Skip to content

fix(deps): EXT-3323 EXT-3324 upgrade axios, qs, express#133

Merged
malinbranduse merged 3 commits intomainfrom
fix/snyk-high-critical-deps
Mar 23, 2026
Merged

fix(deps): EXT-3323 EXT-3324 upgrade axios, qs, express#133
malinbranduse merged 3 commits intomainfrom
fix/snyk-high-critical-deps

Conversation

@malinbranduse
Copy link
Copy Markdown
Contributor

@malinbranduse malinbranduse commented Mar 23, 2026

Summary

  • Upgrades axios, qs, express and adds overrides for minimatch
  • Snyk test passes with zero high/critical issues

@malinbranduse malinbranduse requested review from a team as code owners March 23, 2026 12:21
@snyk-io
Copy link
Copy Markdown
Contributor

snyk-io Bot commented Mar 23, 2026

Snyk checks have passed. No issues have been found so far.

Status Scan Engine Critical High Medium Low Total (0)
Open Source Security 0 0 0 0 0 issues
Licenses 0 0 0 0 0 issues
Code Security 0 0 0 0 0 issues

💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse.

Resolves CVE-2026-25639 (Prototype Pollution), CVE-2025-15284
and CVE-2026-2391 (Resource Exhaustion).
Adds body-parser qs override for transitive dep fix.
@malinbranduse malinbranduse force-pushed the fix/snyk-high-critical-deps branch from 7062ca6 to d1822cd Compare March 23, 2026 12:27
@CLAassistant
Copy link
Copy Markdown

CLAassistant commented Mar 23, 2026

CLA assistant check
All committers have signed the CLA.

@malinbranduse malinbranduse changed the title fix(deps): upgrade axios, qs, express to address multiple high severity CVEs fix(deps): EXT-3323 EXT-3324 upgrade axios, qs, express Mar 23, 2026
@malinbranduse malinbranduse merged commit 89ca692 into main Mar 23, 2026
10 checks passed
@malinbranduse malinbranduse deleted the fix/snyk-high-critical-deps branch March 23, 2026 16:48
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants