Commit 4f93601
* Fix critical CVE in form-data package (GHSA-fjxv-7rqg-78g4)
Updated form-data across multiple packages to address critical security
vulnerability where unsafe random function was used for choosing
boundary
values.
Vulnerability Details:
- Advisory: GHSA-fjxv-7rqg-78g4
- Severity: Critical
- CWE-330: Use of Insufficiently Random Values
- Affected versions: <2.5.4, 3.0.0-3.0.3, 4.0.0-4.0.3
Packages Updated:
- code/package-lock.json
- code/extensions/che-activity-tracker/package-lock.json
- code/extensions/che-api/package-lock.json
- code/extensions/che-commands/package-lock.json
- code/extensions/che-port/package-lock.json
- code/extensions/che-remote/package-lock.json
The form-data package is used as a transitive dependency through:
- @types/node-fetch
- axios
- jsdom
Verification: npm audit confirms the critical form-data vulnerability
has been resolved. Vulnerability count reduced from 14 to 13.
Generated-by: Claude CLI
🤖 Generated with [Claude Code](https://claude.com/claude-code)
* Fix critical CVE in form-data package (GHSA-fjxv-7rqg-78g4)
* Fix critical CVE in form-data package (GHSA-fjxv-7rqg-78g4)
* Fix critical CVE in form-data package (GHSA-fjxv-7rqg-78g4)
* Fix critical CVE in form-data package (GHSA-fjxv-7rqg-78g4)
* Fix critical CVE in form-data package (GHSA-fjxv-7rqg-78g4)
* update che devworkspace-generator version
---------
Signed-off-by: Stephane Bouchet <sbouchet@redhat.com>
Co-authored-by: Claude <noreply@anthropic.com>
1 parent ab62d4f commit 4f93601
12 files changed
Lines changed: 628 additions & 139 deletions
File tree
- code
- extensions
- che-activity-tracker
- che-api
- che-commands
- che-port
- che-remote
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
39 | 39 | | |
40 | 40 | | |
41 | 41 | | |
| 42 | + | |
| 43 | + | |
| 44 | + | |
| 45 | + | |
| 46 | + | |
42 | 47 | | |
43 | 48 | | |
44 | 49 | | |
| |||
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
31 | 31 | | |
32 | 32 | | |
33 | 33 | | |
34 | | - | |
| 34 | + | |
35 | 35 | | |
36 | 36 | | |
37 | 37 | | |
| |||
53 | 53 | | |
54 | 54 | | |
55 | 55 | | |
| 56 | + | |
| 57 | + | |
| 58 | + | |
| 59 | + | |
| 60 | + | |
| 61 | + | |
56 | 62 | | |
57 | 63 | | |
58 | 64 | | |
| |||
0 commit comments