Skip to content

Fix CVE-2025-15284: Upgrade qs to ^6.14.1#177

Merged
maxcanna merged 2 commits intomasterfrom
fix-qs-vulnerability-14465331912900520752
Feb 10, 2026
Merged

Fix CVE-2025-15284: Upgrade qs to ^6.14.1#177
maxcanna merged 2 commits intomasterfrom
fix-qs-vulnerability-14465331912900520752

Conversation

@maxcanna
Copy link
Owner

@maxcanna maxcanna commented Feb 10, 2026

This change upgrades the qs transitive dependency to version ^6.14.1 to resolve CVE-2025-15284. This was achieved by adding a resolutions field to package.json and updating yarn.lock. Tests were run to ensure no regressions.

Force upgrade of `qs` dependency to version 6.14.1 via `resolutions` in package.json to fix a high severity vulnerability.
Updated yarn.lock to reflect the new version.
Verified tests pass with the new version.
Force upgrade of `qs` dependency to version 6.14.1 via `resolutions` in package.json to fix a high severity vulnerability.
Updated yarn.lock to reflect the new version.
Bumped package version to 4.6.12 to satisfy CI version check.
Verified tests pass with the new version.
Repository owner deleted a comment from google-labs-jules bot Feb 10, 2026
@maxcanna maxcanna merged commit 9002e0b into master Feb 10, 2026
4 checks passed
@maxcanna maxcanna deleted the fix-qs-vulnerability-14465331912900520752 branch February 10, 2026 09:29
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant