Skip to content

Update form-data to 4.0.5 to address critical CVEs#2613

Open
nicholas-lockhart wants to merge 4 commits into
Azure:mainfrom
nicholas-lockhart:form-data
Open

Update form-data to 4.0.5 to address critical CVEs#2613
nicholas-lockhart wants to merge 4 commits into
Azure:mainfrom
nicholas-lockhart:form-data

Conversation

@nicholas-lockhart
Copy link
Copy Markdown

The form-data package has a vulnerability which is flagged as critical (CVE-2025-7783). Bumped the version to 4.0.5, which addresses the issue. The tests continue to pass, and there is no need for any additional tests.

@blueww
Copy link
Copy Markdown
Member

blueww commented Dec 11, 2025

@EmmaZhu
Would you please check if this PR has any conflict with the current change for deprecated dependency from you ?
If you are OK, I am good to merge it.

@blueww blueww requested a review from EmmaZhu December 11, 2025 03:22
@nicholas-lockhart
Copy link
Copy Markdown
Author

@blueww @EmmaZhu any updates here?

Copilot AI review requested due to automatic review settings May 27, 2026 16:43
Copy link
Copy Markdown
Contributor

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Note

Copilot was unable to run its full agentic suite in this review.

Updates the changelog to document a security-motivated dependency bump.

Changes:

  • Add an entry noting the form-data package update to 4.0.5 due to CVE concerns.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment thread ChangeLog.md
Comment on lines +13 to +14
- Update form-data package to 4.0.5 to address CVE concerns.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants