WIP: fix(deps): uuid override ^11.0.0 — GHSA-w5hq-g745-h8pq #86
No reviewers
Labels
No labels
autopilot:pending-human
source:analyste
source:defenseur
source:human
source:medic
status:approved
status:blocked
status:in-progress
status:needs-clarification
status:needs-fix
status:ready
status:review
status:triage
type:bug
type:feature
type:infra
type:refactor
type:schema
type:security
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference: maximus/simpl-liste#86
Loading…
Reference in a new issue
No description provided.
Delete branch "defenseur-auto/d8fb641059-1777737632446"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Vuln GHSA-w5hq-g745-h8pq detectee (uuid <10.0.0).
Fix: override uuid ^11.0.0 (CJS stable, uuid@11.1.1 installe).
Rationale: uuid@10 est ESM-only (require() echoue) ; uuid@11 est la version CJS minimale qui satisfait la GHSA. Le bump ^14.0.0 du premier essai etait inutile — ^11.0.0 pre-existant est la correction correcte.
Tests: npm test pass — 6/6 checks (v3/v5 buffer arg, sites vuln).
Source: defenseur-simpl-liste 2026-05-02.
Closes #<ISSUE_NUMBER>
Closes #85
fix(deps): uuid override ^11.0.0 — GHSA-w5hq-g745-h8pqto WIP: fix(deps): uuid override ^11.0.0 — GHSA-w5hq-g745-h8pqWIP: fix(deps): uuid override ^11.0.0 — GHSA-w5hq-g745-h8pqto fix(deps): uuid override ^11.0.0 — GHSA-w5hq-g745-h8pqfix(deps): uuid override ^11.0.0 — GHSA-w5hq-g745-h8pqto WIP: fix(deps): uuid override ^11.0.0 — GHSA-w5hq-g745-h8pqPull request closed