Skip to content
Open
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion package.json
Original file line number Diff line number Diff line change
Expand Up @@ -75,7 +75,7 @@
"form-data": "^4.0.5",
"formstream": "^1.5.2",
"mime-types": "^2.1.35",
"qs": "^6.14.1",
"qs": "^6.14.2",

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

security-critical critical

The pnpm-lock.yaml file has not been updated to reflect the new version of qs. As the pull request description warns, this must be done manually. Without updating the lock file, the project will continue to use the old, vulnerable version of qs (6.14.1).

Please run pnpm install to update pnpm-lock.yaml and commit the resulting changes to ensure the security vulnerability is actually fixed.

Copy link

Copilot AI Feb 16, 2026

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The pnpm-lock.yaml file has not been updated to reflect this version change. Currently, pnpm-lock.yaml still references qs@6.14.1 (lines 1354 and 2887). Without updating the lockfile, the security vulnerability SNYK-JS-QS-15268416 will not actually be fixed when dependencies are installed.

The PR description acknowledges this issue with the warning "Failed to update the pnpm-lock.yaml, please update manually before merging." The lockfile must be regenerated by running pnpm install to ensure qs@6.14.2 is actually used.

Copilot uses AI. Check for mistakes.
"type-fest": "^4.41.0",
"undici": "^7.19.0",
"ylru": "^2.0.0"
Expand Down
Loading