Skip to content

fix(security): update http-proxy-middleware to 2.0.9#5103

Merged
chenjiahan merged 1 commit intoweb-infra-dev:mainfrom
DeveshSapkale:update_http_proxy_middleware_2_0_9
Apr 25, 2025
Merged

fix(security): update http-proxy-middleware to 2.0.9#5103
chenjiahan merged 1 commit intoweb-infra-dev:mainfrom
DeveshSapkale:update_http_proxy_middleware_2_0_9

Conversation

@DeveshSapkale
Copy link
Contributor

Summary

In http-proxy-middleware before 2.0.8 and 3.x before 3.0.4, writeBody can be called twice because "else if" is not used.

Related Links

https://nvd.nist.gov/vuln/detail/CVE-2025-32996

Checklist

  • Tests updated (or not required).
  • Documentation updated (or not required).

@CLAassistant
Copy link

CLAassistant commented Apr 25, 2025

CLA assistant check
All committers have signed the CLA.

@netlify
Copy link

netlify bot commented Apr 25, 2025

Deploy Preview for rsbuild ready!

Name Link
🔨 Latest commit 09e6160
🔍 Latest deploy log https://app.netlify.com/sites/rsbuild/deploys/680b3ebc5a92f300083fdd09
😎 Deploy Preview https://deploy-preview-5103--rsbuild.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.
Lighthouse
Lighthouse
1 paths audited
Performance: 73 (🟢 up 21 from production)
Accessibility: 97 (no change from production)
Best Practices: 100 (no change from production)
SEO: 100 (no change from production)
PWA: 60 (no change from production)
View the detailed breakdown and full score reports

To edit notification comments on pull requests, go to your Netlify site configuration.

Copy link
Member

@chenjiahan chenjiahan left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thank you!

@chenjiahan chenjiahan enabled auto-merge (squash) April 25, 2025 08:00
@chenjiahan chenjiahan merged commit e098287 into web-infra-dev:main Apr 25, 2025
12 checks passed
@DeveshSapkale
Copy link
Contributor Author

@chenjiahan When can we expect the release build in the next few days? Is there a rough estimate for when this change will be available on npm?

@chenjiahan chenjiahan mentioned this pull request Apr 25, 2025
@chenjiahan
Copy link
Member

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants