Skip to content

fixed basic-ftp version basic-ftp@5.0.5 to basic-ftp@5.2.0#11

Open
dheeren-gaud wants to merge 4 commits intomainfrom
basic-ftp-5.2.0
Open

fixed basic-ftp version basic-ftp@5.0.5 to basic-ftp@5.2.0#11
dheeren-gaud wants to merge 4 commits intomainfrom
basic-ftp-5.2.0

Conversation

@dheeren-gaud
Copy link

upgraded vulnerable transitive dependency basic-ftp to a patched version by adding an npm override (basic-ftp: ^5.2.0) and updating the lockfile. This mitigates the path traversal risk in downloadToDir()

@dheeren-gaud dheeren-gaud requested a review from a team as a code owner March 18, 2026 07:56
@dheeren-gaud dheeren-gaud requested a review from MihirR-BS March 18, 2026 07:56
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant