Skip to content

Conversation

@aikido-autofix
Copy link
Contributor

This PR will resolve the following CVEs:

CVE ID Severity Description
CVE-2022-25881
LOW
This affects versions of the package http-cache-semantics before 4.1.1. The issue can be exploited via malicious request header values sent to a server, when that server reads the cache policy from the request using this library.

@vercel
Copy link

vercel bot commented Apr 14, 2025

The latest updates on your projects. Learn more about Vercel for Git ↗︎

Name Status Preview Comments Updated (UTC)
tools ✅ Ready (Inspect) Visit Preview 💬 Add feedback Apr 14, 2025 3:16pm

@deepsource-io
Copy link
Contributor

deepsource-io bot commented Apr 14, 2025

Here's the code health analysis summary for commits 0673785..2d84b76. View details on DeepSource ↗.

Analysis Summary

AnalyzerStatusSummaryLink
DeepSource Scala LogoScala✅ SuccessView Check ↗
DeepSource Swift LogoSwift✅ SuccessView Check ↗
DeepSource JavaScript LogoJavaScript✅ SuccessView Check ↗
DeepSource Ruby LogoRuby✅ SuccessView Check ↗
DeepSource C & C++ LogoC & C++✅ SuccessView Check ↗
DeepSource C# LogoC#✅ SuccessView Check ↗
DeepSource Rust LogoRust✅ SuccessView Check ↗
DeepSource Shell LogoShell✅ SuccessView Check ↗
DeepSource Terraform LogoTerraform✅ SuccessView Check ↗
DeepSource Test coverage LogoTest coverage⚠️ Artifact not reportedTimed out: Artifact was never reportedView Check ↗
DeepSource SQL LogoSQL✅ SuccessView Check ↗
DeepSource Secrets LogoSecrets✅ SuccessView Check ↗
DeepSource Ansible LogoAnsible✅ SuccessView Check ↗

💡 If you’re a repository administrator, you can configure the quality gates from the settings.

@sonarqubecloud
Copy link

@LCSOGthb LCSOGthb merged commit 66f04bb into main Apr 15, 2025
25 of 27 checks passed
@LCSOGthb LCSOGthb deleted the fix/aikido-security-update-packages-3771870-wY73 branch April 15, 2025 00:49
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants