Skip to content

Conversation

@MikeMcC399
Copy link
Collaborator

Situation

npm audit shows

16 vulnerabilities (1 low, 2 moderate, 13 high)

Change

Update

From To
[email protected] [email protected] (latest)

and execute npm audit fix.

Verification

npm ci
npm audit

@cypress-app-bot
Copy link
Collaborator

@jennifer-shehane jennifer-shehane merged commit 0cefd86 into cypress-io:master Jan 28, 2026
12 checks passed
@MikeMcC399 MikeMcC399 deleted the update/semantic-release branch January 28, 2026 18:30
@MikeMcC399
Copy link
Collaborator Author

In between the submission of this PR and its merge, a new vulnerability has been published 🙁

CVE-2026-24842
GHSA-34x7-hfp2-rc4v

resulting in

7 high severity vulnerabilities

due to [email protected]

I will follow up.

@MikeMcC399
Copy link
Collaborator Author

According to npm, the vulnerabilities reported for node-tar are not exploitable in npm.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants