Skip to content

chore: bump jspdf to resolve yarn audit vulnerabilities#8314

Merged
sumanmukherjee03 merged 1 commit intomasterfrom
WP-8242
Mar 18, 2026
Merged

chore: bump jspdf to resolve yarn audit vulnerabilities#8314
sumanmukherjee03 merged 1 commit intomasterfrom
WP-8242

Conversation

@mrdanish26
Copy link
Contributor

@mrdanish26 mrdanish26 commented Mar 17, 2026

TICKET: WP-8242

Workflow failure: https://github.com/BitGo/BitGoJS/actions/runs/23219265762/job/67487881801

Exception Type: CVE

Justification: Critical CVE in jspdf version less than 4.2.1

Current Dependency: jspdf@4.2.0

Upgrade To: jspdf@4.2.1

@mrdanish26 mrdanish26 marked this pull request as ready for review March 17, 2026 23:26
@mrdanish26 mrdanish26 requested a review from a team as a code owner March 17, 2026 23:26
@mrdanish26 mrdanish26 requested a review from a team March 17, 2026 23:58
Copy link

@bhargavirao24 bhargavirao24 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks good. Approving the PR for jspdf@4.2.1 . Low risk of exploitation based on our usage. Socket's scan score is 91, this will be a CVE fix for the two High/Critical issues. Cooldown bypass justified since it is a security patch. PR good to go. I will update the ticket too.

Image

@sumanmukherjee03
Copy link
Contributor

Since the security team has approved this change, on request from Louis Varin, i am admin merging this PR

@sumanmukherjee03 sumanmukherjee03 merged commit 1943026 into master Mar 18, 2026
20 of 21 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants