Skip to content

CG fix - JenkinsDownloadArtifacts task#21186

Merged
v-gayatrij merged 3 commits intomasterfrom
users/v-gayjaiswal/cg-bugs
Jul 31, 2025
Merged

CG fix - JenkinsDownloadArtifacts task#21186
v-gayatrij merged 3 commits intomasterfrom
users/v-gayjaiswal/cg-bugs

Conversation

@v-gayatrij
Copy link
Contributor

@v-gayatrij v-gayatrij commented Jul 30, 2025

Context

Override form-data version in JenkinsDownloadArtifactsV1, V2 tasks to remove vulnerability
Associated alerts:
https://dev.azure.com/mseng/AzureDevOps/_componentGovernance/33/alert/331174?typeId=446682
https://dev.azure.com/mseng/AzureDevOps/_componentGovernance/33/alert/331092?typeId=446682


Task Name

JenkinsDownloadArtifactsV1,
JenkinsDownloadArtifactsV2


Description

Add override property to force the non-vulnerable versions of form-data


Risk Assessment (Low / Medium / High)

Low


Change Behind Feature Flag (Yes / No)

No


Tech Design / Approach

No


Documentation Changes Required (Yes/No)

Indicate whether related documentation needs to be updated.
No


Unit Tests Added or Updated (Yes / No)

No unit tests added


Additional Testing Performed

https://dev.azure.com/canarytest/PipelineTasks/_build/results?buildId=183560&view=results


Logging Added/Updated (Yes/No)

No


Telemetry Added/Updated (Yes/No)

No


Rollback Scenario and Process (Yes/No)

  • Rollback plan is documented.

Dependency Impact Assessed and Regression Tested (Yes/No)

  • All impacted internal modules, APIs, services, and third-party libraries are analyzed.
  • Results are reviewed and confirmed to not break existing functionality.

Checklist

  • Related issue linked (if applicable)
  • Task version was bumped — see versioning guide
  • Verified the task behaves as expected

@v-gayatrij v-gayatrij requested review from a team and manolerazvan as code owners July 30, 2025 12:10
@v-gayatrij v-gayatrij enabled auto-merge (squash) July 31, 2025 12:02
@Deekshitha981
Copy link
Contributor

/azp run

@v-gayatrij v-gayatrij merged commit e5e1328 into master Jul 31, 2025
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants