You are viewing a plain text version of this content. The canonical link for it is here.
Posted to dev@zeppelin.apache.org by "Luciano Resende (JIRA)" <ji...@apache.org> on 2016/07/15 21:14:20 UTC
[jira] [Created] (ZEPPELIN-1193) Update Node JS dependencies to
avoid RegExp DoS
Luciano Resende created ZEPPELIN-1193:
-----------------------------------------
Summary: Update Node JS dependencies to avoid RegExp DoS
Key: ZEPPELIN-1193
URL: https://issues.apache.org/jira/browse/ZEPPELIN-1193
Project: Zeppelin
Issue Type: Bug
Components: build, front-end
Reporter: Luciano Resende
Assignee: Luciano Resende
I was having some intermittent build issues complaining about some node dependencies that needs to be updated to avoid RegExp DoS issues :
[ERROR] npm WARN deprecated minimatch@0.2.14: Please update to minimatch 3.0.2 or higher to avoid a RegExp DoS issue
[ERROR] npm WARN deprecated minimatch@2.0.10: Please update to minimatch 3.0.2 or higher to avoid a RegExp DoS issue
[ERROR] npm WARN deprecated graceful-fs@3.0.8: graceful-fs v3.0.0 and before will fail on node releases >= v7.0. Please update to graceful-fs@^4.0.0 as soon as possible. Use 'npm ls graceful-fs' to find it in the tree.
[ERROR] npm WARN deprecated graceful-fs@2.0.3: graceful-fs v3.0.0 and before will fail on node releases >= v7.0. Please update to graceful-fs@^4.0.0 as soon as possible. Use 'npm ls graceful-fs' to find it in the tree.
[ERROR] npm WARN deprecated minimatch@0.3.0: Please update to minimatch 3.0.2 or higher to avoid a RegExp DoS issue
[ERROR] npm WARN deprecated graceful-fs@1.2.3: graceful-fs v3.0.0 and before will fail on node releases >= v7.0. Please update to graceful-fs@^4.0.0 as soon as possible. Use 'npm ls graceful-fs' to find it in the tree.
[ERROR] npm WARN deprecated lodash@1.0.2: lodash@<3.0.0 is no longer maintained. Upgrade to lodash@^4.0.0.
[ERROR] npm WARN deprecated CSSselect@0.7.0: the module is now available as 'css-select'
[ERROR] npm WARN optional dep failed, continuing fsevents@1.0.12
[ERROR] npm WARN deprecated CSSwhat@0.4.7: the module is now available as 'css-what'
[ERROR] npm WARN deprecated minimatch@1.0.0: Please update to minimatch 3.0.2 or higher to avoid a RegExp DoS issue
--
This message was sent by Atlassian JIRA
(v6.3.4#6332)