Skip to content

Conversation

@charlypa
Copy link
Member

  • Updated pino 9.6.0 → 9.14.0 (fixes CVE-2025-57319 prototype pollution in fast-redact)
  • Updated brace-expansion 2.0.1 → 2.0.2 (fixes CVE-2025-5889 ReDoS)
  • Pino now uses @pinojs/redact instead of vulnerable fast-redact
  • 0 production vulnerabilities remaining

- Updated pino 9.6.0 → 9.14.0 (fixes CVE-2025-57319 prototype pollution in fast-redact)
- Updated brace-expansion 2.0.1 → 2.0.2 (fixes CVE-2025-5889 ReDoS)
- Pino now uses @pinojs/redact instead of vulnerable fast-redact
- 0 production vulnerabilities remaining
@charlypa charlypa merged commit 0dad291 into main Oct 19, 2025
4 checks passed
@charlypa charlypa deleted the ecs branch October 19, 2025 11:52
@sonarqubecloud
Copy link

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants