Skip to content

chore(deps): update dependency formidable to v2.1.3 [security]#714

Open
renovate[bot] wants to merge 1 commit intomainfrom
renovate/npm-formidable-vulnerability
Open

chore(deps): update dependency formidable to v2.1.3 [security]#714
renovate[bot] wants to merge 1 commit intomainfrom
renovate/npm-formidable-vulnerability

Conversation

@renovate
Copy link
Copy Markdown
Contributor

@renovate renovate bot commented May 27, 2025

This PR contains the following updates:

Package Change Age Confidence
formidable 2.1.2 -> 2.1.3 age confidence

GitHub Vulnerability Alerts

CVE-2025-46653

Formidable (aka node-formidable) 2.x before 2.1.3 and 3.x before 3.5.3 relies on hexoid to prevent guessing of filenames for untrusted executable content; however, hexoid is documented as not "cryptographically secure." (Also, there is a scenario in which only the last two characters of a hexoid string need to be guessed, but this is not often relevant.) NOTE: this does not imply that, in a typical use case, attackers will be able to exploit any hexoid behavior to upload and execute their own content.


Configuration

📅 Schedule: Branch creation - "" in timezone Europe/Paris, Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate bot force-pushed the renovate/npm-formidable-vulnerability branch from be30102 to 257b46e Compare June 4, 2025 08:36
@renovate renovate bot force-pushed the renovate/npm-formidable-vulnerability branch from 257b46e to f1aefe8 Compare June 22, 2025 11:05
@renovate renovate bot force-pushed the renovate/npm-formidable-vulnerability branch from f1aefe8 to 8538b31 Compare June 27, 2025 13:58
@renovate renovate bot force-pushed the renovate/npm-formidable-vulnerability branch from 8538b31 to 0bb5340 Compare June 27, 2025 14:23
@renovate renovate bot force-pushed the renovate/npm-formidable-vulnerability branch from 0bb5340 to c24ec68 Compare July 2, 2025 16:48
@renovate renovate bot requested a deployment to build-review July 2, 2025 16:48 Waiting
@renovate renovate bot requested a deployment to build-review July 2, 2025 16:48 Waiting
@sonarqubecloud
Copy link
Copy Markdown

sonarqubecloud bot commented Jul 2, 2025

@renovate renovate bot force-pushed the renovate/npm-formidable-vulnerability branch from c24ec68 to 99aa091 Compare August 10, 2025 15:53
@renovate renovate bot force-pushed the renovate/npm-formidable-vulnerability branch from 99aa091 to 337c98d Compare August 26, 2025 12:30
@renovate renovate bot force-pushed the renovate/npm-formidable-vulnerability branch from 337c98d to e7795d5 Compare August 31, 2025 12:19
@socket-security
Copy link
Copy Markdown

socket-security bot commented Aug 31, 2025

Warning

Review the following alerts detected in dependencies.

According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.

Action Severity Alert  (click "▶" to expand/collapse)
Warn High
Obfuscated code: npm safer-buffer is 94.0% likely obfuscated

Confidence: 0.94

Location: Package overview

From: ?npm/maildev@2.2.1npm/safer-buffer@2.1.2

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/safer-buffer@2.1.2. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

View full report

@renovate renovate bot force-pushed the renovate/npm-formidable-vulnerability branch from e7795d5 to 12d870c Compare September 25, 2025 17:41
@renovate renovate bot changed the title fix(deps): update dependency formidable to v2.1.3 [security] chore(deps): update dependency formidable to v2.1.3 [security] Sep 25, 2025
@renovate renovate bot force-pushed the renovate/npm-formidable-vulnerability branch from 12d870c to 285910a Compare October 21, 2025 18:41
@socket-security
Copy link
Copy Markdown

socket-security bot commented Oct 21, 2025

@renovate renovate bot force-pushed the renovate/npm-formidable-vulnerability branch from 285910a to 5118b89 Compare November 10, 2025 22:59
@renovate renovate bot force-pushed the renovate/npm-formidable-vulnerability branch from 5118b89 to 80bdc0d Compare November 18, 2025 17:30
@sonarqubecloud
Copy link
Copy Markdown

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants