Skip to content

Conversation

@aikido-autofix
Copy link
Contributor

@aikido-autofix aikido-autofix bot commented Dec 4, 2025

This pull request addresses identified vulnerabilities and implements the necessary fixes to strengthen our security posture. Please review and approve so we can merge these changes promptly and reduce potential risk.

Any issues, please ping me, Alan Sower.

Thanks Team

Upgrading next to address vulnerabilities.

🚨 1 CVE resolved by this upgrade, including 1 critical CVE

This PR will resolve the following CVEs:

Issue Severity           Description
AIKIDO-2025-10869
🚨 CRITICAL
Affected versions of this package are vulnerable to unauthenticated remote code execution due to a flaw in how React Server Components decode payloads sent to Server Function endpoints. The issue can be exploited even if no Server Function endpoints are explicitly implemented. Attackers can craft ma...

@aikido-autofix aikido-autofix bot added the aikido Label created by Aikido AutoFix label Dec 4, 2025
@coderabbitai
Copy link

coderabbitai bot commented Dec 4, 2025

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.


Comment @coderabbitai help to get the list of available commands and usage tips.

@github-actions
Copy link

github-actions bot commented Dec 4, 2025

Size Change: 0 B

Total Size: 5.38 MB

ℹ️ View Unchanged
Filename Size
packages/vechain-kit/dist/assets 4.1 kB
packages/vechain-kit/dist/assets-aAdDxPJu.mjs 50.1 kB
packages/vechain-kit/dist/assets-aAdDxPJu.mjs.map 70.2 kB
packages/vechain-kit/dist/assets-DXVXPy3w.cjs 54.8 kB
packages/vechain-kit/dist/assets-DXVXPy3w.cjs.map 71.6 kB
packages/vechain-kit/dist/assets/index.cjs 716 B
packages/vechain-kit/dist/assets/index.d.cts 973 B
packages/vechain-kit/dist/assets/index.d.mts 973 B
packages/vechain-kit/dist/assets/index.mjs 718 B
packages/vechain-kit/dist/index-Bs6t5GxR.d.mts 5.63 kB
packages/vechain-kit/dist/index-Bs6t5GxR.d.mts.map 2.99 kB
packages/vechain-kit/dist/index-CKJkEBaG.d.cts 5.63 kB
packages/vechain-kit/dist/index-CKJkEBaG.d.cts.map 2.99 kB
packages/vechain-kit/dist/index-DHcFWhRZ.d.mts 144 kB
packages/vechain-kit/dist/index-DHcFWhRZ.d.mts.map 41.1 kB
packages/vechain-kit/dist/index-Dpu0rwkj.d.cts 144 kB
packages/vechain-kit/dist/index-Dpu0rwkj.d.cts.map 41.1 kB
packages/vechain-kit/dist/index.cjs 571 kB
packages/vechain-kit/dist/index.cjs.map 1.73 MB
packages/vechain-kit/dist/index.d.cts 20.1 kB
packages/vechain-kit/dist/index.d.mts 20.1 kB
packages/vechain-kit/dist/index.mjs 537 kB
packages/vechain-kit/dist/index.mjs.map 1.68 MB
packages/vechain-kit/dist/utils 4.1 kB
packages/vechain-kit/dist/utils-Bl-JeVTg.cjs 26.2 kB
packages/vechain-kit/dist/utils-Bl-JeVTg.cjs.map 63 kB
packages/vechain-kit/dist/utils-DAs6kMGs.mjs 21.1 kB
packages/vechain-kit/dist/utils-DAs6kMGs.mjs.map 62.7 kB
packages/vechain-kit/dist/utils/index.cjs 1.91 kB
packages/vechain-kit/dist/utils/index.d.cts 2.94 kB
packages/vechain-kit/dist/utils/index.d.mts 2.94 kB
packages/vechain-kit/dist/utils/index.mjs 1.93 kB

compressed-size-action

@Agilulfo1820 Agilulfo1820 merged commit deac832 into main Dec 4, 2025
12 of 13 checks passed
@Agilulfo1820 Agilulfo1820 deleted the fix/-security-issue'supdate-packages-11399870-99Mq branch December 4, 2025 10:15
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

aikido Label created by Aikido AutoFix

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants