Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

qs vulnerable to Prototype Pollution #18052

Open
1 task
Tracked by #17647
edmund-dunn opened this issue May 7, 2024 · 0 comments
Open
1 task
Tracked by #17647

qs vulnerable to Prototype Pollution #18052

edmund-dunn opened this issue May 7, 2024 · 0 comments
Labels
CMS Team CMS Product team that manages both editor exp and devops content-build Defect Something isn't working (issue type)

Comments

@edmund-dunn
Copy link
Contributor

edmund-dunn commented May 7, 2024

Description

This is partly a discovery ticket. If you find this is blocked because of version issues, especially with node please annotate that in the Confluence page and here in the ticket.

A single patch version bump. The PR went stale and was closed. This should be an easy fix with no other dependencies being affected. There are 4 versions of this package installed. We should try to condense that.

Acceptance Criteria

  • Upgrade qs to >= 6.5.3
@edmund-dunn edmund-dunn added Defect Something isn't working (issue type) CMS Team CMS Product team that manages both editor exp and devops content-build labels May 7, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
CMS Team CMS Product team that manages both editor exp and devops content-build Defect Something isn't working (issue type)
Projects
None yet
Development

No branches or pull requests

1 participant