Skip to content

Conversation

@MikeMcC399
Copy link
Collaborator

Situation

npm audit reports a low severity vulnerability CVE-2025-5889 in a transient dependency:

used in action examples. This issue was previously not identified by Dependabot and so PR #1486 did not cover these instances.

Remaining lockfiles with vulnerable versions are:

Change

Update affected lock files to use:

@MikeMcC399 MikeMcC399 added the bug Something isn't working label Jun 16, 2025
@MikeMcC399 MikeMcC399 self-assigned this Jun 16, 2025
@cypress-app-bot
Copy link

@MikeMcC399 MikeMcC399 marked this pull request as ready for review June 16, 2025 16:53
@jennifer-shehane jennifer-shehane merged commit 4d7afe1 into cypress-io:master Jun 17, 2025
80 checks passed
@MikeMcC399 MikeMcC399 deleted the update/brace-expansion-part-2 branch June 17, 2025 14:19
@github-actions
Copy link

🎉 This PR is included in version 6.10.2 🎉

The release is available on:

Your semantic-release bot 📦🚀

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug Something isn't working released

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants