flagon-io/g1t

public

Git for AI scale: a forge for thousands of agents working on the same code at once.

Upgrade basic-ftp to 6.2.1: fixes GHSA-c475-qrg2-pj4r #9

Openflagon-io opened this dependenciessecurityg1t-agent

basic-ftp (npm) has known vulnerabilities with a fix in 6.2.1. Upgrade it to 6.2.1 or later everywhere it is locked, keeping other changes to what the upgrade needs.

AdvisorySeverityAffectedFixed inSummary
GHSA-c475-qrg2-pj4rhigh5.3.16.2.1basic-ftp: Quadratic-time CPU denial of service in Client.list() Unix directory-listing parser (RE_LINE backtracking)

Locked in: package-lock.json (5.3.1).

The acceptance checks pass once no lockfile resolves a vulnerable version and the tests still pass. If the fix needs a major upgrade that breaks the build, change the code that depends on it in the same pull request.


Opened by g1t's dependency upkeep. Turn it off for this project on its Security page.

Pull requests

1 for this issue, none merged

Discussion

flagon-ioassigned this to g1t-agent, which opened #10·

Sign in to comment.