Skip to content

KSP-6488: upgrade dependencies that have vulnerable cross-spawn version#154

Merged
rizchelwood merged 1 commit intomasterfrom
upgrade-cross-spawn-dependencies
Dec 2, 2025
Merged

KSP-6488: upgrade dependencies that have vulnerable cross-spawn version#154
rizchelwood merged 1 commit intomasterfrom
upgrade-cross-spawn-dependencies

Conversation

@rizchelwood
Copy link
Copy Markdown
Contributor

@rizchelwood rizchelwood commented Dec 1, 2025

Resolves https://linear.app/knapsack/issue/KSP-6448/twig-renderer-regular-expression-denial-of-service-redos-in-cross

Packages upgraded:

  • husky
  • eslint
  • execa
  • jest

Updates:

  • Fix eslint errors
  • Update execa commands to v2
  • Update husky config

@rizchelwood rizchelwood requested a review from greylabel December 1, 2025 18:29
@rizchelwood rizchelwood changed the title upgrade dependencies that have vulnerable cross-spawn version KSP-6437: upgrade dependencies that have vulnerable cross-spawn version Dec 1, 2025
@rizchelwood rizchelwood changed the title KSP-6437: upgrade dependencies that have vulnerable cross-spawn version KSP-6488: upgrade dependencies that have vulnerable cross-spawn version Dec 1, 2025
@rizchelwood rizchelwood merged commit 2c1c5fe into master Dec 2, 2025
1 check passed
@rizchelwood rizchelwood deleted the upgrade-cross-spawn-dependencies branch December 2, 2025 17:28
@github-actions
Copy link
Copy Markdown

github-actions bot commented Dec 2, 2025

🚀 PR was released in v3.2.8 🚀

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants