Skip to content

[1.1] Fix security scan: override undici and ws#258

Merged
sachinh-amazon merged 1 commit into
1.1from
fix/security-overrides-1.1
Jun 24, 2026
Merged

[1.1] Fix security scan: override undici and ws#258
sachinh-amazon merged 1 commit into
1.1from
fix/security-overrides-1.1

Conversation

@sachinh-amazon

Copy link
Copy Markdown
Contributor

Fixes HIGH CVEs on 1.1: CVE-2026-6734, CVE-2026-9697, CVE-2026-12151 (undici ^7.28.0), CVE-2026-48779 (ws ^7.5.11)

@sachinh-amazon sachinh-amazon requested review from a team as code owners June 24, 2026 10:01
skazantsev
skazantsev previously approved these changes Jun 24, 2026
…2026-12151, CVE-2026-48779

- undici: ^7.24.0 → ^7.28.0 (CVE-2026-6734, CVE-2026-9697, CVE-2026-12151)
- ws: ^7.5.11 global override (CVE-2026-48779)

Regenerated package-lock overrides for all targets.
@sachinh-amazon sachinh-amazon added this pull request to the merge queue Jun 24, 2026
Merged via the queue into 1.1 with commit c2edf68 Jun 24, 2026
1 check passed
@sachinh-amazon sachinh-amazon deleted the fix/security-overrides-1.1 branch June 24, 2026 13:13
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants