Skip to content

Conversation

@undx
Copy link
Member

@undx undx commented Jan 26, 2026

@undx undx requested review from Copilot and yyin-talend and removed request for Copilot January 26, 2026 16:38
Copy link

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR addresses a security vulnerability (CVE) in the qs package by adding an override to enforce version >=6.14.1 across frontend package configurations. The changes also reorganize dependencies alphabetically for better maintainability.

Changes:

  • Added qs package override to enforce minimum version >=6.14.1 for security
  • Reorganized dependencies alphabetically in package.json files
  • Updated path-to-regexp from version 0.1.10 to 0.1.12 in devDependencies

Reviewed changes

Copilot reviewed 4 out of 6 changed files in this pull request and generated no comments.

File Description
component-tools-webapp/src/main/frontend/package.json Added qs override and reorganized dependencies alphabetically
component-tools-webapp/src/main/frontend/package-template.json Added qs override and reorganized dependencies alphabetically
component-starter-server/src/main/frontend/package.json Added qs override to existing overrides section and reorganized dependencies
component-starter-server/src/main/frontend/package-template.json Added qs override to existing overrides section and reorganized dependencies
Files not reviewed (1)
  • component-tools-webapp/src/main/frontend/package-lock.json: Language not supported

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

@sonar-eks
Copy link

sonar-eks bot commented Jan 26, 2026

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants