This is an automated email from the ASF dual-hosted git repository.
yesamer pushed a commit to branch main
in repository https://gitbox.apache.org/repos/asf/incubator-kie-tools.git
The following commit(s) were added to refs/heads/main by this push:
new 987ffa32fee NO-ISSUE: Upgrade qs to 6.16.0 to address CVE-2026-82417
and CVE-2026-82562 (#3992)
987ffa32fee is described below
commit 987ffa32fee480b7c093774d19d1bbaab540590f
Author: Adarsh vk <[email protected]>
AuthorDate: Sat Sep 12 19:29:36 2026 +0530
NO-ISSUE: Upgrade qs to 6.16.0 to address CVE-2026-82417 and CVE-2026-82562
(#3992)
---
pnpm-lock.yaml | 40 ++++++++++++++++------------------------
pnpm-workspace.yaml | 6 +++---
2 files changed, 19 insertions(+), 27 deletions(-)
diff --git a/pnpm-lock.yaml b/pnpm-lock.yaml
index e5f82155815..f2e140c4626 100644
--- a/pnpm-lock.yaml
+++ b/pnpm-lock.yaml
@@ -14,7 +14,7 @@ overrides:
minimatch@^3>brace-expansion: 1.1.18
minimatch@^5>brace-expansion: 2.1.4
openapi-types: 7.2.3
- '@cypress/request@3>qs': 6.15.2
+ qs: ^6.16.0
path-to-regexp@^0: 0.1.13
react-dropzone: ^11.4.2
superagent: 10.2.2
@@ -20836,12 +20836,8 @@ packages:
resolution: {integrity:
sha512-8YOJEHtxpySA3fFDyCRxA+UUV+fA+rTWnuWvylOK/NCjhY+b4ocCtmu8TtsWb+mYeU+GCHf/S66KZF/AsteKHg==}
engines: {node: '>=0.9'}
- [email protected]:
- resolution: {integrity:
sha512-Rzq0KEyX/w/tEybncDgdkZrJgVUsUMk3xjh3t5bv3S1HTAtg+uOYt72+ZfwiQwKdysThkTBdL/rTi6HDmX9Ddw==}
- engines: {node: '>=0.6'}
-
- [email protected]:
- resolution: {integrity:
sha512-O9gl3zCl5h5blw1KGUzQKhA5oUXSl8rwUIM5o0S3nCXMliSvy5Dzx7/DJcI+SwgICv+IneSZwhBh1oSyEHA71A==}
+ [email protected]:
+ resolution: {integrity:
sha512-h6fhOIaRrID2CbEY2fqs+7t+UXZo+MLAnU5gRIq85uFtdiUPCdsApMlHhXogKVM4HM2DVbIjGNTTYH2OcmP1vA==}
engines: {node: '>=0.6'}
[email protected]:
@@ -25688,7 +25684,7 @@ snapshots:
json-stringify-safe: 5.0.1
mime-types: 2.1.35
performance-now: 2.1.0
- qs: 6.15.2
+ qs: 6.16.0
safe-buffer: 5.2.1
tough-cookie: 5.1.2
tunnel-agent: 0.6.0
@@ -29502,7 +29498,7 @@ snapshots:
'@storybook/client-logger': 7.6.24
'@storybook/core-events': 7.6.24
'@storybook/global': 5.0.0
- qs: 6.15.3
+ qs: 6.16.0
telejson: 7.2.0
tiny-invariant: 1.3.3
@@ -29915,7 +29911,7 @@ snapshots:
dequal: 2.0.3
lodash: 4.18.1
memoizerific: 1.11.3
- qs: 6.15.3
+ qs: 6.16.0
synchronous-promise: 2.0.17
ts-dedent: 2.3.0
util-deprecate: 1.0.2
@@ -30098,7 +30094,7 @@ snapshots:
dependencies:
'@storybook/client-logger': 7.6.24
memoizerific: 1.11.3
- qs: 6.15.3
+ qs: 6.16.0
'@storybook/[email protected]([email protected])':
dependencies:
@@ -32268,7 +32264,7 @@ snapshots:
http-errors: 2.0.1
iconv-lite: 0.4.24
on-finished: 2.4.1
- qs: 6.15.3
+ qs: 6.16.0
raw-body: 2.5.3
type-is: 1.6.18
unpipe: 1.0.0
@@ -32283,7 +32279,7 @@ snapshots:
http-errors: 2.0.1
iconv-lite: 0.7.3
on-finished: 2.4.1
- qs: 6.15.3
+ qs: 6.16.0
raw-body: 3.0.2
type-is: 2.1.0
transitivePeerDependencies:
@@ -34712,7 +34708,7 @@ snapshots:
parseurl: 1.3.3
path-to-regexp: 0.1.13
proxy-addr: 2.0.7
- qs: 6.15.3
+ qs: 6.16.0
range-parser: 1.2.1
safe-buffer: 5.2.1
send: 0.19.2
@@ -34747,7 +34743,7 @@ snapshots:
once: 1.4.0
parseurl: 1.3.3
proxy-addr: 2.0.7
- qs: 6.15.3
+ qs: 6.16.0
range-parser: 1.3.0
router: 2.2.0
send: 1.2.1
@@ -39396,11 +39392,7 @@ snapshots:
[email protected]: {}
- [email protected]:
- dependencies:
- side-channel: 1.1.1
-
- [email protected]:
+ [email protected]:
dependencies:
es-define-property: 1.0.1
side-channel: 1.1.1
@@ -41105,7 +41097,7 @@ snapshots:
formidable: 3.5.4
methods: 1.1.2
mime: 2.6.0
- qs: 6.15.3
+ qs: 6.16.0
transitivePeerDependencies:
- supports-color
@@ -41687,7 +41679,7 @@ snapshots:
[email protected]:
dependencies:
- qs: 6.15.3
+ qs: 6.16.0
tunnel: 0.0.6
underscore: 1.13.8
@@ -41792,7 +41784,7 @@ snapshots:
[email protected]:
dependencies:
- qs: 6.15.3
+ qs: 6.16.0
[email protected]:
dependencies:
@@ -41896,7 +41888,7 @@ snapshots:
[email protected]:
dependencies:
punycode: 1.4.1
- qs: 6.15.3
+ qs: 6.16.0
[email protected]:
dependencies:
diff --git a/pnpm-workspace.yaml b/pnpm-workspace.yaml
index 3a551cd8721..771f5b42852 100644
--- a/pnpm-workspace.yaml
+++ b/pnpm-workspace.yaml
@@ -16,9 +16,9 @@ overrides:
"minimatch@^3>brace-expansion": "1.1.18"
"minimatch@^5>brace-expansion": "2.1.4"
"openapi-types": "7.2.3"
- # CVE-2026-8723: Fix TypeError in qs.stringify (comma arrayFormat +
encodeValuesOnly with null/undefined)
- # Overriding transitive dependency until @cypress/request updates to patched
qs version
- "@cypress/request@3>qs": "6.15.2"
+ # CVE-2026-82417, CVE-2026-82562: TypeError in qs.stringify on a
non-callable constructor.isBuffer
+ # Overriding transitive dependency until all parents update to patched qs
version
+ "qs": "^6.16.0"
"path-to-regexp@^0": "0.1.13"
"react-dropzone": "^11.4.2"
"superagent": "10.2.2"
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]