Skip to content

Commit 252c290

Browse files
authored
Fix critical CVE in form-data package (GHSA-fjxv-7rqg-78g4) (#271)
see also che-incubator/che-code#589 Signed-off-by: Stephane Bouchet <[email protected]>
1 parent 42e6785 commit 252c290

File tree

2 files changed

+108
-7
lines changed

2 files changed

+108
-7
lines changed

package.json

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -51,7 +51,7 @@
5151
},
5252
"devDependencies": {
5353
"@types/jest": "^29.5.14",
54-
"axios": "^1.8.3",
54+
"axios": "^1.13.1",
5555
"eslint": "^9.5.0",
5656
"if-env": "^1.0.4",
5757
"jest": "^29.7.0",
@@ -62,7 +62,7 @@
6262
"typescript": "^5.6.2"
6363
},
6464
"peerDependencies": {
65-
"axios": "^1.8.3"
65+
"axios": "^1.13.1"
6666
},
6767
"prettier": {
6868
"printWidth": 120,

yarn.lock

Lines changed: 106 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -1143,13 +1143,13 @@ asynckit@^0.4.0:
11431143
resolved "https://registry.yarnpkg.com/asynckit/-/asynckit-0.4.0.tgz#c79ed97f7f34cb8f2ba1bc9790bcc366474b4b79"
11441144
integrity sha512-Oei9OH4tRh0YqU3GxhX79dM/mwVgvbZJaSNaRk+bshkj0S5cfHcgYakreBjrHwatXKbz+IoIdYLxrKim2MjW0Q==
11451145

1146-
axios@^1.8.3:
1147-
version "1.10.0"
1148-
resolved "https://registry.yarnpkg.com/axios/-/axios-1.10.0.tgz#af320aee8632eaf2a400b6a1979fa75856f38d54"
1149-
integrity sha512-/1xYAC4MP/HEG+3duIhFr4ZQXR4sQXOIe+o6sdqzeykGLx6Upp/1p8MHqhINOvGeP7xyNHe7tsiJByc4SSVUxw==
1146+
axios@^1.13.1:
1147+
version "1.13.1"
1148+
resolved "https://registry.yarnpkg.com/axios/-/axios-1.13.1.tgz#45b62dc8fe04e0e92274e08b98e910ba3d7963a7"
1149+
integrity sha512-hU4EGxxt+j7TQijx1oYdAjw4xuIp1wRQSsbMFwSthCWeBQur1eF+qJ5iQ5sN3Tw8YRzQNKb8jszgBdMDVqwJcw==
11501150
dependencies:
11511151
follow-redirects "^1.15.6"
1152-
form-data "^4.0.0"
1152+
form-data "^4.0.4"
11531153
proxy-from-env "^1.1.0"
11541154

11551155
babel-jest@^29.7.0:
@@ -1298,6 +1298,14 @@ buffer-from@^1.0.0:
12981298
resolved "https://registry.yarnpkg.com/buffer-from/-/buffer-from-1.1.2.tgz#2b146a6fd72e80b4f55d255f35ed59a3a9a41bd5"
12991299
integrity sha512-E+XQCRwSbaaiChtv6k6Dwgc+bx+Bs6vuKJHHl5kox/BaKbhiXzqQOwK4cO22yElGp2OCmjwVhT3HmxgyPGnJfQ==
13001300

1301+
call-bind-apply-helpers@^1.0.1, call-bind-apply-helpers@^1.0.2:
1302+
version "1.0.2"
1303+
resolved "https://registry.yarnpkg.com/call-bind-apply-helpers/-/call-bind-apply-helpers-1.0.2.tgz#4b5428c222be985d79c3d82657479dbe0b59b2d6"
1304+
integrity sha512-Sp1ablJ0ivDkSzjcaJdxEunN5/XvksFJ2sMBFfq6x0ryhQV/2b/KwFe21cMpmHtPOSij8K99/wSfoEuTObmuMQ==
1305+
dependencies:
1306+
es-errors "^1.3.0"
1307+
function-bind "^1.1.2"
1308+
13011309
callsites@^3.0.0:
13021310
version "3.1.0"
13031311
resolved "https://registry.yarnpkg.com/callsites/-/callsites-3.1.0.tgz#b3630abd8943432f54b3f0519238e33cd7df2f73"
@@ -1479,6 +1487,15 @@ diff-sequences@^29.6.3:
14791487
resolved "https://registry.yarnpkg.com/diff-sequences/-/diff-sequences-29.6.3.tgz#4deaf894d11407c51efc8418012f9e70b84ea921"
14801488
integrity sha512-EjePK1srD3P08o2j4f0ExnylqRs5B9tJjcp9t1krH2qRi8CCdsYfwe9JgSLurFBWwq4uOlipzfk5fHNvwFKr8Q==
14811489

1490+
dunder-proto@^1.0.1:
1491+
version "1.0.1"
1492+
resolved "https://registry.yarnpkg.com/dunder-proto/-/dunder-proto-1.0.1.tgz#d7ae667e1dc83482f8b70fd0f6eefc50da30f58a"
1493+
integrity sha512-KIN/nDJBQRcXw0MLVhZE9iQHmG68qAVIBg9CqmUYjmQIhgij9U5MFvrqkUL5FbtyyzZuOeOt0zdeRe4UY7ct+A==
1494+
dependencies:
1495+
call-bind-apply-helpers "^1.0.1"
1496+
es-errors "^1.3.0"
1497+
gopd "^1.2.0"
1498+
14821499
duplexer@~0.1.1:
14831500
version "0.1.2"
14841501
resolved "https://registry.yarnpkg.com/duplexer/-/duplexer-0.1.2.tgz#3abe43aef3835f8ae077d136ddce0f276b0400e6"
@@ -1521,6 +1538,33 @@ error-ex@^1.3.1:
15211538
dependencies:
15221539
is-arrayish "^0.2.1"
15231540

1541+
es-define-property@^1.0.1:
1542+
version "1.0.1"
1543+
resolved "https://registry.yarnpkg.com/es-define-property/-/es-define-property-1.0.1.tgz#983eb2f9a6724e9303f61addf011c72e09e0b0fa"
1544+
integrity sha512-e3nRfgfUZ4rNGL232gUgX06QNyyez04KdjFrF+LTRoOXmrOgFKDg4BCdsjW8EnT69eqdYGmRpJwiPVYNrCaW3g==
1545+
1546+
es-errors@^1.3.0:
1547+
version "1.3.0"
1548+
resolved "https://registry.yarnpkg.com/es-errors/-/es-errors-1.3.0.tgz#05f75a25dab98e4fb1dcd5e1472c0546d5057c8f"
1549+
integrity sha512-Zf5H2Kxt2xjTvbJvP2ZWLEICxA6j+hAmMzIlypy4xcBg1vKVnx89Wy0GbS+kf5cwCVFFzdCFh2XSCFNULS6csw==
1550+
1551+
es-object-atoms@^1.0.0, es-object-atoms@^1.1.1:
1552+
version "1.1.1"
1553+
resolved "https://registry.yarnpkg.com/es-object-atoms/-/es-object-atoms-1.1.1.tgz#1c4f2c4837327597ce69d2ca190a7fdd172338c1"
1554+
integrity sha512-FGgH2h8zKNim9ljj7dankFPcICIK9Cp5bm+c2gQSYePhpaG5+esrLODihIorn+Pe6FGJzWhXQotPv73jTaldXA==
1555+
dependencies:
1556+
es-errors "^1.3.0"
1557+
1558+
es-set-tostringtag@^2.1.0:
1559+
version "2.1.0"
1560+
resolved "https://registry.yarnpkg.com/es-set-tostringtag/-/es-set-tostringtag-2.1.0.tgz#f31dbbe0c183b00a6d26eb6325c810c0fd18bd4d"
1561+
integrity sha512-j6vWzfrGVfyXxge+O0x5sh6cvxAog0a/4Rdd2K36zCMV5eJ+/+tOAngRO8cODMNWbVRdVlmGZQL2YS3yR8bIUA==
1562+
dependencies:
1563+
es-errors "^1.3.0"
1564+
get-intrinsic "^1.2.6"
1565+
has-tostringtag "^1.0.2"
1566+
hasown "^2.0.2"
1567+
15241568
es6-promise@^4.2.4:
15251569
version "4.2.8"
15261570
resolved "https://registry.yarnpkg.com/es6-promise/-/es6-promise-4.2.8.tgz#4eb21594c972bc40553d276e510539143db53e0a"
@@ -1783,6 +1827,17 @@ form-data@^4.0.0:
17831827
combined-stream "^1.0.8"
17841828
mime-types "^2.1.12"
17851829

1830+
form-data@^4.0.4:
1831+
version "4.0.4"
1832+
resolved "https://registry.yarnpkg.com/form-data/-/form-data-4.0.4.tgz#784cdcce0669a9d68e94d11ac4eea98088edd2c4"
1833+
integrity sha512-KrGhL9Q4zjj0kiUt5OO4Mr/A/jlI2jDYs5eHBpYHPcBEVSiipAvn2Ko2HnPe20rmcuuvMHNdZFp+4IlGTMF0Ow==
1834+
dependencies:
1835+
asynckit "^0.4.0"
1836+
combined-stream "^1.0.8"
1837+
es-set-tostringtag "^2.1.0"
1838+
hasown "^2.0.2"
1839+
mime-types "^2.1.12"
1840+
17861841
from@~0:
17871842
version "0.1.7"
17881843
resolved "https://registry.yarnpkg.com/from/-/from-0.1.7.tgz#83c60afc58b9c56997007ed1a768b3ab303a44fe"
@@ -1822,11 +1877,35 @@ get-caller-file@^2.0.5:
18221877
resolved "https://registry.yarnpkg.com/get-caller-file/-/get-caller-file-2.0.5.tgz#4f94412a82db32f36e3b0b9741f8a97feb031f7e"
18231878
integrity sha512-DyFP3BM/3YHTQOCUL/w0OZHR0lpKeGrxotcHWcqNEdnltqFwXVfhEBQ94eIo34AfQpo0rGki4cyIiftY06h2Fg==
18241879

1880+
get-intrinsic@^1.2.6:
1881+
version "1.3.0"
1882+
resolved "https://registry.yarnpkg.com/get-intrinsic/-/get-intrinsic-1.3.0.tgz#743f0e3b6964a93a5491ed1bffaae054d7f98d01"
1883+
integrity sha512-9fSjSaos/fRIVIp+xSJlE6lfwhES7LNtKaCBIamHsjr2na1BiABJPo0mOjjz8GJDURarmCPGqaiVg5mfjb98CQ==
1884+
dependencies:
1885+
call-bind-apply-helpers "^1.0.2"
1886+
es-define-property "^1.0.1"
1887+
es-errors "^1.3.0"
1888+
es-object-atoms "^1.1.1"
1889+
function-bind "^1.1.2"
1890+
get-proto "^1.0.1"
1891+
gopd "^1.2.0"
1892+
has-symbols "^1.1.0"
1893+
hasown "^2.0.2"
1894+
math-intrinsics "^1.1.0"
1895+
18251896
get-package-type@^0.1.0:
18261897
version "0.1.0"
18271898
resolved "https://registry.yarnpkg.com/get-package-type/-/get-package-type-0.1.0.tgz#8de2d803cff44df3bc6c456e6668b36c3926e11a"
18281899
integrity sha512-pjzuKtY64GYfWizNAJ0fr9VqttZkNiK2iS430LtIHzjBEr6bX8Am2zm4sW4Ro5wjWW5cAlRL1qAMTcXbjNAO2Q==
18291900

1901+
get-proto@^1.0.1:
1902+
version "1.0.1"
1903+
resolved "https://registry.yarnpkg.com/get-proto/-/get-proto-1.0.1.tgz#150b3f2743869ef3e851ec0c49d15b1d14d00ee1"
1904+
integrity sha512-sTSfBjoXBp89JvIKIefqw7U2CCebsc74kiY6awiGogKtoSGbgjYE/G/+l9sF3MWFPNc9IcoOC4ODfKHfxFmp0g==
1905+
dependencies:
1906+
dunder-proto "^1.0.1"
1907+
es-object-atoms "^1.0.0"
1908+
18301909
get-stream@^6.0.0:
18311910
version "6.0.1"
18321911
resolved "https://registry.yarnpkg.com/get-stream/-/get-stream-6.0.1.tgz#a262d8eef67aced57c2852ad6167526a43cbf7b7"
@@ -1873,6 +1952,11 @@ globals@^14.0.0:
18731952
resolved "https://registry.yarnpkg.com/globals/-/globals-14.0.0.tgz#898d7413c29babcf6bafe56fcadded858ada724e"
18741953
integrity sha512-oahGvuMGQlPw/ivIYBjVSrWAfWLBeku5tpPE2fOPLi+WHffIWbuh2tCjhyQhTBPMf5E9jDEH4FOmTYgYwbKwtQ==
18751954

1955+
gopd@^1.2.0:
1956+
version "1.2.0"
1957+
resolved "https://registry.yarnpkg.com/gopd/-/gopd-1.2.0.tgz#89f56b8217bdbc8802bd299df6d7f1081d7e51a1"
1958+
integrity sha512-ZUKRh6/kUFoAiTAtTYPZJ3hw9wNxx+BIBOijnlG9PnrJsCcSjs1wyyD6vJpaYtgnzDrKYRSqf3OO6Rfa93xsRg==
1959+
18761960
graceful-fs@^4.1.6, graceful-fs@^4.2.0, graceful-fs@^4.2.9:
18771961
version "4.2.11"
18781962
resolved "https://registry.yarnpkg.com/graceful-fs/-/graceful-fs-4.2.11.tgz#4183e4e8bf08bb6e05bbb2f7d2e0c8f712ca40e3"
@@ -1900,6 +1984,18 @@ has-flag@^4.0.0:
19001984
resolved "https://registry.yarnpkg.com/has-flag/-/has-flag-4.0.0.tgz#944771fd9c81c81265c4d6941860da06bb59479b"
19011985
integrity sha512-EykJT/Q1KjTWctppgIAgfSO0tKVuZUjhgMr17kqTumMl6Afv3EISleU7qZUzoXDFTAHTDC4NOoG/ZxU3EvlMPQ==
19021986

1987+
has-symbols@^1.0.3, has-symbols@^1.1.0:
1988+
version "1.1.0"
1989+
resolved "https://registry.yarnpkg.com/has-symbols/-/has-symbols-1.1.0.tgz#fc9c6a783a084951d0b971fe1018de813707a338"
1990+
integrity sha512-1cDNdwJ2Jaohmb3sg4OmKaMBwuC48sYni5HUw2DvsC8LjGTLK9h+eb1X6RyuOHe4hT0ULCW68iomhjUoKUqlPQ==
1991+
1992+
has-tostringtag@^1.0.2:
1993+
version "1.0.2"
1994+
resolved "https://registry.yarnpkg.com/has-tostringtag/-/has-tostringtag-1.0.2.tgz#2cdc42d40bef2e5b4eeab7c01a73c54ce7ab5abc"
1995+
integrity sha512-NqADB8VjPFLM2V0VvHUewwwsw0ZWBaIdgo+ieHtK3hasLz4qeCRjYcqfB6AQrBggRKppKF8L52/VqdVsO47Dlw==
1996+
dependencies:
1997+
has-symbols "^1.0.3"
1998+
19031999
hasown@^2.0.2:
19042000
version "2.0.2"
19052001
resolved "https://registry.yarnpkg.com/hasown/-/hasown-2.0.2.tgz#003eaf91be7adc372e84ec59dc37252cedb80003"
@@ -2608,6 +2704,11 @@ map-stream@~0.1.0:
26082704
resolved "https://registry.yarnpkg.com/map-stream/-/map-stream-0.1.0.tgz#e56aa94c4c8055a16404a0674b78f215f7c8e194"
26092705
integrity sha512-CkYQrPYZfWnu/DAmVCpTSX/xHpKZ80eKh2lAkyA6AJTef6bW+6JpbQZN5rofum7da+SyN1bi5ctTm+lTfcCW3g==
26102706

2707+
math-intrinsics@^1.1.0:
2708+
version "1.1.0"
2709+
resolved "https://registry.yarnpkg.com/math-intrinsics/-/math-intrinsics-1.1.0.tgz#a0dd74be81e2aa5c2f27e65ce283605ee4e2b7f9"
2710+
integrity sha512-/IXtbwEk5HTPyEwyKX6hGkYXxM9nbj64B+ilVJnC/R6B0pH5G4V3b0pVbL7DBj4tkhBAppbQUlf6F6Xl9LHu1g==
2711+
26112712
merge-stream@^2.0.0:
26122713
version "2.0.0"
26132714
resolved "https://registry.yarnpkg.com/merge-stream/-/merge-stream-2.0.0.tgz#52823629a14dd00c9770fb6ad47dc6310f2c1f60"

0 commit comments

Comments
 (0)