Skip to content

[_] Upgrade eslint#37

Merged
TamaraFinogina merged 1 commit into
masterfrom
upgrade_eslint
Mar 18, 2026
Merged

[_] Upgrade eslint#37
TamaraFinogina merged 1 commit into
masterfrom
upgrade_eslint

Conversation

@TamaraFinogina
Copy link
Copy Markdown
Contributor

@TamaraFinogina TamaraFinogina commented Mar 18, 2026

Description

Version v6.12.6 of ajv (dependency of eslint) is vulnerable to Uncontrolled Resource Consumption: CVE-2025-69873. Not exploitable, but shows up in scans.

The easiest way to fix it is to upgrade to ESLint 10.0.2, which has ajv as a dependency.

Related Issues

MT-ST-01 from https://inxt.atlassian.net/wiki/spaces/T/pages/1007583233/PQ+Meet+Code+Security+Assessment#MT-ST-01

Checklist

  • Changes have been tested locally.
  • Unit tests have been written or updated as necessary.
  • The code adheres to the repository's coding standards.
  • Relevant documentation has been added or updated.
  • No new warnings or errors have been introduced.
  • SonarCloud issues have been reviewed and addressed.
  • QA Passed

Testing Process

unit tests

@TamaraFinogina TamaraFinogina self-assigned this Mar 18, 2026
@sonarqubecloud
Copy link
Copy Markdown

@TamaraFinogina TamaraFinogina merged commit f408208 into master Mar 18, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants