This is an automated email from the ASF dual-hosted git repository.
amaranhao pushed a commit to branch main
in repository https://gitbox.apache.org/repos/asf/couchdb-fauxton.git
The following commit(s) were added to refs/heads/main by this push:
new 576d727b fix: update node-force to address CVEs (#1499)
576d727b is described below
commit 576d727b284b7b267ef21ff5a9b85d953f0fa137
Author: Antonio Maranhao <[email protected]>
AuthorDate: Wed Dec 17 19:02:51 2025 -0500
fix: update node-force to address CVEs (#1499)
fix CVE-2025-66030, CVE-2025-12816, CVE-2025-66031
---
package-lock.json | 13 +++++++------
package.json | 3 +++
2 files changed, 10 insertions(+), 6 deletions(-)
diff --git a/package-lock.json b/package-lock.json
index 0a1f34ad..31cc7d40 100644
--- a/package-lock.json
+++ b/package-lock.json
@@ -15626,10 +15626,11 @@
}
},
"node_modules/node-forge": {
- "version": "1.3.1",
- "resolved":
"https://registry.npmjs.org/node-forge/-/node-forge-1.3.1.tgz",
- "integrity":
"sha512-dPEtOeMvF9VMcYV/1Wb8CPoVAXtp6MKMlcbAt4ddqmGqUJ6fQZFXkNZNkNlfevtNkGtaSoXf/vNNNSvgrdXwtA==",
+ "version": "1.3.3",
+ "resolved":
"https://registry.npmjs.org/node-forge/-/node-forge-1.3.3.tgz",
+ "integrity":
"sha512-rLvcdSyRCyouf6jcOIPe/BgwG/d7hKjzMKOas33/pHEr6gbq18IK9zV7DiPvzsz0oBJPme6qr6H6kGZuI9/DZg==",
"dev": true,
+ "license": "(BSD-3-Clause OR GPL-2.0)",
"engines": {
"node": ">= 6.13.0"
}
@@ -31081,9 +31082,9 @@
}
},
"node-forge": {
- "version": "1.3.1",
- "resolved":
"https://registry.npmjs.org/node-forge/-/node-forge-1.3.1.tgz",
- "integrity":
"sha512-dPEtOeMvF9VMcYV/1Wb8CPoVAXtp6MKMlcbAt4ddqmGqUJ6fQZFXkNZNkNlfevtNkGtaSoXf/vNNNSvgrdXwtA==",
+ "version": "1.3.3",
+ "resolved":
"https://registry.npmjs.org/node-forge/-/node-forge-1.3.3.tgz",
+ "integrity":
"sha512-rLvcdSyRCyouf6jcOIPe/BgwG/d7hKjzMKOas33/pHEr6gbq18IK9zV7DiPvzsz0oBJPme6qr6H6kGZuI9/DZg==",
"dev": true
},
"node-int64": {
diff --git a/package.json b/package.json
index 61140e4a..aadbebfb 100644
--- a/package.json
+++ b/package.json
@@ -108,6 +108,9 @@
"serialize-javascript": "^6.0.2",
"js-yaml": "4.1.1"
}
+ },
+ "mocha": {
+ "js-yaml": "4.1.1"
}
},
"scripts": {