Skip to content

Conversation

@YounixM
Copy link
Member

@YounixM YounixM commented Mar 26, 2025

snyk-top-banner

Snyk has created this PR to fix 2 vulnerabilities in the yarn dependencies of this project.

Snyk changed the following file(s):

  • frontend/package.json
  • frontend/yarn.lock

Note for zero-installs users

If you are using the Yarn feature zero-installs that was introduced in Yarn V2, note that this PR does not update the .yarn/cache/ directory meaning this code cannot be pulled and immediately developed on as one would expect for a zero-install project - you will need to run yarn to update the contents of the ./yarn/cache directory.
If you are not using zero-install you can ignore this as your flow should likely be unchanged.

Vulnerabilities that will be fixed with an upgrade:

Issue Score
medium severity Server-side Request Forgery (SSRF)
SNYK-JS-AXIOS-9403194
  596  
low severity Cross-site Scripting (XSS)
SNYK-JS-DOMPURIFY-8722251
  421  

Important

  • Check the changes in this PR to ensure they won't cause issues with your project.
  • Max score is 1000. Note that the real score may have changed since the PR was raised.
  • This PR was automatically created by Snyk using the credentials of a real user.

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report
📜 Customise PR templates
🛠 Adjust project settings
📚 Read about Snyk's upgrade logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Server-side Request Forgery (SSRF)
🦉 Cross-site Scripting (XSS)


Important

Upgrade @grafana/data and axios in frontend/package.json to fix SSRF and XSS vulnerabilities.

  • Dependencies:
    • Upgrade @grafana/data from ^11.2.3 to ^11.6.0 in frontend/package.json.
    • Upgrade axios from 1.7.7 to 1.8.3 in frontend/package.json.
  • Vulnerabilities:
    • Fixes SSRF vulnerability in axios (SNYK-JS-AXIOS-9403194).
    • Fixes XSS vulnerability in dompurify (SNYK-JS-DOMPURIFY-8722251).
  • Misc:
    • Note for zero-installs users: Run yarn to update .yarn/cache/ directory.

This description was created by Ellipsis for 4cbb768. It will automatically update as commits are pushed.

@CLAassistant
Copy link

CLA assistant check
Thank you for your submission! We really appreciate it. Like many open source projects, we ask that you sign our Contributor License Agreement before we can accept your contribution.
You have signed the CLA already but the status is still pending? Let us recheck it.

@github-actions
Copy link

Build Error! No Linked Issue found. Please link an issue or mention it in the body using #<issue_id>

@github-actions github-actions bot added the bug Something isn't working label Mar 26, 2025
@github-actions
Copy link

Build Error! No Linked Issue found. Please link an issue or mention it in the body using #<issue_id>

Copy link
Contributor

@ellipsis-dev ellipsis-dev bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

👍 Looks good to me! Reviewed everything up to 4cbb768 in 33 seconds

More details
  • Looked at 22 lines of code in 1 files
  • Skipped 1 files when reviewing.
  • Skipped posting 4 drafted comments based on config settings.
1. frontend/package.json:37
  • Draft comment:
    Upgrade '@grafana/data' to '^11.6.0' per Snyk vulnerability fix. Please review the release notes for any potential breaking changes with this update.
  • Reason this comment was not posted:
    Comment did not seem useful. Confidence is useful = 0% <= threshold 50%
    This comment is related to a dependency change and asks the PR author to review release notes for potential breaking changes. According to the rules, comments on dependency changes or asking the author to review for potential issues are not allowed.
2. frontend/package.json:54
  • Draft comment:
    Upgrade 'axios' to '1.8.3' to address SSRF vulnerability. Ensure that your API usage of axios remains compatible with this version upgrade.
  • Reason this comment was not posted:
    Comment did not seem useful. Confidence is useful = 0% <= threshold 50%
    The comment is about upgrading a dependency, which is generally not within the scope of useful comments according to the rules. It also asks the author to ensure compatibility, which is not allowed.
3. frontend/package.json:37
  • Draft comment:
    Updated '@grafana/data' from ^11.2.3 to ^11.6.0. Please ensure that any minor API changes in Grafana v11.6 do not break existing functionality.
  • Reason this comment was not posted:
    Comment did not seem useful. Confidence is useful = 0% <= threshold 50%
    This comment is about a dependency update and asks the author to ensure that the update does not break existing functionality. According to the rules, comments on dependency changes and asking the author to ensure things are not allowed.
4. frontend/package.json:54
  • Draft comment:
    Upgraded axios from 1.7.7 to 1.8.3 to address SSRF vulnerability (SNYK-JS-AXIOS-9403194). Verify that no breaking changes affect API calls.
  • Reason this comment was not posted:
    Comment did not seem useful. Confidence is useful = 0% <= threshold 50%
    This comment is related to a dependency change, specifically the upgrade of the axios library. The comment asks the PR author to verify that no breaking changes affect API calls, which is against the rules as it asks for verification of behavior. Therefore, this comment should be removed.

Workflow ID: wflow_K8LCdRc3cruNAaJ3


You can customize Ellipsis with 👍 / 👎 feedback, review rules, user-specific overrides, quiet mode, and more.

@YounixM YounixM closed this Nov 6, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug Something isn't working

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants