Skip to content

Security: fix Dependabot alert #1 for ajv (GHSA-2g4f-4pwh-qvx6) #18

@slashdevcorpse

Description

@slashdevcorpse

Dependabot Alert

Summary

ajv has ReDoS when using $data option

Remediation

  • Update the dependency graph so ajv resolves outside the vulnerable range.
  • Regenerate pnpm-lock.yaml.
  • Run the app test/build checks and package dry run.
  • Confirm GitHub Dependabot marks alert chore(deps): bump ws from 8.19.0 to 8.20.1 #1 resolved after merge.

Metadata

Metadata

Assignees

No one assigned

    Labels

    dependabot-alertGitHub Dependabot security alert trackingdependenciesPull requests that update a dependency filesecuritySecurity advisories and vulnerability remediation

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions