Skip to content
This repository was archived by the owner on Jan 27, 2026. It is now read-only.

Conversation

@ona-security-engineer
Copy link

Automated security fix by Ona Agent.

Summary

Upgrades qs from 6.14.0 to 6.14.1 to remediate CVE-2025-15284.

Vulnerability Details

Changes

  • Added overrides section to backend/catalog/package.json to force qs@^6.14.1
  • Updated backend/catalog/package-lock.json with the patched version

Verification

  • ✅ All 75 tests pass

Resolves: JONAS-66

Add npm override to force qs@^6.14.1 in backend/catalog to remediate
DoS vulnerability via arrayLimit bypass in bracket notation.

Co-authored-by: Ona <no-reply@ona.com>
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant