From 510d738fda629e7c26edc994617d038ac57d68ed Mon Sep 17 00:00:00 2001 From: Sanket Date: Fri, 24 Apr 2026 20:04:33 +0530 Subject: [PATCH] OCPBUGS-83777: Fix CVE-2026-29063 in immutable --- package.json | 5 ++++- yarn.lock | 18 +++++++++--------- 2 files changed, 13 insertions(+), 10 deletions(-) diff --git a/package.json b/package.json index a6a36ecd..915d11c0 100644 --- a/package.json +++ b/package.json @@ -99,6 +99,9 @@ }, "resolutions": { "@types/react": "17.0.40", - "webpack": "^5.68.0" + "webpack": "^5.68.0", + "@openshift-console/dynamic-plugin-sdk/immutable": "3.8.3", + "@openshift-console/dynamic-plugin-sdk-internal/immutable": "3.8.3", + "sass/immutable": "4.3.8" } } \ No newline at end of file diff --git a/yarn.lock b/yarn.lock index 8a007672..c8d8c97f 100644 --- a/yarn.lock +++ b/yarn.lock @@ -4330,15 +4330,15 @@ ignore@^5.2.0, ignore@^5.2.4: resolved "https://registry.yarnpkg.com/ignore/-/ignore-5.3.1.tgz#5073e554cd42c5b33b394375f538b8593e34d4ef" integrity sha512-5Fytz/IraMjqpwfd34ke28PTVMjZjJG2MPn5t7OE4eUCUNf8BAa7b5WUS9/Qvr6mwOQS7Mk6vdsMno5he+T8Xw== -immutable@3.x: - version "3.8.2" - resolved "https://registry.yarnpkg.com/immutable/-/immutable-3.8.2.tgz#c2439951455bb39913daf281376f1530e104adf3" - integrity sha512-15gZoQ38eYjEjxkorfbcgBKBL6R7T459OuK+CpcWt7O3KF4uPCx2tD0uFETlUDIyo+1789crbMhTvQBSR5yBMg== - -immutable@^4.0.0: - version "4.3.5" - resolved "https://registry.yarnpkg.com/immutable/-/immutable-4.3.5.tgz#f8b436e66d59f99760dc577f5c99a4fd2a5cc5a0" - integrity sha512-8eabxkth9gZatlwl5TBuJnCsoTADlL6ftEr7A4qgdaTsPyreilDSnUk57SO+jfKcNtxPa22U5KK6DSeAYhpBJw== +immutable@3.8.3, immutable@3.x: + version "3.8.3" + resolved "https://registry.yarnpkg.com/immutable/-/immutable-3.8.3.tgz#0a8d2494a94d4b2d4f0e99986e74dd25d1e9a859" + integrity sha512-AUY/VyX0E5XlibOmWt10uabJzam1zlYjwiEgQSDc5+UIkFNaF9WM0JxXKaNMGf+F/ffUF+7kRKXM9A7C0xXqMg== + +immutable@4.3.8, immutable@^4.0.0: + version "4.3.8" + resolved "https://registry.yarnpkg.com/immutable/-/immutable-4.3.8.tgz#02d183c7727fb2bb1d5d0380da0d779dce9296a7" + integrity sha512-d/Ld9aLbKpNwyl0KiM2CT1WYvkitQ1TSvmRtkcV8FKStiDoA7Slzgjmb/1G2yhKM1p0XeNOieaTbFZmU1d3Xuw== import-fresh@^3.2.1, import-fresh@^3.3.0: version "3.3.0"