Commit 3f994ca
chore(deps): Force basic-ftp >=5.3.0 to fix GHSA-rp42-5vxx-qpwr
Adds a yarn resolution to pull basic-ftp@5.3.0 (patched) in place of
5.2.2, which is vulnerable to a high-severity denial-of-service via
unbounded memory growth in Client.list(). The package is a transitive
dev dependency via @puppeteer/browsers and @wdio/utils.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>1 parent 9147cdc commit 3f994ca
2 files changed
Lines changed: 5 additions & 4 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
103 | 103 | | |
104 | 104 | | |
105 | 105 | | |
| 106 | + | |
106 | 107 | | |
107 | 108 | | |
108 | 109 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
14051 | 14051 | | |
14052 | 14052 | | |
14053 | 14053 | | |
14054 | | - | |
14055 | | - | |
14056 | | - | |
14057 | | - | |
| 14054 | + | |
| 14055 | + | |
| 14056 | + | |
| 14057 | + | |
14058 | 14058 | | |
14059 | 14059 | | |
14060 | 14060 | | |
| |||
0 commit comments