Skip to content

chore(deps): bump basic-ftp from 5.0.5 to 5.3.1#3225

Merged
nkaradzhov merged 1 commit into
masterfrom
dependabot/npm_and_yarn/basic-ftp-5.2.2
May 14, 2026
Merged

chore(deps): bump basic-ftp from 5.0.5 to 5.3.1#3225
nkaradzhov merged 1 commit into
masterfrom
dependabot/npm_and_yarn/basic-ftp-5.2.2

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot Bot commented on behalf of github Apr 10, 2026

Bumps basic-ftp from 5.0.5 to 5.3.1.

Release notes

Sourced from basic-ftp's releases.

5.3.1

5.3.0

  • Changed: Introduced an upper bound for total bytes of directory listing, fixes GHSA-rp42-5vxx-qpwr.
  • Added: Option to increase the upper bound for total bytes of directory listing in Client constructor.

5.2.2

5.2.1

5.2.0

  • Changed: Skip files with invalid name in downloadToDir.

5.1.0

  • Added: Add the option to prevent the use of separate transfer host IPs when using PASV. (#259)
Changelog

Sourced from basic-ftp's changelog.

5.3.1

5.3.0

  • Changed: Introduced an upper bound for total bytes of directory listing, fixes GHSA-rp42-5vxx-qpwr.
  • Added: Option to increase the upper bound for total bytes of directory listing in Client constructor.

5.2.2

5.2.1

5.2.0

5.1.0

  • Added: Add the option to prevent the use of separate transfer host IPs when using PASV. (#259)
Commits
Maintainer changes

This version was pushed to npm by patrickjuchli, a new releaser for basic-ftp since your current version.

Install script changes

This version adds prepare script that runs during installation. Review the package contents before updating.



Note

Medium Risk
Updates a transitive/dev dependency with upstream security-related behavior changes and updated lockfile resolution, which could affect install/build tooling but not production runtime logic.

Overview
Upgrades the basic-ftp dependency from 5.0.5 to 5.3.1 in package-lock.json.

The lockfile refresh also pulls in additional optional platform-specific @esbuild/* packages and fsevents, reflecting updated dependency resolution during install.

Reviewed by Cursor Bugbot for commit 93af0fa. Bugbot is set up for automated code reviews on this repo. Configure here.

Note
Automatic rebases have been disabled on this pull request as it has been open for over 30 days.

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Apr 10, 2026
@jit-ci
Copy link
Copy Markdown

jit-ci Bot commented Apr 10, 2026

🛡️ Jit Security Scan Results

CRITICAL HIGH MEDIUM

✅ No security findings were detected in this PR


Security scan by Jit

@nkaradzhov nkaradzhov closed this Apr 14, 2026
@dependabot @github
Copy link
Copy Markdown
Contributor Author

dependabot Bot commented on behalf of github Apr 14, 2026

OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

@dependabot dependabot Bot deleted the dependabot/npm_and_yarn/basic-ftp-5.2.2 branch April 14, 2026 10:24
@nkaradzhov nkaradzhov restored the dependabot/npm_and_yarn/basic-ftp-5.2.2 branch May 14, 2026 13:45
@nkaradzhov nkaradzhov reopened this May 14, 2026
@nkaradzhov
Copy link
Copy Markdown
Collaborator

@dependabot recreate

Bumps [basic-ftp](https://github.com/patrickjuchli/basic-ftp) from 5.0.5 to 5.3.1.
- [Release notes](https://github.com/patrickjuchli/basic-ftp/releases)
- [Changelog](https://github.com/patrickjuchli/basic-ftp/blob/master/CHANGELOG.md)
- [Commits](patrickjuchli/basic-ftp@v5.0.5...v5.3.1)

---
updated-dependencies:
- dependency-name: basic-ftp
  dependency-version: 5.2.2
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot changed the title chore(deps): bump basic-ftp from 5.0.5 to 5.2.2 chore(deps): bump basic-ftp from 5.0.5 to 5.3.1 May 14, 2026
@dependabot dependabot Bot force-pushed the dependabot/npm_and_yarn/basic-ftp-5.2.2 branch from 70eae0d to 93af0fa Compare May 14, 2026 13:49
@nkaradzhov nkaradzhov merged commit b048206 into master May 14, 2026
18 checks passed
@nkaradzhov nkaradzhov deleted the dependabot/npm_and_yarn/basic-ftp-5.2.2 branch May 14, 2026 14:08
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant