Skip to content

Bump form-data from 4.0.1 to 4.0.5#4

Closed
Copilot wants to merge 1 commit intodependabot/npm_and_yarn/form-data-4.0.5from
copilot/sub-pr-1
Closed

Bump form-data from 4.0.1 to 4.0.5#4
Copilot wants to merge 1 commit intodependabot/npm_and_yarn/form-data-4.0.5from
copilot/sub-pr-1

Conversation

Copy link
Contributor

Copilot AI commented Dec 12, 2025

Addresses security vulnerability in form-data 4.0.1 where unsafe random function is used for boundary generation.

Changes

  • Updates form-data transitive dependency from 4.0.1 to 4.0.5 in package-lock.json
  • Patched version uses secure random generation (fixed in 4.0.4+)

Security Context

Vulnerability: CVE affecting form-data < 4.0.4
Impact: Weak boundary randomness in multipart form data
Resolution: Update to 4.0.5 eliminates vulnerability


💡 You can make Copilot smarter by setting up custom instructions, customizing its development environment and configuring Model Context Protocol (MCP) servers. Learn more Copilot coding agent tips in the docs.

@vercel
Copy link

vercel bot commented Dec 12, 2025

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Preview Comments Updated (UTC)
markdownstudiox Ready Ready Preview Comment Dec 12, 2025 6:22pm

@dependabot dependabot bot deleted the branch dependabot/npm_and_yarn/form-data-4.0.5 December 12, 2025 18:22
@dependabot dependabot bot closed this Dec 12, 2025
Copilot AI changed the title [WIP] Bump form-data from 4.0.1 to 4.0.5 Bump form-data from 4.0.1 to 4.0.5 Dec 12, 2025
Copilot AI requested a review from RexO77 December 12, 2025 18:29
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants