Skip to content

Conversation

@marcdumais-work
Copy link
Contributor

@marcdumais-work marcdumais-work commented Aug 21, 2025

What it does

Update to get rid of this critical severity vulnerability.

see:

https://github.com/dependency-insights/npm/form-data/4.0.0/security?query=org%3Aeclipse-cdt-cloud

How to test

Confirm that CI passes. Optionally perform a "yarn why form-data" and confirm that the version pulled is not vulnerable. The version expected with this PR is:
form-data@4.0.4

Note: there's a small chance that we will have problem when we next try to publish, since we updated @vscode/vsce and ovsx. There is unfortunately no easy way to test publishing at this time as part of the PR. If that happens, we can correct with a follow-up.

Follow-ups

N/A

Review checklist

  • As an author, I have thoroughly tested my changes and carefully followed the instructions in this template

@marcdumais-work marcdumais-work force-pushed the form-fetch-vulnerability branch 2 times, most recently from 098f24b to 040e5e5 Compare August 21, 2025 20:18
@marcdumais-work marcdumais-work changed the title Update dependencies to get rid of form-fetch vulnerability Update dependencies to get rid of form-data vulnerability Aug 21, 2025
Copy link
Contributor

@bhufmann bhufmann left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

After checking out and building the yarn.lock is updated. You need the revert the following change in the yarn.lock:

git diff
diff --git a/yarn.lock b/yarn.lock
index 90fa333..6ded88e 100644
--- a/yarn.lock
+++ b/yarn.lock
@@ -3877,7 +3877,7 @@ js-yaml@^3.10.0, js-yaml@^3.13.1, js-yaml@^3.14.1:
     argparse "^1.0.7"
     esprima "^4.0.0"
 
-"json-bigint@github:sidorares/json-bigint#2c0a5f896d7888e68e5f4ae3c7ea5cd42fd54473":
+json-bigint@sidorares/json-bigint#2c0a5f896d7888e68e5f4ae3c7ea5cd42fd54473:
   version "1.0.0"
   resolved "https://codeload.github.com/sidorares/json-bigint/tar.gz/2c0a5f896d7888e68e5f4ae3c7ea5cd42fd54473"
   dependencies:

Update to get rid of this critical severity vulnerability.

see:

https://github.com/dependency-insights/npm/form-data/4.0.0/security?query=org%3Aeclipse-cdt-cloud

Signed-off-by: Marc Dumais <marc.dumais@ericsson.com>
@marcdumais-work marcdumais-work force-pushed the form-fetch-vulnerability branch from 040e5e5 to a593b9f Compare August 21, 2025 20:27
Copy link
Contributor

@bhufmann bhufmann left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM. Thanks!

@marcdumais-work
Copy link
Contributor Author

Thanks for the review!

@marcdumais-work marcdumais-work merged commit 91131e6 into main Aug 22, 2025
6 checks passed
@marcdumais-work marcdumais-work deleted the form-fetch-vulnerability branch August 22, 2025 13:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants