Skip to content

Conversation

@pradeepjangid195
Copy link
Contributor

@pradeepjangid195 pradeepjangid195 commented Jan 19, 2026

Added resolutions to fix security vulnerabilities:

Ticket: VL-4148

Added resolutions to fix security vulnerabilities:
- tar: ^7.5.3 (GHSA-8qq5-rm4j-mr97 - path sanitization)
- jspdf: ^4.0.0 (GHSA-f8cm-6447-x5h2 - local file inclusion)
- qs: 6.14.1 (GHSA-6rw7-vpxm-498p - DoS via arrayLimit bypass)

All high/critical severity vulnerabilities now resolved.

Ticket: VL-4148
@pradeepjangid195 pradeepjangid195 force-pushed the fix-security-vulnerabilities-tar-jspdf-qs branch from c6c113f to 2cb6c00 Compare January 19, 2026 10:04
@pradeepjangid195 pradeepjangid195 marked this pull request as ready for review January 19, 2026 10:22
@pradeepjangid195 pradeepjangid195 requested a review from a team as a code owner January 19, 2026 10:22
@pradeepjangid195 pradeepjangid195 changed the title fix(deps): resolve high severity vulnerabilities in tar, jspdf, and qs fix(deps): resolve high severity vulnerabilities in tar, jspdf (Code Audit fix) Jan 19, 2026
@pradeepjangid195 pradeepjangid195 merged commit ed26c2e into master Jan 19, 2026
20 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants