Context
The develop dependency graph resolves qs@6.15.3, which is affected by GHSA-x5fp-wj9c-mxmx and GHSA-4mjr-xmp4-gh2g.
Scope
- Resolve
qs to version 6.16.0 or later.
- Refresh the Yarn PnP lockfile deterministically.
- Preserve the existing approved runtime and application contracts.
Acceptance criteria
yarn security:audit reports no active finding for the affected qs advisories.
- Required CI checks pass for the correction pull request.
- The vulnerable
qs@6.15.3 resolution is absent from the effective delivery graph.
Sequencing
This issue is registered as Todo. Implementation must wait for the currently active ordered delivery to complete.
Context
The
developdependency graph resolvesqs@6.15.3, which is affected by GHSA-x5fp-wj9c-mxmx and GHSA-4mjr-xmp4-gh2g.Scope
qsto version 6.16.0 or later.Acceptance criteria
yarn security:auditreports no active finding for the affectedqsadvisories.qs@6.15.3resolution is absent from the effective delivery graph.Sequencing
This issue is registered as Todo. Implementation must wait for the currently active ordered delivery to complete.