Skip to content

Removes reference to vulnerable QS version 6.13.0#28

Merged
SHession merged 1 commit intomainfrom
remove-reference-to-vulnerable-qs-version
Jan 20, 2026
Merged

Removes reference to vulnerable QS version 6.13.0#28
SHession merged 1 commit intomainfrom
remove-reference-to-vulnerable-qs-version

Conversation

@SHession
Copy link
Contributor

@SHession SHession commented Jan 19, 2026

What does this change?

Bumps Express's dependency on body-parser: 1.20.3 -> 1.20.4. Removing the vulnerable QS package.

Addressing: https://github.com/guardian/editorial-collaboration/security/dependabot/39.

How to test

Code is not in use therefore, does not currently require testing.

@SHession SHession added the maintenance Departmental tracking: maintenance work, not a fix or a feature label Jan 19, 2026
@SHession SHession merged commit df2fc66 into main Jan 20, 2026
6 of 7 checks passed
@SHession SHession deleted the remove-reference-to-vulnerable-qs-version branch January 20, 2026 07:49
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

maintenance Departmental tracking: maintenance work, not a fix or a feature

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

Comments