This is an automated email from the ASF dual-hosted git repository.

yesamer pushed a commit to branch main
in repository https://gitbox.apache.org/repos/asf/incubator-kie-tools.git


The following commit(s) were added to refs/heads/main by this push:
     new 987ffa32fee NO-ISSUE: Upgrade qs to 6.16.0 to address CVE-2026-82417 
and CVE-2026-82562 (#3992)
987ffa32fee is described below

commit 987ffa32fee480b7c093774d19d1bbaab540590f
Author: Adarsh vk <[email protected]>
AuthorDate: Sat Sep 12 19:29:36 2026 +0530

    NO-ISSUE: Upgrade qs to 6.16.0 to address CVE-2026-82417 and CVE-2026-82562 
(#3992)
---
 pnpm-lock.yaml      | 40 ++++++++++++++++------------------------
 pnpm-workspace.yaml |  6 +++---
 2 files changed, 19 insertions(+), 27 deletions(-)

diff --git a/pnpm-lock.yaml b/pnpm-lock.yaml
index e5f82155815..f2e140c4626 100644
--- a/pnpm-lock.yaml
+++ b/pnpm-lock.yaml
@@ -14,7 +14,7 @@ overrides:
   minimatch@^3>brace-expansion: 1.1.18
   minimatch@^5>brace-expansion: 2.1.4
   openapi-types: 7.2.3
-  '@cypress/request@3>qs': 6.15.2
+  qs: ^6.16.0
   path-to-regexp@^0: 0.1.13
   react-dropzone: ^11.4.2
   superagent: 10.2.2
@@ -20836,12 +20836,8 @@ packages:
     resolution: {integrity: 
sha512-8YOJEHtxpySA3fFDyCRxA+UUV+fA+rTWnuWvylOK/NCjhY+b4ocCtmu8TtsWb+mYeU+GCHf/S66KZF/AsteKHg==}
     engines: {node: '>=0.9'}
 
-  [email protected]:
-    resolution: {integrity: 
sha512-Rzq0KEyX/w/tEybncDgdkZrJgVUsUMk3xjh3t5bv3S1HTAtg+uOYt72+ZfwiQwKdysThkTBdL/rTi6HDmX9Ddw==}
-    engines: {node: '>=0.6'}
-
-  [email protected]:
-    resolution: {integrity: 
sha512-O9gl3zCl5h5blw1KGUzQKhA5oUXSl8rwUIM5o0S3nCXMliSvy5Dzx7/DJcI+SwgICv+IneSZwhBh1oSyEHA71A==}
+  [email protected]:
+    resolution: {integrity: 
sha512-h6fhOIaRrID2CbEY2fqs+7t+UXZo+MLAnU5gRIq85uFtdiUPCdsApMlHhXogKVM4HM2DVbIjGNTTYH2OcmP1vA==}
     engines: {node: '>=0.6'}
 
   [email protected]:
@@ -25688,7 +25684,7 @@ snapshots:
       json-stringify-safe: 5.0.1
       mime-types: 2.1.35
       performance-now: 2.1.0
-      qs: 6.15.2
+      qs: 6.16.0
       safe-buffer: 5.2.1
       tough-cookie: 5.1.2
       tunnel-agent: 0.6.0
@@ -29502,7 +29498,7 @@ snapshots:
       '@storybook/client-logger': 7.6.24
       '@storybook/core-events': 7.6.24
       '@storybook/global': 5.0.0
-      qs: 6.15.3
+      qs: 6.16.0
       telejson: 7.2.0
       tiny-invariant: 1.3.3
 
@@ -29915,7 +29911,7 @@ snapshots:
       dequal: 2.0.3
       lodash: 4.18.1
       memoizerific: 1.11.3
-      qs: 6.15.3
+      qs: 6.16.0
       synchronous-promise: 2.0.17
       ts-dedent: 2.3.0
       util-deprecate: 1.0.2
@@ -30098,7 +30094,7 @@ snapshots:
     dependencies:
       '@storybook/client-logger': 7.6.24
       memoizerific: 1.11.3
-      qs: 6.15.3
+      qs: 6.16.0
 
   '@storybook/[email protected]([email protected])':
     dependencies:
@@ -32268,7 +32264,7 @@ snapshots:
       http-errors: 2.0.1
       iconv-lite: 0.4.24
       on-finished: 2.4.1
-      qs: 6.15.3
+      qs: 6.16.0
       raw-body: 2.5.3
       type-is: 1.6.18
       unpipe: 1.0.0
@@ -32283,7 +32279,7 @@ snapshots:
       http-errors: 2.0.1
       iconv-lite: 0.7.3
       on-finished: 2.4.1
-      qs: 6.15.3
+      qs: 6.16.0
       raw-body: 3.0.2
       type-is: 2.1.0
     transitivePeerDependencies:
@@ -34712,7 +34708,7 @@ snapshots:
       parseurl: 1.3.3
       path-to-regexp: 0.1.13
       proxy-addr: 2.0.7
-      qs: 6.15.3
+      qs: 6.16.0
       range-parser: 1.2.1
       safe-buffer: 5.2.1
       send: 0.19.2
@@ -34747,7 +34743,7 @@ snapshots:
       once: 1.4.0
       parseurl: 1.3.3
       proxy-addr: 2.0.7
-      qs: 6.15.3
+      qs: 6.16.0
       range-parser: 1.3.0
       router: 2.2.0
       send: 1.2.1
@@ -39396,11 +39392,7 @@ snapshots:
 
   [email protected]: {}
 
-  [email protected]:
-    dependencies:
-      side-channel: 1.1.1
-
-  [email protected]:
+  [email protected]:
     dependencies:
       es-define-property: 1.0.1
       side-channel: 1.1.1
@@ -41105,7 +41097,7 @@ snapshots:
       formidable: 3.5.4
       methods: 1.1.2
       mime: 2.6.0
-      qs: 6.15.3
+      qs: 6.16.0
     transitivePeerDependencies:
       - supports-color
 
@@ -41687,7 +41679,7 @@ snapshots:
 
   [email protected]:
     dependencies:
-      qs: 6.15.3
+      qs: 6.16.0
       tunnel: 0.0.6
       underscore: 1.13.8
 
@@ -41792,7 +41784,7 @@ snapshots:
 
   [email protected]:
     dependencies:
-      qs: 6.15.3
+      qs: 6.16.0
 
   [email protected]:
     dependencies:
@@ -41896,7 +41888,7 @@ snapshots:
   [email protected]:
     dependencies:
       punycode: 1.4.1
-      qs: 6.15.3
+      qs: 6.16.0
 
   [email protected]:
     dependencies:
diff --git a/pnpm-workspace.yaml b/pnpm-workspace.yaml
index 3a551cd8721..771f5b42852 100644
--- a/pnpm-workspace.yaml
+++ b/pnpm-workspace.yaml
@@ -16,9 +16,9 @@ overrides:
   "minimatch@^3>brace-expansion": "1.1.18"
   "minimatch@^5>brace-expansion": "2.1.4"
   "openapi-types": "7.2.3"
-  # CVE-2026-8723: Fix TypeError in qs.stringify (comma arrayFormat + 
encodeValuesOnly with null/undefined)
-  # Overriding transitive dependency until @cypress/request updates to patched 
qs version
-  "@cypress/request@3>qs": "6.15.2"
+  # CVE-2026-82417, CVE-2026-82562: TypeError in qs.stringify on a 
non-callable constructor.isBuffer
+  # Overriding transitive dependency until all parents update to patched qs 
version
+  "qs": "^6.16.0"
   "path-to-regexp@^0": "0.1.13"
   "react-dropzone": "^11.4.2"
   "superagent": "10.2.2"


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to