Skip to content

Fix npm package vulnerabilities#1610

Merged
marcomura merged 1 commit intomainfrom
mmura/fix-vulnerabilities
Feb 14, 2026
Merged

Fix npm package vulnerabilities#1610
marcomura merged 1 commit intomainfrom
mmura/fix-vulnerabilities

Conversation

@marcomura
Copy link
Collaborator

@marcomura marcomura commented Feb 14, 2026

diff 6.0.0 - 8.0.2
jsdiff has a Denial of Service vulnerability in parsePatch and applyPatch - GHSA-73rr-hh4g-fpgx

markdown-it 13.0.0 - 14.1.0
Severity: moderate
markdown-it is has a Regular Expression Denial of Service (ReDoS) - GHSA-38c4-r59v-3vqw

qs 6.7.0 - 6.14.1
qs's arrayLimit bypass in comma parsing allows denial of service - GHSA-w7fw-mjwx-w883


Rovo Dev has reviewed this pull request
Any suggestions or improvements have been posted as pull request comments.

@marcomura marcomura merged commit 683ff78 into main Feb 14, 2026
13 checks passed
@marcomura marcomura deleted the mmura/fix-vulnerabilities branch February 14, 2026 01:37
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants