Skip to content

fixed basic-ftp version basic-ftp@5.0.5 to basic-ftp@5.2.0#11

Merged
SaranshBS merged 6 commits intomainfrom
basic-ftp-5.2.0
Mar 24, 2026
Merged

fixed basic-ftp version basic-ftp@5.0.5 to basic-ftp@5.2.0#11
SaranshBS merged 6 commits intomainfrom
basic-ftp-5.2.0

Conversation

@dheeren-gaud
Copy link
Contributor

upgraded vulnerable transitive dependency basic-ftp to a patched version by adding an npm override (basic-ftp: ^5.2.0) and updating the lockfile. This mitigates the path traversal risk in downloadToDir()

@dheeren-gaud dheeren-gaud requested a review from a team as a code owner March 18, 2026 07:56
@dheeren-gaud dheeren-gaud requested a review from MihirR-BS March 18, 2026 07:56
@SaranshBS SaranshBS merged commit 3eba4d7 into main Mar 24, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants