Skip to content

Commit e573f39

Browse files
amitsi-bsclaude
andcommitted
LTS-2751/3157/3397: bump basic-ftp, fast-uri, tmp to fixed versions (npm overrides)
Security dependency-CVE bumps (APPSEC-449) via package.json `overrides` (all three are transitive/package-lock deps): - basic-ftp ^5.2.0 -> ^5.3.1 : resolves 5.3.1. Clears GHSA-rpmf-866q-6p89 / GHSA-rp42-5vxx-qpwr / GHSA-chqc-8p9q-pq6q / GHSA-6v7q-wjvx-w8wg (CRLF/FTP cmd injection + DoS, <=5.3.0). LTS-2751 - fast-uri +^3.1.3 : resolves 3.1.3. Clears GHSA-q3j6-qgpj-74h6 / GHSA-v39h-62p7-jpjc (path traversal + host confusion, <=3.1.1). LTS-3157 - tmp +0.2.7 : resolves 0.2.7. Clears GHSA-7c78-jf6q-g5cm (path traversal via non-string template, 0.2.6). Avoids the semver-major browserstack-node-sdk downgrade npm audit fix would otherwise force. LTS-3397 Verified: npm audit no longer flags basic-ftp/fast-uri/tmp. lodash (LTS-2752) is already at a safe 4.18.1 in the resolved tree (not flagged) - no change needed. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
1 parent 8fae217 commit e573f39

2 files changed

Lines changed: 27 additions & 50 deletions

File tree

‎package-lock.json‎

Lines changed: 24 additions & 49 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

‎package.json‎

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -16,7 +16,9 @@
1616
"qs": "6.14.2",
1717
"jws": "4.0.1",
1818
"tar-fs": "3.1.1",
19-
"basic-ftp": "^5.2.0",
19+
"basic-ftp": "^5.3.1",
20+
"fast-uri": "^3.1.3",
21+
"tmp": "0.2.7",
2022
"protobufjs": "7.6.4",
2123
"glob@7.2.3": {
2224
"minimatch": "3.1.5"

0 commit comments

Comments
 (0)