Skip to content

Conversation

@kim-tsao
Copy link
Member

@kim-tsao kim-tsao commented Jan 9, 2026

Hey, I just made a Pull Request!

Fixes:
https://issues.redhat.com/browse/RHIDP-11321

CVE-2025-15284 (qs bump to 6.14.1)

  • Updated with yarn up -R express body-parser qs

CVE-2026-22029 (@remix-run/router bump to 1.23.2)
CVE-2025-68470 (react-router bump to 6.30.2) --> supersedes #2014

  • Updated with yarn up -R react-router react-router-dom

CVE-2025-65945 (jws bump to 3.2.3 and 4.0.1)

✔️ Checklist

  • A changeset describing the change and affected packages. (more info)
  • Added or Updated documentation
  • Tests for new functionality and regression tests for bug fixes
  • Screenshots attached (for UI changes)

@sonarqubecloud
Copy link

sonarqubecloud bot commented Jan 9, 2026

@christoph-jerolimov
Copy link
Member

christoph-jerolimov commented Jan 10, 2026

@kim-tsao i'm just worried if it possible that this was reverted by accident if we just update the yarn.lock?

This will also not affect the shipped plugin, it's "only" for cleaning up our security boards right? Maybe a topic for on of our sync calls.

Feel free to merge this. :)

@kim-tsao kim-tsao merged commit b153551 into redhat-developer:main Jan 10, 2026
10 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants