Skip to content

Commit 35b66e7

Browse files
antonisclaude
andauthored
chore(deps): bump on-headers to ^1.1.0 (#5704)
Adds a yarn resolution to force on-headers to >=1.1.0, patching HTTP response header manipulation vulnerability (affected range: < 1.1.0). Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
1 parent b01fd91 commit 35b66e7

File tree

2 files changed

+5
-4
lines changed

2 files changed

+5
-4
lines changed

package.json

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -65,6 +65,7 @@
6565
"qs": "^6.14.2",
6666
"lodash": "^4.17.23",
6767
"tar-fs": "^3.1.1",
68+
"on-headers": "^1.1.0",
6869
"diff": "^5.2.2",
6970
"tar": "^7.5.7"
7071
},

yarn.lock

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -27635,10 +27635,10 @@ __metadata:
2763527635
languageName: node
2763627636
linkType: hard
2763727637

27638-
"on-headers@npm:~1.0.2":
27639-
version: 1.0.2
27640-
resolution: "on-headers@npm:1.0.2"
27641-
checksum: 2bf13467215d1e540a62a75021e8b318a6cfc5d4fc53af8e8f84ad98dbcea02d506c6d24180cd62e1d769c44721ba542f3154effc1f7579a8288c9f7873ed8e5
27638+
"on-headers@npm:^1.1.0":
27639+
version: 1.1.0
27640+
resolution: "on-headers@npm:1.1.0"
27641+
checksum: 98aa64629f986fb8cc4517dd8bede73c980e31208cba97f4442c330959f60ced3dc6214b83420491f5111fc7c4f4343abe2ea62c85f505cf041d67850f238776
2764227642
languageName: node
2764327643
linkType: hard
2764427644

0 commit comments

Comments
 (0)