Skip to content

Commit 3f994ca

Browse files
antonisclaude
andcommitted
chore(deps): Force basic-ftp >=5.3.0 to fix GHSA-rp42-5vxx-qpwr
Adds a yarn resolution to pull basic-ftp@5.3.0 (patched) in place of 5.2.2, which is vulnerable to a high-severity denial-of-service via unbounded memory growth in Client.list(). The package is a transitive dev dependency via @puppeteer/browsers and @wdio/utils. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
1 parent 9147cdc commit 3f994ca

2 files changed

Lines changed: 5 additions & 4 deletions

File tree

package.json

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -103,6 +103,7 @@
103103
"qs": "^6.14.2",
104104
"lodash": "^4.18.1",
105105
"tar-fs": "^3.1.1",
106+
"basic-ftp": "^5.3.0",
106107
"on-headers": "^1.1.0",
107108
"diff": "^5.2.2",
108109
"tar": "^7.5.11",

yarn.lock

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -14051,10 +14051,10 @@ __metadata:
1405114051
languageName: node
1405214052
linkType: hard
1405314053

14054-
"basic-ftp@npm:^5.0.2":
14055-
version: 5.2.2
14056-
resolution: "basic-ftp@npm:5.2.2"
14057-
checksum: 11234c0fd6b810ac3641acf3c03338ae8d0d0ca23aaeaa56204bae05b9dd6f93117312b6d729fde56c20c197711dbe5655363a8590c61f7efa399cb63b56e00d
14054+
"basic-ftp@npm:^5.3.0":
14055+
version: 5.3.0
14056+
resolution: "basic-ftp@npm:5.3.0"
14057+
checksum: b2c93d98541c805171813bddd7e6349b7fc304ba8896acf60b0b4393253204cff88aa2a31adbaec2f1a58f78e90005672c30796042a2c717a69ccae10160d72d
1405814058
languageName: node
1405914059
linkType: hard
1406014060

0 commit comments

Comments
 (0)