Skip to content

Commit 19fb0ee

Browse files
authored
Bumped qs version for CVE-2025-15284. (#428)
* Bumped qs version for CVE-2025-15284. Signed-off-by: Thomas Hurney <hurneyt@amazon.com> * Adjusted dependency version. Signed-off-by: Thomas Hurney <hurneyt@amazon.com> --------- Signed-off-by: Thomas Hurney <hurneyt@amazon.com>
1 parent 5482d8c commit 19fb0ee

File tree

2 files changed

+62
-8
lines changed

2 files changed

+62
-8
lines changed

package.json

Lines changed: 3 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -32,6 +32,7 @@
3232
"minimist": "^1.2.6",
3333
"tough-cookie": "^4.1.3",
3434
"@cypress/request": "^3.0.0",
35-
"form-data": "4.0.4"
35+
"form-data": "4.0.4",
36+
"qs": "^6.14.1"
3637
}
37-
}
38+
}

yarn.lock

Lines changed: 59 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -307,6 +307,14 @@ call-bind@^1.0.2, call-bind@^1.0.5, call-bind@^1.0.6, call-bind@^1.0.7:
307307
get-intrinsic "^1.2.4"
308308
set-function-length "^1.2.1"
309309

310+
call-bound@^1.0.2:
311+
version "1.0.4"
312+
resolved "https://registry.yarnpkg.com/call-bound/-/call-bound-1.0.4.tgz#238de935d2a2a692928c538c7ccfa91067fd062a"
313+
integrity sha512-+ys997U96po4Kx/ABpBCqhA9EuxJaQWDQg7295H4hBphv3IZg0boBKuwYpt4YXp6MZ5AmZQnU/tyMTlRpaSejg==
314+
dependencies:
315+
call-bind-apply-helpers "^1.0.2"
316+
get-intrinsic "^1.3.0"
317+
310318
caseless@~0.12.0:
311319
version "0.12.0"
312320
resolved "https://registry.yarnpkg.com/caseless/-/caseless-0.12.0.tgz#1b681c21ff84033c826543090689420d187151dc"
@@ -871,7 +879,7 @@ get-intrinsic@^1.1.3, get-intrinsic@^1.2.1, get-intrinsic@^1.2.3, get-intrinsic@
871879
has-symbols "^1.0.3"
872880
hasown "^2.0.0"
873881

874-
get-intrinsic@^1.2.6:
882+
get-intrinsic@^1.2.5, get-intrinsic@^1.2.6, get-intrinsic@^1.3.0:
875883
version "1.3.0"
876884
resolved "https://registry.yarnpkg.com/get-intrinsic/-/get-intrinsic-1.3.0.tgz#743f0e3b6964a93a5491ed1bffaae054d7f98d01"
877885
integrity sha512-9fSjSaos/fRIVIp+xSJlE6lfwhES7LNtKaCBIamHsjr2na1BiABJPo0mOjjz8GJDURarmCPGqaiVg5mfjb98CQ==
@@ -1350,6 +1358,11 @@ object-inspect@^1.13.1:
13501358
resolved "https://registry.yarnpkg.com/object-inspect/-/object-inspect-1.13.2.tgz#dea0088467fb991e67af4058147a24824a3043ff"
13511359
integrity sha512-IRZSRuzJiynemAXPYtPe5BoI/RESNYR7TYm50MC5Mqbd3Jmw5y790sErYw3V6SryFJD64b74qQQs9wn5Bg/k3g==
13521360

1361+
object-inspect@^1.13.3:
1362+
version "1.13.4"
1363+
resolved "https://registry.yarnpkg.com/object-inspect/-/object-inspect-1.13.4.tgz#8375265e21bc20d0fa582c22e1b13485d6e00213"
1364+
integrity sha512-W67iLl4J2EXEGTbfeHCffrjDfitvLANg0UlX3wFUUSTx92KXRFegMHUVgSqE+wvhAbi4WqjGg9czysTV2Epbew==
1365+
13531366
object-is@^1.1.2, object-is@^1.1.5:
13541367
version "1.1.6"
13551368
resolved "https://registry.yarnpkg.com/object-is/-/object-is-1.1.6.tgz#1a6a53aed2dd8f7e6775ff870bea58545956ab07"
@@ -1506,12 +1519,12 @@ punycode@^2.1.1:
15061519
resolved "https://registry.yarnpkg.com/punycode/-/punycode-2.3.1.tgz#027422e2faec0b25e1549c3e1bd8309b9133b6e5"
15071520
integrity sha512-vYt7UD1U9Wg6138shLtLOvdAu+8DsC/ilFtEVHcH+wydcSpNE20AfSOduf6MkRFahL5FY7X1oU7nKVZFtfq8Fg==
15081521

1509-
qs@6.10.4:
1510-
version "6.10.4"
1511-
resolved "https://registry.yarnpkg.com/qs/-/qs-6.10.4.tgz#6a3003755add91c0ec9eacdc5f878b034e73f9e7"
1512-
integrity sha512-OQiU+C+Ds5qiH91qh/mg0w+8nwQuLjM4F4M/PbmhDOoYehPh+Fb0bDjtR1sOvy7YKxvj28Y/M0PhP5uVX0kB+g==
1522+
qs@6.10.4, qs@^6.14.1:
1523+
version "6.15.0"
1524+
resolved "https://registry.yarnpkg.com/qs/-/qs-6.15.0.tgz#db8fd5d1b1d2d6b5b33adaf87429805f1909e7b3"
1525+
integrity sha512-mAZTtNCeetKMH+pSjrb76NAM8V9a05I9aBZOHztWy/UqcJdQYNsf59vrRKWnojAT9Y+GbIvoTBC++CPHqpDBhQ==
15131526
dependencies:
1514-
side-channel "^1.0.4"
1527+
side-channel "^1.1.0"
15151528

15161529
querystringify@^2.1.1:
15171530
version "2.2.0"
@@ -1672,6 +1685,35 @@ shebang-regex@^3.0.0:
16721685
resolved "https://registry.yarnpkg.com/shebang-regex/-/shebang-regex-3.0.0.tgz#ae16f1644d873ecad843b0307b143362d4c42172"
16731686
integrity sha512-7++dFhtcx3353uBaq8DDR4NuxBetBzC7ZQOhmTQInHEd6bSrXdiEyzCvG07Z44UYdLShWUyXt5M/yhz8ekcb1A==
16741687

1688+
side-channel-list@^1.0.0:
1689+
version "1.0.0"
1690+
resolved "https://registry.yarnpkg.com/side-channel-list/-/side-channel-list-1.0.0.tgz#10cb5984263115d3b7a0e336591e290a830af8ad"
1691+
integrity sha512-FCLHtRD/gnpCiCHEiJLOwdmFP+wzCmDEkc9y7NsYxeF4u7Btsn1ZuwgwJGxImImHicJArLP4R0yX4c2KCrMrTA==
1692+
dependencies:
1693+
es-errors "^1.3.0"
1694+
object-inspect "^1.13.3"
1695+
1696+
side-channel-map@^1.0.1:
1697+
version "1.0.1"
1698+
resolved "https://registry.yarnpkg.com/side-channel-map/-/side-channel-map-1.0.1.tgz#d6bb6b37902c6fef5174e5f533fab4c732a26f42"
1699+
integrity sha512-VCjCNfgMsby3tTdo02nbjtM/ewra6jPHmpThenkTYh8pG9ucZ/1P8So4u4FGBek/BjpOVsDCMoLA/iuBKIFXRA==
1700+
dependencies:
1701+
call-bound "^1.0.2"
1702+
es-errors "^1.3.0"
1703+
get-intrinsic "^1.2.5"
1704+
object-inspect "^1.13.3"
1705+
1706+
side-channel-weakmap@^1.0.2:
1707+
version "1.0.2"
1708+
resolved "https://registry.yarnpkg.com/side-channel-weakmap/-/side-channel-weakmap-1.0.2.tgz#11dda19d5368e40ce9ec2bdc1fb0ecbc0790ecea"
1709+
integrity sha512-WPS/HvHQTYnHisLo9McqBHOJk2FkHO/tlpvldyrnem4aeQp4hai3gythswg6p01oSoTl58rcpiFAjF2br2Ak2A==
1710+
dependencies:
1711+
call-bound "^1.0.2"
1712+
es-errors "^1.3.0"
1713+
get-intrinsic "^1.2.5"
1714+
object-inspect "^1.13.3"
1715+
side-channel-map "^1.0.1"
1716+
16751717
side-channel@^1.0.4:
16761718
version "1.0.6"
16771719
resolved "https://registry.yarnpkg.com/side-channel/-/side-channel-1.0.6.tgz#abd25fb7cd24baf45466406b1096b7831c9215f2"
@@ -1682,6 +1724,17 @@ side-channel@^1.0.4:
16821724
get-intrinsic "^1.2.4"
16831725
object-inspect "^1.13.1"
16841726

1727+
side-channel@^1.1.0:
1728+
version "1.1.0"
1729+
resolved "https://registry.yarnpkg.com/side-channel/-/side-channel-1.1.0.tgz#c3fcff9c4da932784873335ec9765fa94ff66bc9"
1730+
integrity sha512-ZX99e6tRweoUXqR+VBrslhda51Nh5MTQwou5tnUDgbtyM0dBgmhEDtWGP/xbKn6hqfPRHujUNwz5fy/wbbhnpw==
1731+
dependencies:
1732+
es-errors "^1.3.0"
1733+
object-inspect "^1.13.3"
1734+
side-channel-list "^1.0.0"
1735+
side-channel-map "^1.0.1"
1736+
side-channel-weakmap "^1.0.2"
1737+
16851738
signal-exit@^3.0.2:
16861739
version "3.0.7"
16871740
resolved "https://registry.yarnpkg.com/signal-exit/-/signal-exit-3.0.7.tgz#a9a1767f8af84155114eaabd73f99273c8f59ad9"

0 commit comments

Comments
 (0)