Commit f2f4d3a
committed
fix: resolve npm audit security vulnerabilities
Add overrides to patch vulnerable transitive dependencies in fs-js-lite's
request dependency chain:
- form-data >=2.5.4 (critical: unsafe random boundary)
- qs >=6.14.1 (moderate: arrayLimit bypass DoS)
- tough-cookie >=5.1.2 (moderate: prototype pollution)
Remaining unfixable: pm2 ReDoS (no fix available), request SSRF
(deprecated package, fs-js-lite upstream dependency).1 parent 9ac6a27 commit f2f4d3a
2 files changed
Lines changed: 38 additions & 32 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
44 | 44 | | |
45 | 45 | | |
46 | 46 | | |
| 47 | + | |
| 48 | + | |
| 49 | + | |
| 50 | + | |
| 51 | + | |
| 52 | + | |
| 53 | + | |
| 54 | + | |
| 55 | + | |
47 | 56 | | |
48 | 57 | | |
49 | 58 | | |
| |||
0 commit comments