Skip to content

[Fix] Dependabot security issue: Formidable relies on hexoid to prevent guessing of filenames for untrusted executable content #880

Merged
sbarrio merged 1 commit into
developfrom
sbarrio/fix/security-issue-with-formidable-dep-from-code-push
May 20, 2025
Merged

[Fix] Dependabot security issue: Formidable relies on hexoid to prevent guessing of filenames for untrusted executable content #880
sbarrio merged 1 commit into
developfrom
sbarrio/fix/security-issue-with-formidable-dep-from-code-push

Conversation

@sbarrio
Copy link
Copy Markdown
Contributor

@sbarrio sbarrio commented May 16, 2025

What does this PR do?

This PR forces the resolution for the react-native-code-push formidable dependency to version 3.5.2, which solves a light security issue raised by dependabot here.

Review checklist (to be filled by reviewers)

  • Feature or bugfix MUST have appropriate tests
  • Make sure you discussed the feature or bugfix with the maintaining team in an Issue
  • Make sure each commit and the PR mention the Issue number (cf the CONTRIBUTING doc)
  • If this PR is auto-generated, please make sure also to manually update the code related to the change

@sbarrio sbarrio self-assigned this May 16, 2025
@sbarrio sbarrio marked this pull request as ready for review May 16, 2025 10:49
@sbarrio sbarrio requested a review from a team as a code owner May 16, 2025 10:49
@sbarrio sbarrio merged commit dc21920 into develop May 20, 2025
8 checks passed
@sbarrio sbarrio deleted the sbarrio/fix/security-issue-with-formidable-dep-from-code-push branch May 20, 2025 07:44
@cdn34dd cdn34dd mentioned this pull request May 22, 2025
4 tasks
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants