Skip to content

Conversation

@jaaaaavier
Copy link
Contributor

This PR resolves a security vulnerability found in form-data (CVE-2025-7783) where insecure usage of Math.random() for multipart boundaries could lead to data injection attacks.

The Fix I have added a resolution in package.json to force the project to use form-data@^4.0.4 globally. This overrides the version constraint imposed by Cypress and aligns all dependencies to the secure version.

@vercel
Copy link

vercel bot commented Feb 3, 2026

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
website Ready Ready Preview, Comment Feb 3, 2026 10:55am

@jaaaaavier jaaaaavier self-assigned this Feb 3, 2026
@jaaaaavier jaaaaavier added the dependencies Pull requests that update a dependency file label Feb 3, 2026
@sonarqubecloud
Copy link

sonarqubecloud bot commented Feb 3, 2026

@jaaaaavier jaaaaavier changed the base branch from main to update/metatags- February 3, 2026 10:58
@jaaaaavier jaaaaavier changed the base branch from update/metatags- to main February 3, 2026 10:58
@jaaaaavier jaaaaavier changed the base branch from main to update/metatags- February 3, 2026 11:00
@jaaaaavier jaaaaavier changed the base branch from update/metatags- to main February 3, 2026 11:00
@jaaaaavier jaaaaavier changed the base branch from main to update/metatags- February 3, 2026 11:02
@jaaaaavier jaaaaavier merged commit 6658ff5 into update/metatags- Feb 3, 2026
10 checks passed
@jaaaaavier jaaaaavier deleted the fix/dependan-bot-alert branch February 3, 2026 11:02
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant