Skip to content

fix: update tough-cookie to tough-cookie to 4.1.3 #820

Open
utruong309 wants to merge 1 commit intokubeflow:notebooks-v1from
utruong309:pr3-update-tough-cookie
Open

fix: update tough-cookie to tough-cookie to 4.1.3 #820
utruong309 wants to merge 1 commit intokubeflow:notebooks-v1from
utruong309:pr3-update-tough-cookie

Conversation

@utruong309
Copy link

@utruong309 utruong309 commented Jan 7, 2026

This PR updates tough-cookie to version 4.1.3 across all CRUD web app frontends:

  • common/frontend
  • jupyter/frontend
  • tensorboards/frontend
  • volumes/frontend

This resolves the following security issue:

Steps performed:

  • Added npm overrides to enforce tough-cookie@4.1.3 where required
  • Regenerated package-lock.json in each affected frontend
  • Ran npm install to ensure clean dependency resolution
  • Verified that all vulnerable dependency paths resolve to tough-cookie@4.1.3
  • Confirmed Cypress dependencies remain unaffected
  • Signed all commits to comply with DCO requirements

Signed-off-by: Uyen Truong uyenthutruong09@gmail.com

@github-project-automation github-project-automation bot moved this to Needs Triage in Kubeflow Notebooks Jan 7, 2026
@google-oss-prow google-oss-prow bot added the area/ci area - related to ci label Jan 7, 2026
@utruong309 utruong309 force-pushed the pr3-update-tough-cookie branch 2 times, most recently from 0cff8dc to d5ab49a Compare January 8, 2026 01:05
@utruong309 utruong309 changed the base branch from main to notebooks-v1 January 9, 2026 17:27
Signed-off-by: utruong309 <uyenthutruong09@gmail.com>
@utruong309 utruong309 force-pushed the pr3-update-tough-cookie branch from d5ab49a to e3413ce Compare January 9, 2026 17:53
@google-oss-prow google-oss-prow bot added area/backend area - related to backend components area/frontend area - related to frontend components area/v1 area - version - kubeflow notebooks v1 labels Jan 9, 2026
@google-oss-prow
Copy link

[APPROVALNOTIFIER] This PR is NOT APPROVED

This pull-request has been approved by:
Once this PR has been reviewed and has the lgtm label, please assign orfeas-k for approval. For more information see the Kubernetes Code Review Process.

The full list of commands accepted by this bot can be found here.

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@github-actions
Copy link

This pull request has been automatically marked as stale because it has not had recent activity.
It will be closed if no further activity occurs.
Thank you for your contributions.

Members may comment /lifecycle frozen to prevent this pull request from being marked as stale.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area/backend area - related to backend components area/ci area - related to ci area/frontend area - related to frontend components area/v1 area - version - kubeflow notebooks v1 lifecycle/stale size/XXL

Projects

Status: Needs Triage

Development

Successfully merging this pull request may close these issues.

1 participant