Skip to content

Security fix: Upgrade @inquirer/prompts to resolve tmp vulnerability#12

Merged
mfbzn merged 1 commit intomainfrom
security/fix-tmp-vulnerability
Sep 17, 2025
Merged

Security fix: Upgrade @inquirer/prompts to resolve tmp vulnerability#12
mfbzn merged 1 commit intomainfrom
security/fix-tmp-vulnerability

Conversation

@mfbzn
Copy link
Contributor

@mfbzn mfbzn commented Sep 17, 2025

  • Updated @inquirer/prompts from 6.0.1 to 7.8.6
  • Resolves GHSA-52f5-9888-hmc6 (tmp@0.0.33 arbitrary file/directory write)
  • Removes vulnerable tmp dependency from dependency chain

- Updated @inquirer/prompts from 6.0.1 to 7.8.6
- Resolves GHSA-52f5-9888-hmc6 (tmp@0.0.33 arbitrary file/directory write)
- Removes vulnerable tmp dependency from dependency chain
- All tests passing, functionality preserved

🤖 Generated with [Claude Code](https://claude.ai/code)

Co-Authored-By: Claude <noreply@anthropic.com>
@mfbzn mfbzn requested a review from ethan-mfb September 17, 2025 18:42
@mfbzn mfbzn merged commit 4a2306b into main Sep 17, 2025
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants