Skip to content

[release-1.9/orchestrator] bump 1.9.9 CVEs - #4591

Open
JessicaJHee wants to merge 1 commit into
redhat-developer:release-1.9/orchestratorfrom
JessicaJHee:1.9.9-orchestrator-cves
Open

[release-1.9/orchestrator] bump 1.9.9 CVEs#4591
JessicaJHee wants to merge 1 commit into
redhat-developer:release-1.9/orchestratorfrom
JessicaJHee:1.9.9-orchestrator-cves

Conversation

@JessicaJHee

Copy link
Copy Markdown
Member

Hey, I just made a Pull Request!

Description

Bumps transitive dependencies to address CVEs for rhdh-plugins orchestrator workspace (1.9.9 release stream).

Package Version CVEs
@xmldom/xmldom 0.8.10 → 0.8.15 CVE-2026-83605, CVE-2026-83608, CVE-2026-83613, CVE-2026-83614, CVE-2026-83615, CVE-2026-83619, CVE-2026-83607, CVE-2026-83616
fast-uri 3.0.3 → 3.1.7 CVE-2026-75975, CVE-2026-75899, CVE-2026-6322, CVE-2026-75931, CVE-2026-76172, CVE-2026-84394, CVE-2026-84292
[DEV] handlebars 4.7.8 → 4.7.9 CVE-2026-33937, CVE-2026-33938, CVE-2026-33941
[DEV] fflate (not PROD) 0.8.2 → 0.8.3 CVE-2026-45820
[DEV] immutable 3.8.2 → 3.8.4 CVE-2026-59879
[DEV] smol-toml 1.3.1 → 1.8.0 CVE-2026-85730
[DEV - partial] undici 7.28.0 → 7.29.1 CVE-2026-19534 (vulnerable under infinispan

Fixed with yarn up -R in orchestrator workspace.

Which issue(s) does this PR fix

@xmldom/xmldom tickets:

fast-uri tickets:

✔️ Checklist

  • A changeset describing the change and affected packages. (more info)
  • Added or Updated documentation
  • Tests for new functionality and regression tests for bug fixes
  • Screenshots attached (for UI changes)

Signed-off-by: Jessica He <jhe@redhat.com>
@sonarqubecloud

sonarqubecloud Bot commented Sep 4, 2026

Copy link
Copy Markdown

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant