Skip to content

fix: bump uuid resolution to 11.1.1#565

Merged
shanghaikid merged 1 commit into
mainfrom
fix/dependabot-uuid-11-1-1
May 7, 2026
Merged

fix: bump uuid resolution to 11.1.1#565
shanghaikid merged 1 commit into
mainfrom
fix/dependabot-uuid-11-1-1

Conversation

@shanghaikid
Copy link
Copy Markdown
Contributor

related: https://github.com/milvus-io/milvus-sdk-node/security/dependabot/249

Summary

  • Bump the thrift/uuid Yarn resolution from 11.1.0 to patched 11.1.1.
  • Update yarn.lock so transitive uuid resolves to a version fixed for GHSA-w5hq-g745-h8pq / CVE-2026-41907.

Test plan

  • yarn why uuid
  • yarn build

Signed-off-by: ryjiang <jiangruiyi@gmail.com>
@sre-ci-robot
Copy link
Copy Markdown

[APPROVALNOTIFIER] This PR is NOT APPROVED

This pull-request has been approved by: shanghaikid

The full list of commands accepted by this bot can be found here.

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@shanghaikid shanghaikid merged commit 2d5a46a into main May 7, 2026
1 of 2 checks passed
@shanghaikid shanghaikid deleted the fix/dependabot-uuid-11-1-1 branch May 7, 2026 07:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants