Skip to content

chore(deps): yarn upgrade qs#1500

Merged
orta merged 1 commit intodanger:mainfrom
s2-ctraut:chore--upgrade-qs
Mar 12, 2026
Merged

chore(deps): yarn upgrade qs#1500
orta merged 1 commit intodanger:mainfrom
s2-ctraut:chore--upgrade-qs

Conversation

@s2-ctraut
Copy link
Contributor

npm audit
│ high │ qs's arrayLimit bypass in its bracket notation allows │
│ │ DoS via memory exhaustion │
│ Package │ qs │
│ Vulnerable versions │ <6.14.1 │
│ Patched versions │ >=6.14.1 │
│ Paths │ .>danger>@gitbeaker/rest>@gitbeaker/core>qs │
│ More info │ GHSA-6rw7-vpxm-498p
1 vulnerabilities found
Severity: 1 high

@orta
Copy link
Member

orta commented Mar 12, 2026

This isn't really a thing (updating our lockfile for a library) but I'll take it as it seems harmless

@orta orta merged commit 9799b71 into danger:main Mar 12, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants