Skip to content

[1.2] Fix security scan: regenerate lockfiles + override undici, ws, tar, form-data#259

Merged
sachinh-amazon merged 1 commit into
1.2from
fix/security-overrides-1.2
Jun 24, 2026
Merged

[1.2] Fix security scan: regenerate lockfiles + override undici, ws, tar, form-data#259
sachinh-amazon merged 1 commit into
1.2from
fix/security-overrides-1.2

Conversation

@sachinh-amazon

Copy link
Copy Markdown
Contributor

Fixes npm ci failure (missing http-proxy in lockfile) and HIGH/MEDIUM CVEs: CVE-2026-6734, CVE-2026-9697, CVE-2026-12151 (undici), CVE-2026-48779 (ws), CVE-2026-12143 (form-data), CVE-2026-53655 (tar)

… CVEs

- Fix npm ci failure: regenerate package-lock-overrides to include http-proxy
- undici: ^7.24.0 → ^7.28.0 (CVE-2026-6734, CVE-2026-9697, CVE-2026-12151)
- ws: ^8.20.1 → ^8.21.0, chrome-remote-interface/ws: ^7.5.11 (CVE-2026-48779)
- form-data: ^4.0.6 (CVE-2026-12143)
- tar: ^7.5.16 (CVE-2026-53655)

Regenerated package-lock overrides for all targets.
@sachinh-amazon sachinh-amazon requested review from a team as code owners June 24, 2026 11:57
@sachinh-amazon sachinh-amazon temporarily deployed to security-scanning-workflow-env June 24, 2026 11:58 — with GitHub Actions Inactive
@sachinh-amazon sachinh-amazon temporarily deployed to security-scanning-workflow-env June 24, 2026 11:58 — with GitHub Actions Inactive
@sachinh-amazon sachinh-amazon had a problem deploying to security-scanning-workflow-env June 24, 2026 11:58 — with GitHub Actions Failure
@sachinh-amazon sachinh-amazon temporarily deployed to security-scanning-workflow-env June 24, 2026 11:58 — with GitHub Actions Inactive
@sachinh-amazon sachinh-amazon had a problem deploying to security-scanning-workflow-env June 24, 2026 11:58 — with GitHub Actions Failure
@sachinh-amazon sachinh-amazon temporarily deployed to security-scanning-workflow-env June 24, 2026 11:58 — with GitHub Actions Inactive
@sachinh-amazon sachinh-amazon had a problem deploying to security-scanning-workflow-env June 24, 2026 11:58 — with GitHub Actions Failure
@sachinh-amazon sachinh-amazon had a problem deploying to security-scanning-workflow-env June 24, 2026 11:58 — with GitHub Actions Failure
@sachinh-amazon sachinh-amazon added this pull request to the merge queue Jun 24, 2026
Merged via the queue into 1.2 with commit fd6c28d Jun 24, 2026
8 of 16 checks passed
@sachinh-amazon sachinh-amazon deleted the fix/security-overrides-1.2 branch June 24, 2026 13:13
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants