Skip to content

Comments

Update go and npm dependencies to remediate security vulnerabilities#1018

Merged
pskrbasu merged 1 commit intov1.4.xfrom
fix/vulnerability-updates-v1.4.x-3
Feb 20, 2026
Merged

Update go and npm dependencies to remediate security vulnerabilities#1018
pskrbasu merged 1 commit intov1.4.xfrom
fix/vulnerability-updates-v1.4.x-3

Conversation

@pskrbasu
Copy link
Collaborator

Summary

  • tar: 7.5.7 → 7.5.8 (CVE-2026-26960, high) - Arbitrary File Read/Write via Hardlink Target Escape
  • qs: 6.14.1 → 6.14.2 (CVE-2026-2391, low) - arrayLimit bypass in comma parsing allows DoS
  • jsonpath: 1.2.0 → 1.2.1 (CVE-2026-1615, high) - Arbitrary Code Injection via unsafe evaluation
  • filippo.io/edwards25519: 1.1.0 → 1.1.1 (CVE-2026-26958, low) - MultiScalarMult invalid results

Not addressed

  • elliptic (CVE-2025-14505, low): Already at latest version 6.6.1; no patched version available yet

Test plan

  • Go build (make) succeeds
  • Dashboard UI build (yarn build) succeeds
  • yarn why confirms updated versions for tar, qs, jsonpath
  • go.mod confirms edwards25519 v1.1.1

🤖 Generated with Claude Code

- tar: 7.5.7 → 7.5.8 (CVE-2026-26960, high)
- qs: 6.14.1 → 6.14.2 (CVE-2026-2391, low)
- jsonpath: 1.2.0 → 1.2.1 (CVE-2026-1615, high)
- filippo.io/edwards25519: 1.1.0 → 1.1.1 (CVE-2026-26958, low)

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
@graza-io graza-io self-requested a review February 20, 2026 08:08
@pskrbasu pskrbasu merged commit 0b2b566 into v1.4.x Feb 20, 2026
23 checks passed
@pskrbasu pskrbasu deleted the fix/vulnerability-updates-v1.4.x-3 branch February 20, 2026 09:21
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants