Skip to content

Conversation

jschuppan-sap
Copy link

This fixes this issue I opened earlier.
With this pull request, inquirer is set to a minimum version of 8.2.7 which fixes CVE-2025-54798 caused by a child dependency.

@jschuppan-sap jschuppan-sap requested a review from a team as a code owner September 2, 2025 18:00
Copy link

changeset-bot bot commented Sep 2, 2025

🦋 Changeset detected

Latest commit: 970f368

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 21 packages
Name Type
@sap-ux/ui5-library-reference-inquirer Patch
@sap-ux/repo-app-import-sub-generator Patch
@sap-ux/cf-deploy-config-inquirer Patch
@sap-ux/flp-config-sub-generator Patch
@sap-ux/ui5-application-inquirer Patch
@sap-ux/fiori-app-sub-generator Patch
@sap-ux/ui5-library-inquirer Patch
@sap-ux/flp-config-inquirer Patch
@sap-ux/ui-service-inquirer Patch
@sap-ux/fiori-mcp-server Patch
@sap-ux/adp-tooling Patch
@sap-ux/fe-fpm-cli Patch
@sap-ux/ui5-library-reference-sub-generator Patch
@sap-ux/cf-deploy-config-sub-generator Patch
@sap-ux/deploy-config-sub-generator Patch
@sap-ux/ui5-library-sub-generator Patch
@sap-ux/adp-flp-config-sub-generator Patch
@sap-ux/create Patch
@sap-ux/ui-service-sub-generator Patch
@sap-ux/generator-adp Patch
@sap-ux/preview-middleware Patch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

Copy link

cla-assistant bot commented Sep 2, 2025

CLA assistant check
All committers have signed the CLA.

@jschuppan-sap jschuppan-sap force-pushed the fix/update-vuln-inquirer-version branch 3 times, most recently from 001813b to 778b108 Compare September 2, 2025 22:30
@jschuppan-sap jschuppan-sap force-pushed the fix/update-vuln-inquirer-version branch from 778b108 to 970f368 Compare September 3, 2025 13:59
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

BUG - Multiple Packages depend on an outdated and vulnerable version of 'inquirer'
1 participant