Skip to content

Security/update vulnerable dependencies#55

Open
mgwoj wants to merge 2 commits intoakamai:masterfrom
mgwoj:security/update-vulnerable-dependencies
Open

Security/update vulnerable dependencies#55
mgwoj wants to merge 2 commits intoakamai:masterfrom
mgwoj:security/update-vulnerable-dependencies

Conversation

@mgwoj
Copy link
Copy Markdown

@mgwoj mgwoj commented Dec 22, 2025

No description provided.

- Add form-data override to ^4.0.4 (fixes CVE-2025-7783, CVSS 9.4)
- Add axios override to ^1.12.0 (fixes CVE-2025-58754, CVSS 7.5)
- Resolves all high/critical npm audit vulnerabilities
- Fix brace-expansion ReDoS vulnerability (GHSA-v6h2-p8h4-qcjw)
- Fix js-yaml prototype pollution (GHSA-mh29-5h37-fv8m)
- Applied via npm audit fix (non-breaking)
- All vulnerabilities now resolved (0 remaining)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

1 participant