fix(cve): update axios, browserslist, baseline-browser-mapping for CVE fixes - #9352
Conversation
Fixes CVE-2026-67313, CVE-2026-67320 Update axios override from >=1.18.1 to >=1.19.0 and bump frontend direct dep from ^1.18.1 to ^1.19.0. Minor version bump.
…to 2.11.15 Fixes CVE-2026-73088, CVE-2026-73089, CVE-2026-45819 Update browserslist from 4.28.1 to 4.28.8 and baseline-browser-mapping from 2.9.19 to 2.11.15 via in-place lockfile surgery. Minor bumps.
|
Important Review skippedAuto reviews are disabled on base/target branches other than the default branch. Please check the settings in the CodeRabbit UI or the ⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: CHILL Plan: Pro Plus Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
manaswinidas
left a comment
There was a problem hiding this comment.
/lgtm
/approve
Tested as non-admin user:
- Create a workbench
- Start/stop an existing workbench
- Pipelines and other pages load fine.
These work fine.
|
[APPROVALNOTIFIER] This PR is APPROVED This pull-request has been approved by: manaswinidas The full list of commands accepted by this bot can be found here. The pull request process is described here DetailsNeeds approval from an approver in each of these files:
Approvers can indicate their approval by writing |
166f30d
into
opendatahub-io:stable-2.x
Summary
Round 4 CVE fixes for RHOAI 2.25.11 — addresses 5 CVEs (8 Jira trackers fixed, 4 VEX-closed, 1 RBAC issue noted).
Changes
browserslist and baseline-browser-mapping updated via in-place lockfile surgery (dependency list changed between versions).
VEX-Closed
Not in scope
Jira Trackers
Test plan
npm run buildpassesnpm run test:backend— 17/17 tests pass