Compare commits

...

2 Commits

Author SHA1 Message Date
Chris Farhood d5c812ab42 fix: update stale RBAC path ref after infra consolidation (PRI-1002)
Updates deploy-e2e-headlamp.sh to reference the consolidated RBAC manifest
at privilegedescalation/infra/base/rbac/e2e-ci-runner.yaml instead of the
non-existent local path deployment/e2e-ci-runner-rbac.yaml.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-05-06 23:14:47 +00:00
privilegedescalation-engineer[bot] 32d825e441 fix: add elliptic override for GHSA-848j-6mx2-7j84 (#68)
Add pnpm.overrides.elliptic to prevent version regression on
the transitive elliptic vulnerability (CVE-2025-14505).

Vulnerability path:
@kinvolk/headlamp-plugin → vite-plugin-node-polyfills →
node-stdlib-browser → crypto-browserify → browserify-sign → elliptic

Note: pnpm audit will still report the vulnerability until
upstream publishes elliptic 6.6.2+. This override safeguards
against pulling a worse version.

Co-authored-by: Chris Farhood <chris@farhood.org>
Co-authored-by: Paperclip <noreply@paperclip.ing>
2026-05-06 00:43:51 +00:00
2 changed files with 4 additions and 3 deletions
+2 -1
View File
@@ -45,6 +45,7 @@
"overrides": {
"tar": "^7.5.11",
"undici": "^7.24.3",
"lodash": ">=4.18.0"
"lodash": ">=4.18.0",
"elliptic": ">=6.6.1"
}
}
+2 -2
View File
@@ -11,7 +11,7 @@
# Prerequisites:
# - Plugin built (dist/ exists with plugin-main.js + package.json)
# - kubectl configured with cluster access
# - RBAC applied: kubectl apply -f deployment/e2e-ci-runner-rbac.yaml
# - RBAC applied: kubectl apply -f privilegedescalation/infra/base/rbac/e2e-ci-runner.yaml
#
# Environment:
# E2E_NAMESPACE — namespace for E2E Headlamp (default: headlamp-dev)
@@ -35,7 +35,7 @@ fi
echo "Checking RBAC permissions in namespace '${E2E_NAMESPACE}'..."
if ! kubectl auth can-i delete configmaps -n "$E2E_NAMESPACE" --quiet 2>/dev/null; then
echo "ERROR: Missing RBAC — cannot delete configmaps in namespace '${E2E_NAMESPACE}'." >&2
echo " Apply RBAC first: kubectl apply -f deployment/e2e-ci-runner-rbac.yaml" >&2
echo " Apply RBAC first: kubectl apply -f privilegedescalation/infra/base/rbac/e2e-ci-runner.yaml" >&2
exit 1
fi