Skip to content

Commit 5f673c2

Browse files
typotterclaude
andcommitted
Fix CVE-2025-7783 vulnerability in form-data dependency
Added yarn resolution to force form-data >= 4.0.4, which patches the critical vulnerability in versions 4.0.0-4.0.3. The vulnerable version was transitively included via jest-environment-jsdom -> jsdom -> form-data. 🤖 Generated with [Claude Code](https://claude.com/claude-code) Co-Authored-By: Claude Sonnet 4.5 (1M context) <[email protected]>
1 parent 5789448 commit 5f673c2

File tree

2 files changed

+10
-5
lines changed

2 files changed

+10
-5
lines changed

package.json

Lines changed: 4 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -80,5 +80,8 @@
8080
"uuid": "^11.0.5",
8181
"yargs": "^17.7.2"
8282
},
83-
"packageManager": "[email protected]+sha512.a6b2f7906b721bba3d67d4aff083df04dad64c399707841b7acf00f6b133b7ac24255f2652fa22ae3534329dc6180534e98d17432037ff6fd140556e2bb3137e"
83+
"packageManager": "[email protected]+sha512.a6b2f7906b721bba3d67d4aff083df04dad64c399707841b7acf00f6b133b7ac24255f2652fa22ae3534329dc6180534e98d17432037ff6fd140556e2bb3137e",
84+
"resolutions": {
85+
"form-data": "^4.0.4"
86+
}
8487
}

yarn.lock

Lines changed: 6 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -2474,13 +2474,15 @@ for-each@^0.3.3:
24742474
dependencies:
24752475
is-callable "^1.1.3"
24762476

2477-
form-data@^4.0.0:
2478-
version "4.0.1"
2479-
resolved "https://registry.yarnpkg.com/form-data/-/form-data-4.0.1.tgz#ba1076daaaa5bfd7e99c1a6cb02aa0a5cff90d48"
2480-
integrity sha512-tzN8e4TX8+kkxGPK8D5u0FNmjPUjw3lwC9lSLxxoB/+GtsJG91CO8bSWy73APlgAZzZbXEYZJuxjkHH2w+Ezhw==
2477+
form-data@^4.0.0, form-data@^4.0.4:
2478+
version "4.0.5"
2479+
resolved "https://registry.yarnpkg.com/form-data/-/form-data-4.0.5.tgz#b49e48858045ff4cbf6b03e1805cebcad3679053"
2480+
integrity sha512-8RipRLol37bNs2bhoV67fiTEvdTrbMUYcFTiy3+wuuOnUog2QBHCZWXDRijWQfAkhBj2Uf5UnVaiWwA5vdd82w==
24812481
dependencies:
24822482
asynckit "^0.4.0"
24832483
combined-stream "^1.0.8"
2484+
es-set-tostringtag "^2.1.0"
2485+
hasown "^2.0.2"
24842486
mime-types "^2.1.12"
24852487

24862488
fs.realpath@^1.0.0:

0 commit comments

Comments
 (0)