Skip to content

[PR-BOT] [JIRA: GRAL-5705] Fixed vulnerabilities#189

Closed
pipedrive-backoffice-pr[bot] wants to merge 1 commit intomasterfrom
PR-BOT-10643060f70c95bc4e041fbf10c10f88d7112ad13a8807121da68f86
Closed

[PR-BOT] [JIRA: GRAL-5705] Fixed vulnerabilities#189
pipedrive-backoffice-pr[bot] wants to merge 1 commit intomasterfrom
PR-BOT-10643060f70c95bc4e041fbf10c10f88d7112ad13a8807121da68f86

Conversation

@pipedrive-backoffice-pr
Copy link

Fixed vulnerabilities

Dependency Affected Version Fixed Version Status Reason
cross-spawn 7.0.3 7.0.5 fixed ✅ already fixed before install
form-data 2.3.3 2.5.4 fixed ✅ already fixed before install
form-data 4.0.0 4.0.4 fixed ✅ already fixed before install
form-data 4.0.0 4.0.4 fixed ✅ already fixed before install
node-forge 1.3.1 1.3.2 fixed ✅ already fixed before install
node-forge 1.3.1 1.3.2 fixed ✅ already fixed before install
jws 3.2.2 3.2.3 fixed ✅ already fixed before install
qs 6.5.3 6.14.1 fixed ✅ already fixed before install
tar 6.2.1 7.5.3 fixed ✅ already fixed before install
tar 6.2.1 7.5.4 fixed ✅ already fixed before install
tar 6.2.1 7.5.7 fixed ✅ already fixed before install
next 13.5.1 15.0.8 fixed ✅ already fixed before install

Related JIRA ticket:
https://pipedrive.atlassian.net/browse/GRAL-5705

Related Backoffice Task:
https://backoffice.pipedrive.tools/plugins/backoffice-plugin-pr-bot/history?taskId=335

PR was opened by infosec-vulnerability-scanner

@IgnorancePulls
Copy link
Contributor

Closing this PR as it targets the wrong location. The vulnerabilities are in individual apps under /apps/ folder, not at the root level. A new PR will be created that properly fixes all vulnerabilities in each app.

IgnorancePulls added a commit that referenced this pull request Feb 11, 2026
- Update tar@6.2.1 → 7.5.7 in 5 apps (CVE-2026-23745, CVE-2026-23950, CVE-2026-24842)
- Update form-data (2.3.3 → 2.5.4, 4.0.0 → 4.0.4) in 6 apps (CVE-2025-7783)
- Update jws@3.2.2 → 3.2.3 in 3 apps (CVE-2025-65945)
- Update next@13.5.1 → 15.0.8 in custom-ui-floating-window-demo (GHSA-h25m-26qc-wcjf)
- Update node-forge@1.3.1 → 1.3.3 in todo (CVE-2025-12816, CVE-2025-66031)
- Update cross-spawn@7.0.3 → 7.0.5 in remix-cars-service (CVE-2024-21538)

Fixed 18 vulnerabilities identified in GRAL-5705. Updated package-lock.json
files for all affected apps. PR #189 was closed as it incorrectly targeted
the root directory instead of individual apps.

Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant