koa-body icon indicating copy to clipboard operation
koa-body copied to clipboard

chore: upgrade formidable

Open guillenotfound opened this issue 2 years ago • 14 comments

Upgrading formidable dependency to its latest version.

Checklist

  • [x] I have ensured my pull request is not behind the main or master branch of the original repository.
  • [x] I have rebased all commits where necessary so that reviewing this pull request can be done without having to merge it first.
  • [x] I have written a commit message that passes commitlint linting.
  • [ ] I have ensured that my code changes pass linting tests.
  • [x] I have ensured that my code changes pass unit tests.
  • [x] I have described my pull request and the reasons for code changes along with context if necessary.

guillenotfound avatar Oct 25 '23 10:10 guillenotfound

New and updated dependencies detected. Learn more about Socket for GitHub ↗︎

Packages Version New capabilities Transitives Size Publisher
formidable 3.5.1 None +0 165 kB grossacasacs
@types/formidable 2.0.6...3.4.4 None +0/-0 19 kB types

socket-security[bot] avatar Oct 25 '23 10:10 socket-security[bot]

Any chance to get this merge and create a new release? 🙏

guillenotfound avatar Oct 30 '23 08:10 guillenotfound

Any chance to get this merge and create a new release? 🙏

guillenotfound avatar Oct 30 '23 08:10 guillenotfound

Hey everyone, can we get this merge and a new release? Yarn audit just warned us that formidable has a critical vulnerability related to file uploads, so this would be much appreciated

ThisGuyOverHere avatar Apr 23 '24 08:04 ThisGuyOverHere

Hey here. npm audit alarm us, that formidable has critical vulnerability . Can we merge it and create new release?

fant1kua avatar Apr 23 '24 09:04 fant1kua

Same problem

EvgeniyShigartsov avatar Apr 23 '24 13:04 EvgeniyShigartsov

same, too

zakiFaner avatar Apr 24 '24 08:04 zakiFaner

I have same problem could we fix this asap please

othmane-elgoubi avatar Apr 24 '24 09:04 othmane-elgoubi

Hey y'all. When can we get this merged in? This is a fairly large blocker for a lot of projects

dbidwell94 avatar Apr 24 '24 18:04 dbidwell94

@MarkHerhold please

zakiFaner avatar Apr 25 '24 06:04 zakiFaner

@othmane-elgoubi when can we expect this to be merged and released? Thanks!

jineshjin avatar Apr 25 '24 11:04 jineshjin

Pretty please can this be merged and released asap?

yemling avatar Apr 25 '24 15:04 yemling

The only saving grace to this seemingly dead project is that https://github.com/advisories/GHSA-8cp3-66vr-3r4c was withdrawn.

dbidwell94 avatar Apr 25 '24 17:04 dbidwell94