Skip to content

Security: Bump basic-ftp override version#33207

Merged
r-farkhutdinov merged 1 commit into
DevExpress:26_1from
r-farkhutdinov:26_1_security_bump_deps
Apr 9, 2026
Merged

Security: Bump basic-ftp override version#33207
r-farkhutdinov merged 1 commit into
DevExpress:26_1from
r-farkhutdinov:26_1_security_bump_deps

Conversation

@r-farkhutdinov
Copy link
Copy Markdown
Contributor

No description provided.

@r-farkhutdinov r-farkhutdinov self-assigned this Apr 9, 2026
Copilot AI review requested due to automatic review settings April 9, 2026 09:03
@r-farkhutdinov r-farkhutdinov added dependencies Pull requests that update a dependency file 26_1 labels Apr 9, 2026
Copy link
Copy Markdown
Contributor

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Updates the workspace’s pnpm override and lockfile to ensure basic-ftp resolves to 5.2.1 (and not older vulnerable versions) across transitive dependencies.

Changes:

  • Bump pnpm override selector for basic-ftp from <5.2.0 to <5.2.1, targeting ~5.2.1.
  • Regenerate/update pnpm-lock.yaml to reflect basic-ftp@5.2.1 in packages and snapshots.

Reviewed changes

Copilot reviewed 1 out of 2 changed files in this pull request and generated no comments.

File Description
package.json Updates pnpm.overrides to force basic-ftp to ~5.2.1 for any dependency requesting <5.2.1.
pnpm-lock.yaml Updates lockfile entries so resolved dependency graph uses basic-ftp@5.2.1 (including get-uri’s dependency).
Files not reviewed (1)
  • pnpm-lock.yaml: Language not supported

@r-farkhutdinov r-farkhutdinov merged commit d53427d into DevExpress:26_1 Apr 9, 2026
107 checks passed
sjbur pushed a commit to sjbur/DevExtreme that referenced this pull request May 5, 2026
Co-authored-by: Ruslan Farkhutdinov <ruslan.farkhutdinov@devexpress.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

26_1 dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants