Skip to content

[IGNORE] update vulnerable dependencies and update concurrently to v10.0.3#671

Open
jgbernalp wants to merge 1 commit into
mainfrom
upgrade-vulnerable-dependencies-10-06-2026
Open

[IGNORE] update vulnerable dependencies and update concurrently to v10.0.3#671
jgbernalp wants to merge 1 commit into
mainfrom
upgrade-vulnerable-dependencies-10-06-2026

Conversation

@jgbernalp

Copy link
Copy Markdown
Contributor

Description

Upgrade vulnerable dependencies

qs  6.11.1 - 6.15.1
Severity: moderate
qs has a remotely triggerable DoS: qs.stringify crashes with TypeError on null/undefined entries in comma-format arrays when encodeValuesOnly is set - https://github.com/advisories/GHSA-q8mj-m7cp-5q26
fix available via `npm audit fix`
node_modules/express/node_modules/qs
node_modules/qs
  express  4.21.0 - 4.22.1 || 5.0.0-alpha.1 - 5.0.1
  Depends on vulnerable versions of qs
  node_modules/express

react-router  6.7.0 - 6.30.3
Severity: moderate
React Router's same-origin redirect with path starting // causes open redirect via protocol-relative URL reinterpretation - https://github.com/advisories/GHSA-2j2x-hqr9-3h42
fix available via `npm audit fix`
node_modules/react-router
  react-router-dom  6.6.3-pre.0 - 6.30.3
  Depends on vulnerable versions of react-router
  node_modules/react-router-dom

shell-quote  1.1.0 - 1.8.3
Severity: critical
shell-quote quote() does not escape newlines in object .op values - https://github.com/advisories/GHSA-w7jw-789q-3m8p
fix available via `npm audit fix`
node_modules/shell-quote
  concurrently  9.2.1
  Depends on vulnerable versions of shell-quote
  node_modules/concurrently

turbo  <=2.9.13-canary.1
Severity: moderate
Trubo: Login callback CSRF/session fixation - https://github.com/advisories/GHSA-hcf7-66rw-9f5r
Turbo: Unexpected local code execution during Yarn Berry detection - https://github.com/advisories/GHSA-3qcw-2rhx-2726
fix available via `npm audit fix`
node_modules/turbo

ws  8.0.0 - 8.20.0
Severity: moderate
ws: Uninitialized memory disclosure - https://github.com/advisories/GHSA-58qx-3vcg-4xpx
fix available via `npm audit fix`
node_modules/ws
  @module-federation/dts-plugin  <=2.5.0
  Depends on vulnerable versions of ws
  node_modules/@module-federation/dts-plugin
    @module-federation/cli  <=2.5.0
    Depends on vulnerable versions of @module-federation/dts-plugin
    node_modules/@module-federation/cli
      @module-federation/enhanced  <=0.0.1-rc.0 || 0.1.2 - 2.5.0
      Depends on vulnerable versions of @module-federation/cli
      Depends on vulnerable versions of @module-federation/dts-plugin
      Depends on vulnerable versions of @module-federation/manifest
      Depends on vulnerable versions of @module-federation/rspack
      node_modules/@module-federation/enhanced
        @module-federation/node  <=0.0.0-research-issue-4085-20251016232757 || 2.1.2 - 2.7.43
        Depends on vulnerable versions of @module-federation/enhanced
        node_modules/@module-federation/node
          @module-federation/rsbuild-plugin  <=2.5.0
          Depends on vulnerable versions of @module-federation/enhanced
          Depends on vulnerable versions of @module-federation/node
          node_modules/@module-federation/rsbuild-plugin
    @module-federation/manifest  <=0.0.0-research-issue-4085-20251016232757 || 0.1.3 - 2.5.0
    Depends on vulnerable versions of @module-federation/dts-plugin
    node_modules/@module-federation/manifest
      @module-federation/rspack  <=2.5.0
      Depends on vulnerable versions of @module-federation/dts-plugin
      Depends on vulnerable versions of @module-federation/manifest
      node_modules/@module-federation/rspack

Checklist

  • Pull request has a descriptive title and context useful to a reviewer.
  • Pull request title follows the [<catalog_entry>] <commit message> naming convention using one of the
    following catalog_entry values: FEATURE, ENHANCEMENT, BUGFIX, BREAKINGCHANGE, DOC,IGNORE.
  • All commits have DCO signoffs.

…10.0.3

Signed-off-by: Gabriel Bernal <gbernal@redhat.com>
@jgbernalp jgbernalp requested a review from a team as a code owner June 10, 2026 11:42
@jgbernalp jgbernalp requested review from Gladorme and removed request for a team June 10, 2026 11:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant