Skip to content

Fix/tmp security patch - #265

Merged
rakesh-talanki merged 3 commits into
apigee:masterfrom
rakesh-talanki:fix/tmp-security-patch
Jul 30, 2026
Merged

Fix/tmp security patch#265
rakesh-talanki merged 3 commits into
apigee:masterfrom
rakesh-talanki:fix/tmp-security-patch

Conversation

@rakesh-talanki

Copy link
Copy Markdown
Collaborator

This fix is related to PR #256

akaustav and others added 3 commits January 1, 2026 10:08
PR apigee#256 previously bumped this dependency to 0.2.5, which successfully patched the Symlink vulnerability (CVE-2025-54798). However, the Path Traversal vulnerability (CVE-2026-44705) via prefix/postfix parameters was only recently patched in version 0.2.7.

This update bumps the dependency to ^0.2.7 to ensure both CVEs are comprehensively remediated.

Test Suite: 91 specs, 0 failures.
@akaustav

akaustav commented Jul 29, 2026

Copy link
Copy Markdown
Contributor

@rakesh-talanki - Thank you for opening this PR preserving the commits from my PR #256 and bumping the tmp package to 0.2.7 in an attempt to resolve issue #255. I do NOT have the ability to merge either PRs. Neither can I review your PR or run the pending check on this PR. So, I have requested @kevya-google for advice on how to proceed with the next steps on these PRs - see messages from this comment onward: #256 (comment)

@rakesh-talanki
rakesh-talanki merged commit 7c231b5 into apigee:master Jul 30, 2026
7 checks passed
@akaustav

akaustav commented Jul 30, 2026

Copy link
Copy Markdown
Contributor

@rakesh-talanki - Thanks for merging this PR to fix the underlying security vulnerabilities mentioned in issue #255. I have closed that issue.

@kevya-google / @rakesh-talanki - Would you have the necessary knowledge and / or access to release this change into the corresponding npm package hosted at: https://www.npmjs.com/package/apigeetool? Perhaps as version 0.16.6?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants