fix: update node-forge to 1.4.0 to patch security vulnerabilities (#46)

Resolves 4 high-severity vulnerabilities in node-forge:
- GHSA-2328-f5f3-gj25: basicConstraints bypass
- GHSA-q67f-28xg-22rw: signature forgery Ed25519
- GHSA-5m6q-g25r-mvwx: Denial of Service via Infinite Loop
- GHSA-ppp5-5v6c-4jwp: signature forgery RSA-PKCS

Fixes PRI-21

Co-authored-by: Pawla Abdul (Bot) <pawla@groombook.dev>
This commit was merged in pull request #46.
This commit is contained in:
privilegedescalation-engineer[bot]
2026-04-15 00:14:40 +00:00
committed by GitHub
parent 2798bca085
commit 2c17512372
2 changed files with 6 additions and 6 deletions
+1 -1
View File
@@ -54,7 +54,7 @@
"undici": "^7.24.3"
},
"dependencies": {
"node-forge": "^1.3.1"
"node-forge": "^1.4.0"
},
"devDependencies": {
"@headlamp-k8s/eslint-config": "^0.6.0",
+5 -5
View File
@@ -9,8 +9,8 @@ importers:
.:
dependencies:
node-forge:
specifier: ^1.3.1
version: 1.3.3
specifier: ^1.4.0
version: 1.4.0
devDependencies:
'@headlamp-k8s/eslint-config':
specifier: ^0.6.0
@@ -3851,8 +3851,8 @@ packages:
resolution: {integrity: sha512-pyFS63ptit/P5WqUkt+UUfe+4oevH+bFeIiPPdfb0pFeYEu/1ELnJu5l+5EcTKYL5M7zaAa7S8ddywgXypqKCw==}
engines: {node: '>= 0.4'}
node-forge@1.3.3:
resolution: {integrity: sha512-rLvcdSyRCyouf6jcOIPe/BgwG/d7hKjzMKOas33/pHEr6gbq18IK9zV7DiPvzsz0oBJPme6qr6H6kGZuI9/DZg==}
node-forge@1.4.0:
resolution: {integrity: sha512-LarFH0+6VfriEhqMMcLX2F7SwSXeWwnEAJEsYm5QKWchiVYVvJyV9v7UDvUv+w5HO23ZpQTXDv/GxdDdMyOuoQ==}
engines: {node: '>= 6.13.0'}
node-releases@2.0.36:
@@ -9913,7 +9913,7 @@ snapshots:
object.entries: 1.1.9
semver: 6.3.1
node-forge@1.3.3: {}
node-forge@1.4.0: {}
node-releases@2.0.36: {}