Skip to content

V6.4.0 all security prs#3178

Draft
zerbitx wants to merge 78 commits intomainfrom
v6.4.0-all-security-prs
Draft

V6.4.0 all security prs#3178
zerbitx wants to merge 78 commits intomainfrom
v6.4.0-all-security-prs

Conversation

@zerbitx
Copy link
Collaborator

@zerbitx zerbitx commented Mar 24, 2026

v6.4.0-alpha — Merged Security & Dependency PRs

This PR aims to consolidate all of the automated PRs (at the time this was created) to get them building together and test them for the next minor release. 🤞

Contains 38 PRs (13 dependabot + 25 Snyk).


Dependabot (13)

PR Dependency Update
#3091 react-timeago (ui) 4.4.0 → 8.3.0
#3092 whatwg-fetch (ui) 2.0.3 → 3.6.20
#3093 url-loader (ui) 2.1.0 → 4.1.1
#3094 github.com/pkg/sftp 1.13.1 → 1.13.10
#3095 terser-webpack-plugin (ui) 1.4.6 → 5.3.16
#3096 github.com/evanphx/json-patch 4.12.0 → 5.9.11+incompatible
#3097 tslint (ui) 5.20.1 → 6.1.3
#3098 sw-precache-webpack-plugin (ui) 0.11.5 → 1.0.0
#3099 github.com/joho/godotenv 1.3.0 → 1.5.1
#3100 k8s.io/apimachinery 0.29.0 → 0.35.0
#3101 github.com/go-resty/resty/v2 2.7.0 → 2.17.1
#3173 inquirer (dist/npm) 7.3.3 → 13.3.2
#3177 find-process (dist/npm) 1.4.7 → 2.1.1

Snyk (25)

PR Dependency Update
#3023 sass (docs) 1.63.4 → 1.93.2
#3024 classnames (docs) 2.3.2 → 2.5.1
#3025 docusaurus-plugin-sass (docs) 0.2.3 → 0.2.6
#3038 Fix: js-yaml vuln (ui) SNYK-JS-JSYAML-13961110
#3039 redocusaurus (docs) 1.6.3 → 2.0.0
#3055 express 4.17.3 → 4.22.0
#3058 express 4.21.2 → 4.22.0
#3071 Fix: qs vuln (ui) SNYK-JS-QS-14724253
#3089 Fix: react-router vuln (ui) SNYK-JS-REACTROUTER-14908286
#3110 mermaid (docs) 10.9.3 → 11.0.0
#3118 alpine (Docker) latest → 3.23.3
#3126 golang Docker image 1.25.4-alpine → 1.26rc3-alpine
#3129 golang Docker image 1.17-alpine → 1.26.0-alpine
#3130 golang Docker image 1.17-alpine → 1.26.0-alpine
#3131 express 4.21.1 → 4.22.0
#3132 express 4.21.0 → 4.22.0
#3133 express 4.18.1 → 4.22.0
#3134 golang Docker image 1.17-alpine → 1.26.0-alpine
#3135 golang Docker image 1.17-alpine → 1.26.0-alpine
#3136 Fix: qs vuln (ui) SNYK-JS-QS-15268416
#3140 Fix: ajv ReDoS (docs) SNYK-JS-AJV-15274295
#3141 webpack (examples/quickstart-kubectl) 4.38.0 → 5.98.0
#3148 nodemon (examples) 2.0.22 → 3.1.12
#3171 golang Docker image 1.13 → latest
#3172 @kubernetes/client-node (ui) 0.17.1 → 0.21.0

snyk-bot and others added 30 commits October 24, 2025 08:56
Snyk has created this PR to upgrade sass from 1.63.4 to 1.93.2.

See this package in yarn:
sass

See this project in Snyk:
https://app.snyk.io/org/devspace/project/432c6c4d-5f97-4566-9a1a-0ff3240f0c2d?utm_source=github&utm_medium=referral&page=upgrade-pr
Snyk has created this PR to upgrade classnames from 2.3.2 to 2.5.1.

See this package in yarn:
classnames

See this project in Snyk:
https://app.snyk.io/org/devspace/project/432c6c4d-5f97-4566-9a1a-0ff3240f0c2d?utm_source=github&utm_medium=referral&page=upgrade-pr
Snyk has created this PR to upgrade docusaurus-plugin-sass from 0.2.3 to 0.2.6.

See this package in yarn:
docusaurus-plugin-sass

See this project in Snyk:
https://app.snyk.io/org/devspace/project/432c6c4d-5f97-4566-9a1a-0ff3240f0c2d?utm_source=github&utm_medium=referral&page=upgrade-pr
Bumps [react-timeago](https://github.com/naman34/react-timeago) from 4.4.0 to 8.3.0.
- [Release notes](https://github.com/naman34/react-timeago/releases)
- [Changelog](https://github.com/nmn/react-timeago/blob/master/CHANGELOG.md)
- [Commits](https://github.com/naman34/react-timeago/commits)

---
updated-dependencies:
- dependency-name: react-timeago
  dependency-version: 8.3.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [whatwg-fetch](https://github.com/github/fetch) from 2.0.3 to 3.6.20.
- [Release notes](https://github.com/github/fetch/releases)
- [Changelog](https://github.com/JakeChampion/fetch/blob/main/CHANGELOG.md)
- [Commits](JakeChampion/fetch@v2.0.3...v3.6.20)

---
updated-dependencies:
- dependency-name: whatwg-fetch
  dependency-version: 3.6.20
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [url-loader](https://github.com/webpack-contrib/url-loader) from 2.1.0 to 4.1.1.
- [Release notes](https://github.com/webpack-contrib/url-loader/releases)
- [Changelog](https://github.com/webpack-contrib/url-loader/blob/master/CHANGELOG.md)
- [Commits](webpack-contrib/url-loader@v2.1.0...v4.1.1)

---
updated-dependencies:
- dependency-name: url-loader
  dependency-version: 4.1.1
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [github.com/pkg/sftp](https://github.com/pkg/sftp) from 1.13.1 to 1.13.10.
- [Release notes](https://github.com/pkg/sftp/releases)
- [Commits](pkg/sftp@v1.13.1...v1.13.10)

---
updated-dependencies:
- dependency-name: github.com/pkg/sftp
  dependency-version: 1.13.10
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [terser-webpack-plugin](https://github.com/webpack/terser-webpack-plugin) from 1.4.6 to 5.3.16.
- [Release notes](https://github.com/webpack/terser-webpack-plugin/releases)
- [Changelog](https://github.com/webpack/terser-webpack-plugin/blob/main/CHANGELOG.md)
- [Commits](webpack/terser-webpack-plugin@v1.4.6...v5.3.16)

---
updated-dependencies:
- dependency-name: terser-webpack-plugin
  dependency-version: 5.3.16
  dependency-type: direct:development
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [github.com/evanphx/json-patch](https://github.com/evanphx/json-patch) from 4.12.0+incompatible to 5.9.11+incompatible.
- [Release notes](https://github.com/evanphx/json-patch/releases)
- [Commits](evanphx/json-patch@v4.12.0...v5.9.11)

---
updated-dependencies:
- dependency-name: github.com/evanphx/json-patch
  dependency-version: 5.9.11+incompatible
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [tslint](https://github.com/palantir/tslint) from 5.20.1 to 6.1.3.
- [Release notes](https://github.com/palantir/tslint/releases)
- [Changelog](https://github.com/palantir/tslint/blob/master/CHANGELOG.md)
- [Commits](palantir/tslint@5.20.1...6.1.3)

---
updated-dependencies:
- dependency-name: tslint
  dependency-version: 6.1.3
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [sw-precache-webpack-plugin](https://github.com/goldhand/sw-precache-webpack-plugin) from 0.11.5 to 1.0.0.
- [Changelog](https://github.com/goldhand/sw-precache-webpack-plugin/blob/master/CHANGELOG.md)
- [Commits](goldhand/sw-precache-webpack-plugin@v0.11.5...v1.0.0)

---
updated-dependencies:
- dependency-name: sw-precache-webpack-plugin
  dependency-version: 1.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [github.com/joho/godotenv](https://github.com/joho/godotenv) from 1.3.0 to 1.5.1.
- [Release notes](https://github.com/joho/godotenv/releases)
- [Commits](joho/godotenv@v1.3.0...v1.5.1)

---
updated-dependencies:
- dependency-name: github.com/joho/godotenv
  dependency-version: 1.5.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [k8s.io/apimachinery](https://github.com/kubernetes/apimachinery) from 0.29.0 to 0.35.0.
- [Commits](kubernetes/apimachinery@v0.29.0...v0.35.0)

---
updated-dependencies:
- dependency-name: k8s.io/apimachinery
  dependency-version: 0.35.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [github.com/go-resty/resty/v2](https://github.com/go-resty/resty) from 2.7.0 to 2.17.1.
- [Release notes](https://github.com/go-resty/resty/releases)
- [Commits](go-resty/resty@v2.7.0...v2.17.1)

---
updated-dependencies:
- dependency-name: github.com/go-resty/resty/v2
  dependency-version: 2.17.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
…k.json to reduce vulnerabilities

The following vulnerabilities are fixed with an upgrade:
- https://snyk.io/vuln/SNYK-JS-QS-15268416
…-cluster/package-lock.json to reduce vulnerabilities

The following vulnerabilities are fixed with an upgrade:
- https://snyk.io/vuln/SNYK-JS-QS-15268416
…json to reduce vulnerabilities

The following vulnerabilities are fixed with an upgrade:
- https://snyk.io/vuln/SNYK-JS-QS-15268416
zerbitx added 28 commits March 24, 2026 14:24
@netlify
Copy link

netlify bot commented Mar 24, 2026

Deploy Preview for devspace-docs failed.

Name Link
🔨 Latest commit 94376fd
🔍 Latest deploy log https://app.netlify.com/projects/devspace-docs/deploys/69c301dc20814f0008db297b

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants