You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
The upgraded @kubernetes/client-node@1.0.0 now explicitly depends on form-data: ^4.0.0. However, the existing overrides in package.json (visible in context) force form-data to version 2.5.5. This major version mismatch is highly likely to cause runtime errors (such as 'form.getHeaders is not a function' or similar) because node-fetch (the new underlying HTTP client) and the Kubernetes client's internal logic expect the v4 API. The override should be updated to a compatible v4 version.
Upgrading @kubernetes/client-node from 0.22.3 to 1.0.0 is a major breaking change. This version completely removes the request and byline dependencies in favor of node-fetch. Application code that relies on passing request options (like custom proxies or agents), accesses the internal request state, or uses the specific streaming behaviors of the previous version (especially in Watch or Logs APIs) will break. This automated PR does not include the necessary code migrations required for this major version bump.
@kubernetes/client-node@1.0.0 incorrectly includes @types/node: ^22.0.0 in its runtime dependencies. Since this project already depends on @types/node: ^20.17.52 at the root, this will result in two different versions of Node.js global type definitions being present in the dependency tree. This typically causes 'Duplicate identifier' errors during TypeScript compilation (tsc), preventing the project from building successfully.
"@types/node": "^22.0.0",
📚 Repository Context Analyzed
This review considered 15 relevant code sections from 2 files (average relevance: 0.75)
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Snyk has created this PR to fix 2 vulnerabilities in the npm dependencies of this project.
Snyk changed the following file(s):
package.jsonpackage-lock.jsonVulnerabilities that will be fixed with an upgrade:
SNYK-JS-REQUEST-3361831
SNYK-JS-UUID-16133035
Important
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.
For more information:
🧐 View latest project report
📜 Customise PR templates
🛠 Adjust project settings
📚 Read about Snyk's upgrade logic
Learn how to fix vulnerabilities with free interactive lessons:
🦉 Server-side Request Forgery (SSRF)