Skip to content

Conversation

@MikeMcC399
Copy link
Collaborator

This PR updates the examples to cypress@15.8.0 released Dec 16, 2025.

systeminformation vulnerability

CVE-2025-68154

During update, npm reported the high severity vulnerability CVE-2025-68154 (GHSA-wphj-fx3q-84ch) in Cypress in examples regarding the use of the npm module systeminformation<5.27.14 This is logged as issue cypress-io/cypress#33146 and has to be fixed in the Cypress repo and released before it can be fixed here.

pnpm and Yarn do not report vulnerabilities during installation. These are separate commands, for instance the following commands show the vulnerability CVE-2025-68154:

cd examples/yarn-classic
yarn audit
cd ../yarn-modern
corepack enable yarn
yarn npm audit -R
cd ../basic-pnpm
pnpm audit

@cypress-app-bot
Copy link

@MikeMcC399 MikeMcC399 self-assigned this Dec 17, 2025
@MikeMcC399 MikeMcC399 marked this pull request as ready for review December 17, 2025 11:38
Copy link
Member

@jennifer-shehane jennifer-shehane left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thank you for logging the new issue. I've been doing a LOT of dep/CVE maintenance lately. 👍🏻

@jennifer-shehane jennifer-shehane merged commit ed2a10d into cypress-io:master Dec 17, 2025
82 checks passed
@MikeMcC399
Copy link
Collaborator Author

@jennifer-shehane

Thank you for logging the new issue. I've been doing a LOT of dep/CVE maintenance lately. 👍🏻

No problem! I saw that you've introduced knip and that you're working through major clean-up work!

@MikeMcC399 MikeMcC399 deleted the update/cypress-15.8.0 branch December 17, 2025 14:22
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants