5Bshort%20text%5D%22%20~%20%22CVE-2026-42338%22%20OR%20%22security%20cve%5Bshort%20text%5D%22%20~%20%22CVE-2026-27139%22%20OR%20%22security%20cve%5Bshort%20text%5D%22%20~%20%22CVE-2026-27139%22%20OR%20%22security%20cve%5Bshort%20text%5D%22%20~%20%22CVE-2026-6042%22%20OR%20%22security%20cve%5Bshort%20text%5D%22%20~%20%22CVE-2026-40200%22%20OR%20%22security%20cve%5Bshort%20text%5D%22%20~%20%22CVE-2026-27135%22)%20ORDER%20BY%20created%20ASC) <!-- ⚠️ ↑↑↑ Auto-generated by Codefresh CI. Any edits may be overridden. ↑↑↑ ⚠️ -->
1 parent 85cfc07 commit 260f11d

3 files changed

Lines changed: 1980 additions & 1592 deletions

File tree

Dockerfile

Lines changed: 5 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,4 @@
1-
FROM node:24.13.0-alpine3.23
1+
FROM node:24.15.0-alpine3.23
22
ARG TARGETPLATFORM
33
RUN apk --update add --no-cache \
44
bash \
@@ -7,17 +7,17 @@ RUN apk --update add --no-cache \
77
git \
88
jq
99
RUN npm upgrade -g npm
10-
COPY --from=mikefarah/yq:4.52.4 /usr/bin/yq /usr/local/bin/yq
11-
ADD --chmod=775 https://dl.k8s.io/release/v1.35.3/bin/${TARGETPLATFORM}/kubectl /usr/local/bin/kubectl
10+
COPY --from=mikefarah/yq:4.53.2 /usr/bin/yq /usr/local/bin/yq
11+
ADD --chmod=775 https://dl.k8s.io/release/v1.36.0/bin/${TARGETPLATFORM}/kubectl /usr/local/bin/kubectl
1212
WORKDIR /cf-cli
1313
COPY package.json yarn.lock check-version.js run-check-version.js /cf-cli/
1414
RUN yarn install --prod --frozen-lockfile && \
1515
yarn cache clean
1616
COPY . /cf-cli
1717
RUN yarn generate-completion
1818

19-
#purpose of security
20-
RUN npm -g uninstall npm
19+
# Purpose of security:
20+
RUN npm uninstall -g --logs-max=0 corepack npm
2121

2222
RUN ln -s $(pwd)/lib/interface/cli/codefresh /usr/local/bin/codefresh
2323
RUN codefresh components update --location components

package.json

Lines changed: 3 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
11
{
22
"name": "codefresh",
3-
"version": "1.1.3",
3+
"version": "1.1.4",
44
"description": "Codefresh command line utility",
55
"main": "index.js",
66
"preferGlobal": true,
@@ -41,14 +41,13 @@
4141
"resolutions": {
4242
"json-schema": "^0.4.0",
4343
"ansi-regex": "^5.0.1",
44-
"kubernetes-client/@kubernetes/client-node": ">=0.22.2",
44+
"kubernetes-client/@kubernetes/client-node": "^0.22.2",
4545
"tough-cookie": "^4.1.3",
4646
"openid-client": "^4.9.0",
4747
"**/request/form-data": "^2.5.5",
48-
"**/request/qs": "6.14.2"
48+
"**/request/qs": "^6.14.2"
4949
},
5050
"dependencies": {
51-
"@codefresh-io/docker-reference": "^0.0.5",
5251
"adm-zip": "^0.5.5",
5352
"ajv": "^6.14.0",
5453
"bluebird": "^3.5.1",
@@ -73,21 +72,17 @@
7372
"kefir": "^3.8.1",
7473
"kubernetes-client": "^9.0.0",
7574
"lodash": "^4.17.23",
76-
"mkdirp": "^0.5.1",
7775
"moment": "^2.29.4",
7876
"mongodb": "^4.17.2",
7977
"node-forge": "^1.3.0",
8078
"ora": "^5.4.1",
81-
"prettyjson": "^1.2.5",
82-
"promise-retry": "^2.0.1",
8379
"recursive-readdir": "^2.2.3",
8480
"request": "^2.88.0",
8581
"request-promise": "^4.2.6",
8682
"requestretry": "^7.0.2",
8783
"rimraf": "^2.6.2",
8884
"semver": "^7.5.4",
8985
"tar-stream": "^2.2.0",
90-
"uuid": "^3.1.0",
9186
"yaml": "^1.10.0",
9287
"yargs": "^15.4.1",
9388
"yargs-parser": "^13.0.0",

0 commit comments

Comments
 (0)